Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dashboard IPSec show link as up, even if it is not.

    Scheduled Pinned Locked Moved 2.2 Snapshot Feedback and Problems - RETIRED
    5 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mrzaz
      last edited by

      Background:

      I have three phase 1 connections (four Phase 2)

      • IPv4, dest1, 1 ph1, 1 ph2
      • IPv4, dest2, 1 ph1, 2 ph2
      • IPv6, dest2, 1 ph1, 1 ph2

      I have one IPSec connection (dest 2) with two Phase 2 nets (192.168.120.0 and 192.168.121.0) going over the same Phase1 connection.

      Previously in 2.1.5, this was shown as 4 entries in the Dashboard IPSec table.  (Basically one each representing one phase2 connection each.)
      If one phase 2 has gone down, then one entry in the Dashboard IPSec table was down and it was also seen as one down in the Overview screen in the Dashboard IPSec table.

      In 2.2 RC, there is still 4 entries in the Dashboard IPSec table and it looks exactly the same as in 2.1.5

      HOWEVER now it show all four entries as green "UP", even if I know that one Phase2 is NOT up.
      If I check the IPSec Status page and expand the "Show child SA entries", the "192.168.121.0" net is not up.
      Feels to me that this is a bug in the 2.2 RC Dashboard IPSec widget.

      (192.168.121.0 net is the OpenVPN Server for roadwarriors and is not always in state where someone is connected = No ping/traffic from this interface over the IPSec.)

      See attached screenshots.

      UPDATE:
      I found this bug #4045 that is suppose to be resolved according to Chris.
      https://redmine.pfsense.org/issues/4045
      According to cmb, it is not the same fault as 4045, but a new one.

      Dan Lundqvist
      MRZAZ.COM
      Stockholm, Sweden
      Pic1.jpg
      Pic1.jpg_thumb
      Pic2_final.jpg
      Pic2_final.jpg_thumb
      Pic3.jpg
      Pic3.jpg_thumb
      Pic4.jpg
      Pic4.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        That's not the same issue as #4045, but there does appear to be an issue there, looking into it.

        1 Reply Last reply Reply Quote 0
        • M
          mrzaz
          last edited by

          Good. :-)

          //Danne

          1 Reply Last reply Reply Quote 0
          • M
            mrzaz
            last edited by

            cmb:  Did you manage to find the faulty and/or have you created a ticket ?

            I also had an idea. Could the problem, as described in https://redmine.pfsense.org/issues/4129,
            possible fool the widget into thinking the second P2 link is up somehow?  Was just an idea.
            Maybe not 2 cents worth, but. :-)

            //Danne

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              that's now covered by https://redmine.pfsense.org/issues/4139 as it regressed further today.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.