Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Initiate the tunnel from the pfSense

    Scheduled Pinned Locked Moved IPsec
    11 Posts 2 Posters 5.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      Fill in a Keep-Alive IP address inside of the remote subnet, then it will try to initiate the tunnel when the Keep-Alive ping is sent.

      See also here:
      http://doc.pfsense.org/index.php/Why_can%27t_I_query_SNMP,_use_syslog,_NTP,_or_other_services_initiated_by_the_firewall_itself_over_IPsec_VPN%3F

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • D
        danielobs
        last edited by

        @jimp:

        Fill in a Keep-Alive IP address inside of the remote subnet, then it will try to initiate the tunnel when the Keep-Alive ping is sent.

        Hi,

        My network is 192.168.1.0/24 and IP of pfsense is 192.168.1.254
        Remote Network with Netasq is 192.168.10.0/24 and Netasq local IP is 192.168.10.254

        In my  pfsense configuration in VPN tunel I have :
        Keep alive Automatically ping host : 192.168.10.254 (IP of Netasq in the second network)

        In the System - Static Routes I have :

        Interface: LAN
        Network: 192.168.10.0/24  (Remote Network with Netasq)
        Gateway: 192.168.1.254  (my pfsense ip)

        Unfortunately, I still can not initiate IPSec tunel from my network.

        Best regards,

        Daniel

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          If that is the case, but they can initiate a tunnel to you, then the Netasq side might be blocking inbound IPsec so your initiation request never gets all the way there.

          You can look at the IPsec log to confirm this, it is probably trying but timing out.

          pfSense (by default) allows inbound IPsec from the remote peer when you add a tunnel. I'm not sure if the Netasq device would do the same.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • D
            danielobs
            last edited by

            When I made ping from my network to 192.168.10.254 in pfsense Diagnostics: System logs: IPSEC VPN  log is empty.
            No information about IPSec.

            Best regards,

            Daniel

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Post screenshots of your IPsec tunnel configuration.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • D
                danielobs
                last edited by

                @jimp:

                Post screenshots of your IPsec tunnel configuration.

                ipsec-1.jpg
                ipsec-1.jpg_thumb
                ipsec-2.jpg
                ipsec-2.jpg_thumb
                ipsec-3.jpg
                ipsec-3.jpg_thumb
                ipsec-4.jpg
                ipsec-4.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  Looks normal.

                  Can you clear the IPsec logs, then go to Status > Services, restart racoon, then try to ping and post the contents of the IPsec log after trying.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • D
                    danielobs
                    last edited by

                    @jimp:

                    Looks normal.

                    Can you clear the IPsec logs, then go to Status > Services, restart racoon, then try to ping and post the contents of the IPsec log after trying.

                    After restart racoon in log is :

                    Last 50 IPSEC log entries
                    Sep 29 16:14:43 racoon: INFO: @(#)ipsec-tools 0.7.2 (http://ipsec-tools.sourceforge.net)
                    Sep 29 16:14:43 racoon: INFO: @(#)This product linked OpenSSL 0.9.8e 23 Feb 2007 (http://www.openssl.org/)
                    Sep 29 16:14:43 racoon: INFO: Reading configuration from "/var/etc/racoon.conf"
                    Sep 29 16:14:43 racoon: [Self]: INFO: 192.168.2.254[500] used as isakmp port (fd=14)
                    Sep 29 16:14:43 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=15)
                    Sep 29 16:14:43 racoon: [Self]: INFO: 89.77.51.111[500] used as isakmp port (fd=16)
                    Sep 29 16:14:43 racoon: [Self]: INFO: 192.168.1.254[500] used as isakmp port (fd=17)
                    Sep 29 16:14:43 racoon: INFO: unsupported PF_KEY message REGISTER
                    Sep 29 16:14:43 racoon: ERROR: such policy already exists. anyway replace it: 192.168.1.0/24[0] 192.168.1.254/32[0] proto=any dir=in
                    Sep 29 16:14:43 racoon: ERROR: such policy already exists. anyway replace it: 192.168.1.254/32[0] 192.168.1.0/24[0] proto=any dir=out
                    Sep 29 16:14:44 racoon: [Self]: INFO: 192.168.2.254[500] used as isakmp port (fd=14)
                    Sep 29 16:14:44 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=15)
                    Sep 29 16:14:44 racoon: [Self]: INFO: 89.77.51.111[500] used as isakmp port (fd=16)
                    Sep 29 16:14:44 racoon: [Self]: INFO: 192.168.1.254[500] used as isakmp port (fd=17)
                    Sep 29 16:14:51 racoon: [Self]: INFO: 192.168.2.254[500] used as isakmp port (fd=14)
                    Sep 29 16:14:51 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=15)
                    Sep 29 16:14:51 racoon: [Self]: INFO: 89.77.51.111[500] used as isakmp port (fd=16)
                    Sep 29 16:14:51 racoon: [Self]: INFO: 192.168.1.254[500] used as isakmp port (fd=17)

                    But after ping I have no new positions in this log.

                    Ping is :

                    C:>ping 192.168.10.254

                    Badanie 192.168.10.254 z 32 bajtami danych:
                    Odpowiedź z 192.168.1.254: Limit czasu wygaśnięcia (TTL) upłynął podczas tranzytu.
                    Odpowiedź z 192.168.1.254: Limit czasu wygaśnięcia (TTL) upłynął podczas tranzytu.
                    Odpowiedź z 192.168.1.254: Limit czasu wygaśnięcia (TTL) upłynął podczas tranzytu.
                    Odpowiedź z 192.168.1.254: Limit czasu wygaśnięcia (TTL) upłynął podczas tranzytu.

                    Statystyka badania ping dla 192.168.10.254:
                        Pakiety: Wysłane = 4, Odebrane = 4, Utracone = 0 (0% straty),

                    Limit czasu wygaśnięcia (TTL) upłynął podczas tranzytu. = Time Limit (TTL) expired in transit.

                    Regards,

                    Daniel

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      And pfSense is the gateway for the workstation you are pinging from?

                      What if you try to ping from the web interface (Diagnostics > Ping) with the LAN interface selected?

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • D
                        danielobs
                        last edited by

                        @jimp:

                        And pfSense is the gateway for the workstation you are pinging from?

                        What if you try to ping from the web interface (Diagnostics > Ping) with the LAN interface selected?

                        Yes is the gateway.
                        ipconfig :
                        Konfiguracja IP systemu Windows
                        Karta Ethernet Połączenie lokalne:

                        Sufiks DNS konkretnego połączenia : local
                          Adres IPv6 połączenia lokalnego . : fe80::140c:40e9:35df:1d6%13
                          Adres IPv4. . . . . . . . . . . . . : 192.168.1.140
                          Maska podsieci. . . . . . . . . . : 255.255.255.0
                          Brama domyślna. . . . . . . . . . : 192.168.1.254  !!!

                        ping result is in txt file

                        ping-from-webgui.txt

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.