• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPsec such policy does not already exist

Scheduled Pinned Locked Moved IPsec
3 Posts 2 Posters 7.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    ameno_123
    last edited by Dec 18, 2009, 9:05 PM

    Hi,
    I have this erreur in my log :

    racoon: ERROR: such policy does not already exist: "192.168.0.0/24[0] 192.168.1.10/32[0] proto=any dir=out"
    racoon: ERROR: such policy does not already exist: "192.168.1.10/32[0] 192.168.0.0/24[0] proto=any dir=in"

    My lan office : 192.168.0.0
    Pfsense IP : 192.168.0.1
    My IP home : 192.168.1.10

    I want connect to my office with IPsec.
    I ping Pfsense, i dont ping my server office : 192.168.0.100

    firewall log :
    block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1599, length 40
    4. 996311 rule 74/0(match): block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1600, length 40
    4. 995961 rule 74/0(match): block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1601, length 40

    what is the solution!?

    nb: excuse my bad english (:

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Dec 19, 2009, 12:19 AM

      That error is normal, especially if your tunnels are using main mode.

      It looks like you need to add firewall rules on the IPsec tab under Firewall > Rules. If you want to allow everything add a rule to allow all protocols from any to any. Be sure you set the protocol to "any" because it defaults to TCP.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A
        ameno_123
        last edited by Dec 19, 2009, 1:39 AM

        :) work fine.. tnks
        I ping only ip dhcp on remote network, and i dont ping de fixed ip…

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received