Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PSKs incorrect in ipsec.secrets - Still an Issue in 2.2.1

    Scheduled Pinned Locked Moved IPsec
    12 Posts 2 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cmb
      last edited by

      That's not the same issue for sure. The only gotcha I see there is editing the user doesn't immediately update the ipsec.secrets, you have to go to VPN>IPsec and hit Save.

      You mentioned email, the username is actually what gets put into ipsec.secrets, there is no email associated with user accounts. If you just use your username, I'm guessing it'll work. They are put in there correctly.

      1 Reply Last reply Reply Quote 0
      • A
        anomaly0617
        last edited by

        @cmb:

        That's not the same issue for sure. The only gotcha I see there is editing the user doesn't immediately update the ipsec.secrets, you have to go to VPN>IPsec and hit Save.

        You mentioned email, the username is actually what gets put into ipsec.secrets, there is no email associated with user accounts. If you just use your username, I'm guessing it'll work. They are put in there correctly.

        Hi cmb,

        First, thanks for the response!

        I'm aware that email addresses do not necessarily equal user accounts, however many of us do have email accounts out there as the username because of how unique it really is… (I can have 5 dsmiths but only one dsmith@thatdomain.com)

        As a result, this method of setting a username and a PSK has worked from pfSense 1.2.3 on through 2.1.5 or 2.1.6, but as of 2.2 and beyond the @ sign or some other factor that I'm not aware of seems to have broken it.

        So the issue is that in cases where I have 30-50 road warrior users out there with their email address as their username, fixing it would require generating new accounts and touching every device prior to upgrading the firewall. If there's a fix to the problem on the horizon, I'd rather wait for it. :-)

        Hope this Helps!

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          I mis-read that "edit my user" part as meaning users in the user manager. The @ character isn't an accepted username for the user manager, and never has been. You're actually using the VPN>IPsec, PSK tab, where emails are fine. What you're describing should work, I'll double check that with the Shrew Soft config you're showing when I have a moment.

          1 Reply Last reply Reply Quote 0
          • A
            anomaly0617
            last edited by

            @cmb:

            I mis-read that "edit my user" part as meaning users in the user manager. The @ character isn't an accepted username for the user manager, and never has been. You're actually using the VPN>IPsec, PSK tab, where emails are fine. What you're describing should work, I'll double check that with the Shrew Soft config you're showing when I have a moment.

            Cool. Thanks, cmb! PM me if you need access to a test firewall. I can easily make one available to you.

            Hope this Helps!

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              Could you re-test this on 2.2.3? Snapshots available at https://snapshots.pfsense.org. I don't see any issues here.

              1 Reply Last reply Reply Quote 0
              • A
                anomaly0617
                last edited by

                Sure, I'll test-upgrade a firewall over the weekend and see if the problem is resolved. :-)

                Hope this Helps!

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  Thanks. I'll be around this weekend, would like to look into it with you if it's still an issue.

                  1 Reply Last reply Reply Quote 0
                  • A
                    anomaly0617
                    last edited by

                    @cmb:

                    Thanks. I'll be around this weekend, would like to look into it with you if it's still an issue.

                    No luck, cmb. I'm going to PM you some remote login details now. :-)

                    Hope this Helps!

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb
                      last edited by

                      The issue was this:
                      https://redmine.pfsense.org/issues/4781

                      it works now. I applied that change to the 2.2.3 system you brought up, and can connect fine now. If you can confirm as well that'd be appreciated.

                      Thanks for your help!

                      1 Reply Last reply Reply Quote 0
                      • A
                        anomaly0617
                        last edited by

                        @cmb:

                        The issue was this:
                        https://redmine.pfsense.org/issues/4781

                        it works now. I applied that change to the 2.2.3 system you brought up, and can connect fine now. If you can confirm as well that'd be appreciated.

                        Thanks for your help!

                        I'll check this afternoon when I make it back to a location I can check it from. Thanks, cmb!

                        Hope this Helps!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.