Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec Multiple Phase 2s Not Showing in Status

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 142 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rgibson
      last edited by

      Hi,

      I'm hoping someone can help me. This is my fist time with pfSense. I created an IPsec VPN from my pfSense box to a remote Sophos XGS firewall with one phase 2 tunnel. Wow, it worked. Pat myself on the back.
      I created another phase 2 tunnel and set it up on the Sophos end and it also appeared to work after restarting the pfSense VPN service. At some point I had to restart the service again. When looking at the Sophos status I noticed that there was a problem with the second phase 2 tunnel. Checking the status on the pfSense box the phase 2 tunnel was not showing in status. I created a third phase 2 and set it up on the Sophos side and it isn't showing either.

      Anyone have any ideas of where to start troubleshooting? I looked at the logs but I don't seen anything that jumps out at me.

      Thanks
      Rob

      C 1 Reply Last reply Reply Quote 0
      • C Offline
        cswroe @rgibson
        last edited by

        @rgibson Does it by chance show them all in the same P2 window? I have a couple that show that.
        2144.png

        You could also try the IPsec Widget on the dashboard, I find that an easier overview.
        2145.png

        R 1 Reply Last reply Reply Quote 0
        • R Offline
          rgibson @cswroe
          last edited by

          @cswroe
          Strangely enough after about 20 minutes the second tunnel showed up. A full day later and I still don't have the third.

          06ed0e55-5376-4639-ade5-ca58839c2961-image.png

          35663a07-9d07-4a36-82bf-c93212f09bc1-image.png

          C R 2 Replies Last reply Reply Quote 0
          • C Offline
            cswroe @rgibson
            last edited by

            @rgibson Curious if you tried the widget to see if it reflects the same.

            1 Reply Last reply Reply Quote 0
            • R Offline
              rgibson @rgibson
              last edited by

              The widget shows that all three tunnels are up. However the Sophos side still says that there is no connection on the third tunnel. Also cannot ping across.

              Snag_233c72.png

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.