Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec

    IPsec
    3
    4
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rkuo
      last edited by

      Using Cisco IPSec for VPN under OS X or iOS, DNS server settings are no longer being handled properly by the client.  This was working properly in 2.1, but in 2.2 something broke.  Oddly, I can see the server settings in the VPN on OS X, but it seems not to send lookups for the domain to the configured DNS server.

      The other odd thing is that with scutil –dns, the search domains are "my.domain.comp", not "my.domain.com".  That's definitely weird.

      1 Reply Last reply Reply Quote 0
      • E
        eri--
        last edited by

        Check the RELEASE notes on the phase2 setting for mobile clients.
        Probably your dns servers are not in the phase2 definition.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          check /var/etc/ipsec/strongswan.conf for what it's setting. Should be something like:

          # Search domain and default domain
          			28674 = example.com
          			28675 = example.com
          

          The problem with DNS server reachability is probably with Ermal noted, the P2 local network in strongswan is strictly enforced where racoon may not have.

          1 Reply Last reply Reply Quote 0
          • R
            rkuo
            last edited by

            Thanks all.  I do have DNS set in phase 2.  It simply does not work.

            See https://forum.pfsense.org/index.php?topic=88226.0 for an identical example with more thorough logs.

            I suspect a possible migration or upgrade issue, but I would need to find the time to do a clean install.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.