Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    P2s flip-flopping and going stale

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 284 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • TitaniumCoder477T
      TitaniumCoder477
      last edited by TitaniumCoder477

      I have what I think is a relatively simple setup:

      • pfSense firewall onsite <--> Linode VM
      • The IPsec tunnel has three P2s, one for the LAN bridge, and two for VLANs; these are meant to be accessible from the Linode VM

      alt text

      The symptom I have experienced off and on for many months is that my webservers, on the GENERAL subnet, will become unreachable. When I investigate, I find the IPsec tunnel connected and looking normal. But I can't ping the VLAN gateway from the Linode VM.

      Last night and again this morning, I noticed a few new clues:

      1. When I can't ping one gateway, I can always ping the other two VLAN gateways.
      2. When a gateway automatically re-installs, it is able to ping and one of the others is not.
      3. When I disconnect a P2 manually that I was able to ping across, the other one that I was not able to ping across is immediately fixed.

      Also, the symptoms are always cleared up temporarily whenever I disconnect/reconnect P1 or when I reboot the firewall.

      Figure 1: The GEN_VLAN gateway is unreachable from the Linode VM
      alt text

      Figure 2: I disconnect the GAM_VLAN P2 and now the GEN_VLAN gateway is reachable
      alt text

      Figure 3: I reconnect the GAM_VLAN P2 and all three are still reachable
      alt text

      Here are my basic settings for P1:
      alt text

      Here are my basic settings for all the P2s with the only change being the Life Time value:
      alt text

      • Life Time for the P2s are 3600, 3800, and 4000

      And here is my /etc/ipsec.conf on the Linode VM:
      alt text

      Any ideas? I've tried quite a few different things already, too many to list really, and all "shots in the dark" based on a mix of Internet research and limited knowledge.

      YayPeacePeaceY 1 Reply Last reply Reply Quote 0
      • YayPeacePeaceY
        YayPeacePeace @TitaniumCoder477
        last edited by

        @TitaniumCoder477 Send a print of Status / IPsec / SADs and SPDs while the GEN_VLAN gateway is unreachable.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.