• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

2.1 ipsec broken

Scheduled Pinned Locked Moved IPsec
9 Posts 5 Posters 3.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    ccb056
    last edited by Nov 15, 2013, 3:29 AM

    It seems that somewhere between 2.0.3 and 2.1 ipsec got broken.

    I notice this happens a lot when my modem restarts.  It will bring down the ipsec tunnel (obviously).
    However, in 2.0.3 when the modem comes back the ipsec tunnel comes back up.
    In 2.1 the tunnel doesn't come back until racoon is restarted.

    :(

    1 Reply Last reply Reply Quote 0
    • T
      Thowie
      last edited by Dec 5, 2013, 9:00 PM

      Hi,
      ive got the same error. Sometimes the phase1 dont get up… And i don't see any try in the logs of racoon... But on the other side ( draygtek router ) i see that the router try it every 30 seconds.
      But in racoon no logline.
      After i restart racoon everything works great...
      MfG
      Thomas

      1 Reply Last reply Reply Quote 0
      • C
        ccb056
        last edited by Dec 11, 2013, 10:24 PM

        I have created a bug in redmine for this:

        https://redmine.pfsense.org/issues/3321

        1 Reply Last reply Reply Quote 0
        • C
          ccb056
          last edited by Apr 14, 2014, 11:10 PM

          This is broken again in 2.1.2

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Apr 15, 2014, 1:39 AM

            Nothing related to this changed from 2.1.1 to 2.1.2, very few things changed at all between, it was only a few days. Going to need more info.

            1 Reply Last reply Reply Quote 0
            • C
              ccb056
              last edited by Apr 15, 2014, 1:53 AM

              Chris, it's pretty easy to replicate.

              Get an IPSEC tunnel running on a 2.1.2 amd64 box, powercycle the modem on the pfsense box, and then watch how racoon never brings the tunnels back when the modem regains connection.

              1 Reply Last reply Reply Quote 0
              • T
                Thowie
                last edited by Apr 28, 2014, 9:22 AM Apr 28, 2014, 9:18 AM

                Hello,
                the error still exists in Version 2.1.2… You cant see any logs... but the tunnel won't get up... If you resart racoon or reboot the firewall everything works...
                FYI: We installed pfsense in vmware and use carp ip for vpn.
                and we updated from running pfsense 2.03 boxes...

                THX

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by May 3, 2014, 2:02 PM

                  Anyone to post some real info here? "Oh noes it (still) no workie" is absolutely useless…. WFM.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mix_room
                    last edited by May 8, 2014, 8:07 AM

                    THIS thread also has problems with IPSec and CARP. Likely the issue is related.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received