Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    MAC flapping with ipsec VPN

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tempest
      last edited by

      Hello, I'm new to pfsense and am having an issue with my ipsec VPN.

      I recently upgraded my company's Internet connection in two locations.  I put pfsense routers on both ends, the WAN ports have external IP addresses on the same subnet with the same external gateway.

      I set up a VPN between the two locations and got it functioning.  The other day I noticed temporary drops in both internet connectivity from one of the locations.  These drops would last for a few minutes, then it would come back up and the VPN would reestablish itself.

      Speaking to the ISP, they indicated that what I'm seeing is MAC address flapping - the equipment on both ends is seeing the same MAC address from time to time and it is messing with their MAC forwarding tables.

      The tech indicated that he thought I could make a change to the ipsec connection that would fix the issue, but admitted that he was not familiar enough with ipsec to tell me what that was.  Any ideas?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        IPsec wouldn't have anything to do with that.

        Are you spoofing the MAC for the WAN interface on either side? If you are, remove that from at least one (ideally both), and reboot them to restore the proper MAC address.

        If you are using CARP VIPs on either side, make sure they are using different VHIDs at each location.

        That, or if you had really bad luck and actually got two NICs with the same MAC, are about the only ways that will happen.

        If you aren't spoofing the MAC or using CARP VIPs, check Status > Interfaces on both and see what it says your MAC address is on either side.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.