Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does pfsense/freebsd filter the "session id"?

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 4 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      aldo
      last edited by

      not really your problem ther is only one ip proberly only one person can connect.
      because it does not differentiate.

      get more ips on your wan and send them out differnet ones????
      make a tunnel between the two sites.

      1 Reply Last reply Reply Quote 0
      • A
        avel
        last edited by

        thanks for replying.

        Well, they claim that it would work on other offices were also only one
        fix ip-adress for outside connections is available… so they tend to
        be sure that it is our problem.

        A site-to-site is not possible, since the policy of the customer
        does not allow that anymore (big company, you know...).

        Any other idea? Can it be NAT?

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          I've had 3-4 simultaneous client machines connected to the same Cisco VPN device before.

          I'm guessing they must not have NAT-T enabled on their end. It works fine with that.

          1 Reply Last reply Reply Quote 0
          • A
            avel
            last edited by

            thanks for the answer.

            Ok, but if their configuration works for other supporting companies
            and since you can confirm that these kind of connections do work at all,
            the problem must be on our side.

            What could it be? We only got some inbound-NAT rules, but
            i don't think they have anything to do with it, as said, the
            firewall rules are just "LAN -> any", and we do automatic NAT
            from LAN to internet.

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              what pfsense version are you running?

              1 Reply Last reply Reply Quote 0
              • A
                avel
                last edited by

                pfSense 1.0.1 RELEASE

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  Well, shouldn't matter, one of the machines I go through to get to the Internet is a 1.0-RC version.

                  Do you have advanced outbound NAT enabled?

                  1 Reply Last reply Reply Quote 0
                  • A
                    avel
                    last edited by

                    no, "advanced outbound NAT " is disabled.
                    I have "Enable IPSec passthru" aktivated.

                    1 Reply Last reply Reply Quote 0
                    • S
                      sullrich
                      last edited by

                      Upgrade to a recent testing snapshot: http://snapshots.pfsense.com/FreeBSD6/RELENG_1_2/updates/

                      1 Reply Last reply Reply Quote 0
                      • C
                        cmb
                        last edited by

                        I seriously doubt if a snapshot is going to change anything, but I would try it.

                        There are some IPsec passthrough changes, though I don't think it will matter because I'm running behind way older versions than what you are and don't have problems.

                        1 Reply Last reply Reply Quote 0
                        • C
                          cmb
                          last edited by

                          Something just hit me. Looking back at the subject, "session ID", that's not IPsec related (AFAIK). Is this by chance a PPTP or L2TP connection? We (or at least I) hear Cisco and assume IPsec.

                          1 Reply Last reply Reply Quote 0
                          • A
                            avel
                            last edited by

                            i assume they use IPSec yes, but i have forwarded the question to be sure.
                            I will post the answer as soon as i get it.

                            1 Reply Last reply Reply Quote 0
                            • A
                              avel
                              last edited by

                              ok i got an answer:

                              "…this is a common problem we do encounter with many routers that are not Cisco/AVM,
                              the address translation of IPSec is not handled correctly, therfore our gateway can't
                              differentiate between the incomming connections..."

                              So it's IPSec. Any ideas?

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.