• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Enc0 not routing traffic

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 3.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mirage-42
    last edited by Aug 17, 2011, 3:55 PM

    Hi everyone,

    I have set up an IPSec tunnel between a PFsense 2.0-RC1 and an IPCop.

    The tunnel is marked as UP on both sides

    From the network beyond the IPCop, I can ping every single machine beyond the PFSense.
    From the network beyond the PFSense, I can't ping machines beyond the IPCop.

    What gives me trouble is :
      * IPCop side, I have an ipsec interface, with an IP address and route to the other side of the IPSec tunnel
      * PFSense side I have an enc0 interface, without IP address and no trace of a route in the routing tables to the IPCop side :

    IPCOP

    
    # ifconfig
    ...
    ipsec0    Link encap:Ethernet  HWaddr MA:CA:DD:RE:SS:00  
                  inet addr:public ip address  Mask:255.255.255.248
                  UP RUNNING NOARP  MTU:16260  Metric:1
    ...
    
    # ip route list
    ...
    LAN ADDRESS PFSIDE/24 via Public IP GW dev ipsec0
    ...
    
    

    PFSENSE

    
    # ifconfig
    ...
    enc0: flags=41 <up,running>metric 0 mtu 1536
    
    # netstat -nr
    gives no mention of route to ipcop side lan</up,running> 
    

    Am I missing something ?

    Thanks for your help

    1 Reply Last reply Reply Quote 0
    • M
      Metu69salemi
      last edited by Aug 17, 2011, 4:51 PM

      MTU doesnt match

      1 Reply Last reply Reply Quote 0
      • M
        mirage-42
        last edited by Aug 18, 2011, 6:58 AM

        True,

        But actually I can't change the MTU trough the PFSense's GUI nor trough the IPCOp's one.
        And that doesn't explain why it works in a way and not in the other way, does it ?

        I forgot to mention that my IPCop is straight on the Internet (bridge mode on the ISP's router), and my PFSense is behind onther ISP's router, which can't be in bridge mode.

        1 Reply Last reply Reply Quote 0
        • M
          Metu69salemi
          last edited by Aug 18, 2011, 2:00 PM

          Then i dont know

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received