• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Dashboard Show IPSEC inactive

Scheduled Pinned Locked Moved 2.2 Snapshot Feedback and Problems - RETIRED
13 Posts 7 Posters 3.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cmb
    last edited by Nov 25, 2014, 8:08 PM

    I fixed that today, thanks.

    1 Reply Last reply Reply Quote 0
    • J
      jgraham5481
      last edited by Nov 25, 2014, 9:04 PM

      Yep, works in todays snapshot! Thank You!

      1 Reply Last reply Reply Quote 0
      • R
        rr2squared
        last edited by Dec 27, 2014, 1:20 AM

        Just migrated from 2.1.5 to 2.2-RC and problem exists in this release.  Status page (diag_ipsec.php) shows tunnels active, but widget shows them inactive.

        Release info:
        2.2-RC (i386)
        built on Fri Dec 26 09:31:09 CST 2014
        FreeBSD 10.1-RELEASE-p3

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Dec 28, 2014, 3:27 AM

          All known issues there have been fixed, including some regressions introduced early last week, confirmed fixed on a number of systems on the 26th snapshot. What does your diag_ipsec.php page look like exactly? Screenshot would be helpful.

          1 Reply Last reply Reply Quote 0
          • E
            eskild
            last edited by Dec 28, 2014, 5:16 PM

            2.2-RC (i386)
            built on Sun Dec 28 04:40:24 CST 2014
            FreeBSD 10.1-RELEASE-p3

            I my system, 3/7 ipsec ph2 is up, but the widget shows all 7 as down.

            ipsec-diag.png
            ipsec-diag.png_thumb
            ipsec-status.png
            ipsec-status.png_thumb

            1 Reply Last reply Reply Quote 0
            • K
              kitdavis
              last edited by Dec 28, 2014, 5:51 PM

              I see the same behaviour as well.
              The dashboard never shows more than 6 tunnels as being up.

              dashboard1229.png
              dashboard1229.png_thumb
              IPSEC1229.png
              IPSEC1229.png_thumb

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by Dec 29, 2014, 6:09 PM

                @eskild:

                I my system, 3/7 ipsec ph2 is up, but the widget shows all 7 as down.

                Your counters are all 0, if you pass traffic across it does it then show as up?

                1 Reply Last reply Reply Quote 0
                • E
                  eskild
                  last edited by Dec 29, 2014, 6:55 PM

                  No. I have traffic through 2/7 ph2, but "Active Tunnels" is still 0.

                  1 Reply Last reply Reply Quote 0
                  • R
                    rr2squared
                    last edited by Dec 30, 2014, 3:20 PM

                    Additional information:  tunnels that show as "down" in the widget are all missing the <iketype>tag in config.xml.  These tunnels were all created on earlier versions of pfSense and migrated during the router upgrade.  Manually setting iketype to ikev1 below <ikeid>resolves the widget problem.

                    I can't tell you exactly what release originally created the config.xml entries, since my backups don't go back that far, but it seems like the migration process ought to check for missing <iketype>and set it to ikev1 if missing.</iketype></ikeid></iketype>

                    1 Reply Last reply Reply Quote 0
                    • P
                      phil.davis
                      last edited by Dec 30, 2014, 5:40 PM Dec 30, 2014, 4:35 PM

                      https://github.com/pfsense/pfsense/pull/1412
                      Maybe this pull request will help - it allows for iketype being empty, similar to what is already done in other places like /usr/local/www/vpn_ipsec.php and /etc/inc/vpn.inc
                      Try the 1-line change to the if test there and confirm if it makes it work.

                      Edit add:
                      It also looks like there would be a problem on Status->IPsec disconnect/connect button for those entries with no iketype.
                      https://github.com/pfsense/pfsense/pull/1413
                      Can you also confirm if that is a problem, and if this pull request fixes it?

                      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                      1 Reply Last reply Reply Quote 0
                      • J
                        jimp Rebel Alliance Developer Netgate
                        last edited by Dec 30, 2014, 5:51 PM

                        Given that we'd probably be better off with some upgrade code to explicitly set the iketype on upgrade so it isn't ever undefined, too.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • P
                          phil.davis
                          last edited by Dec 30, 2014, 6:04 PM

                          @jimp:

                          Given that we'd probably be better off with some upgrade code to explicitly set the iketype on upgrade so it isn't ever undefined, too.

                          Yes, there are already a few places in the code that treat empty iketype as ikev1, thus working with the old configs. A search for "iketype" turned up the 2 places above that did not handle the empty iketype case.

                          But it is nice that the config explicitly specifies things like this, because in 10 years when there is IKEv1,2,3,4… people will be a little confused by an ancient config with no iketype specified, and it saves future new code having to remember to handle the empty case.

                          As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                          If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            [[user:consent.lead]]
                            [[user:consent.not_received]]