Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    One way traffic

    Scheduled Pinned Locked Moved IPsec
    8 Posts 2 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jonb
      last edited by

      I have an issue were I get 1 way traffic with PFsense. As far as I can make out is that PFsense doesn't always tear down the old tunnel when the new one is created. This I believe makes PF use the old tunnels rather than the new ones.

      I am having this issue connecting to Cisco and draytek kits. I tried to resolve this by setting the DPD to 5 but yet the old tunnel stays up when the other side doesn't have anything shown. When the one way comms occur in the SAD page you can see that their are 4 tunnels instead of just one. The old way I have found to fix this is to delete the old tunnels.

      Does anyone have any suggestions on what is causing this.

      Hosted desktops and servers with support without complication.
      www.blueskysystems.co.uk

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        System > Advanced, check "Prefer old IPsec SAs"

        I've had to check that often when working with devices from other vendors.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          Jonb
          last edited by

          Cool thanks will give it a try.

          Hosted desktops and servers with support without complication.
          www.blueskysystems.co.uk

          1 Reply Last reply Reply Quote 0
          • J
            Jonb
            last edited by

            Should the DPD not detect the dead tunnels?

            Hosted desktops and servers with support without complication.
            www.blueskysystems.co.uk

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              I believe DPD happens at the phase 1 (ISAKMP SA) level and not at the Phase 2 (IPsec SA) level where this issue happens.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • J
                Jonb
                last edited by

                Hmmm this is a tuff one as the issue has been made easier with the above fix but hasn't fixed it. As right no I have 10 inbound connections and 2 outbound with a draytek 2820. So this is a problem somewhere.

                Hosted desktops and servers with support without complication.
                www.blueskysystems.co.uk

                1 Reply Last reply Reply Quote 0
                • J
                  Jonb
                  last edited by

                  Is there anyway to fix this to stop multiple tunnel to be created per VPN subnet.

                  Hosted desktops and servers with support without complication.
                  www.blueskysystems.co.uk

                  1 Reply Last reply Reply Quote 0
                  • J
                    Jonb
                    last edited by

                    Does anyone have any ideas how to stop this multiple tunnel issue.

                    Hosted desktops and servers with support without complication.
                    www.blueskysystems.co.uk

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.