Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC do not route trafic coming from other IP's (not local subnet but from a subnet connected with a router with local)

    IPsec
    2
    2
    134
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      costinguv
      last edited by

      Hi,
      I am new on pfSense and IPSEC and now I am stuck for few days trying to configure all I need.

      I have next config:
      my local net: 10.10.0.x with gw 10.10.0.254 (used for internet connection)
      on the gw i have also a openvpn server and clients have ip's in 10.8.0.x and gw for them on 10.8.0.1

      I installed pfSense for IPSEC and in next time want to move slowly all services form old router (ClearOS) on pfSense.
      So I have pfsense on 10.10.0.200 and remote net is 10.30.0.x.
      All routing between 10.10.0 and 10.30.0 are working ok.
      The same from 10.8 to 10.10
      But when I try ping from 10.8 ip to IPSEC ip, pfsense receive on xn0 interface the ICMP packet but do not pass to enc0. I receive TTL expired in transit.

      If i ping from 10.30.0 ip to 10.8.0.1, packet go to destination and when return stuck in the same place, on xn0 interface of pfsense.
      As I told, ping from 10.8 to 10.10.0.200 is ok. Also ping from 10.30 to 10.0.0.254 is ok.
      I do not understand why pfsense do not want to route a packet to 10.30 comming from 10.8

      Any advice is welcome.
      Thanks

      1 Reply Last reply Reply Quote 0
      • P
        pete35
        last edited by

        Hi,
        you may try do reboot the pfsense, the routing table is sometimes a little bit weird.

        <a href="https://carsonlam.ca">bintang88</a>
        <a href="https://carsonlam.ca">slot88</a>

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.