• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC Changes Require Reboot

Scheduled Pinned Locked Moved IPsec
5 Posts 2 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    khancock
    last edited by Sep 27, 2017, 12:15 PM

    Any changes to an IPSEC tunnel requires a reboot to take effect.  Why?

    System Netgate SG-2440
    BIOS Vendor: coreboot
    Version: ADI_RCCVE-01.00.00.12-nodebug
    Version 2.3.4-RELEASE-p1 (amd64)
    built on Fri Jul 14 14:52:43 CDT 2017
    FreeBSD 10.3-RELEASE-p19

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Sep 27, 2017, 3:20 PM

      What changes, specifically? I haven't ever seen that happen that I can recall.

      Next time, instead of a reboot, if the changes do not apply then go to Status > Services and stop the IPsec service and then start it again. Do not use the restart button.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • K
        khancock
        last edited by Sep 27, 2017, 10:44 PM

        If I add another Phase 2 entry I have to reboot.  I tried to restart just IPSEC but it does not work.  I thought this was due to old hardware so I upgraded to NetGate and the problem persists.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Sep 28, 2017, 3:37 PM

          @khancock:

          If I add another Phase 2 entry I have to reboot.

          I make P2 changes all the time and they take effect when expected, you'll have to be more specific. Do these new P2s get added to only a single tunnel? Do they overlap anything else? Anything special about them?

          Since this doesn't appear to be happening to anyone else, there must be something distinct about your setup that is triggering the behavior

          @khancock:

          I tried to restart just IPSEC but it does not work

          Did you use the "restart" button or did you actually stop and then start the service as I suggested? A restart doesn't restart IPsec, it only tells strongSwan to reload the configuration file.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • K
            khancock
            last edited by Sep 28, 2017, 9:10 PM

            Nothing special about them, just adding another host or network to the tunnel.  I haven't stopped and started the IPSEC service, just used the icon that shows restart service.  We'll try that.

            This config has been running around 7 years and this behavior started around 2 years ago.

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received