Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec Mobile traffic passthrough

    Scheduled Pinned Locked Moved IPsec
    6 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jschmall
      last edited by

      IPSec VPN is configured nicely, I can connect to it from my iPhone, and I can access IPs on the LAN and I can browse the internet just fine.

      However, despite any of my rules, NAT configuration, hair pulling or crying, I can NOT get my mobile traffic to pass through the tunnel.ย  Getting my IP while connected to the VPN shows my phones public IP, not my home IP.

      Any ideas? Am I just blind or is this above my head, it shouldn't be.

      I can post anything you need, screenshots, logs, whatever.ย  I could really use some help here.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Do you have "Provide a list of accessible networks to clients" checked on the IPsec mobile tab? If so, try unchecking it.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          jschmall
          last edited by

          I did have it checked but now that I've unchecked it and provided a DNS server list, the racoon daemon crashes if I try to log into the VPN.

          Any ideas?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            That's probably a quirk in racoon where it won't let you send four DNS servers, only three. If you send four, we've found that it causes a crash.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • J
              jschmall
              last edited by

              Dude, seriously, I love you. It works perfectly now.

              One more question though, what is changed by unchecking "Provide a list of accessible networks to clients"? Curiosity has the better of me.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                When checked, the server takes the list of networks on the mobile Phase 2 and sends them to the client as a "net list" or "split network" list, so that only the networks provided will be sent across the tunnel and others go to the Internet directly, rather than tunneling everything.

                It's up to the client to obey that setting. Some don't support it at all and always require a manual list, others respect it, others ignore it on purpose and send everything no matter what you do.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.