Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec configuration files lost after reboot.

    Scheduled Pinned Locked Moved IPsec
    27 Posts 4 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      You don't need to start IPsec from the CLI. pfSense will start the IPsec service on its own if you have everything setup and enabled properly.

      You are most likely not passing the correct set of parameters for it to read the correct configuration.

      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A
        artemis
        last edited by

        Ok so how can i ensure that i have setup it correctly and it will be able to start the service its own.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Use the GUI to set it up, and have at least one enabled P1+P2, the rest should happen naturally.

          Unless you are making manual modifications or trying to do something the GUI doesn't support, you shouldn't have to take any special steps here.

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • A
            artemis
            last edited by

            But the configuration came from the gui. Enabling mobile clients phase 1 + phase 2 and last l2tp. Thats it. When i am restarting the vm i issue the command ipsec status and nothing is appear. Clearly something is worng.

            K 1 Reply Last reply Reply Quote 0
            • K
              Konstanti @artemis
              last edited by

              @artemis Hay
              To help you answer the questions
              Sorry for my English

              1. during PF booting there is a message "Configuring IPsec VPN...done" ?
              2. After booting there is in the /var/etc/ipsec/ file strongswan.conf ?
              3. IFCONFIG shows that there is an enc0 interface after booting?
              1 Reply Last reply Reply Quote 0
              • A
                artemis
                last edited by

                @Konstanti Hello and thank you for your reply.

                1. It shows that the IPsec VTI interface is done( Nothing about IPsec VPN and i saw the L2TP vpn configured ok)
                  2)There is no ipsec folder inside etc :( (It shows the l2tp but not the ipsec)
                  3)Yes there is an enc0 after booting.
                K 1 Reply Last reply Reply Quote 0
                • K
                  Konstanti @artemis
                  last edited by

                  @artemis enc0 UP or DOWN ?? after booting
                  0_1545391810670_f6bc823d-88d8-41fe-9ed3-f4e0708ea69f-image.png

                  1 Reply Last reply Reply Quote 0
                  • A
                    artemis
                    last edited by

                    It seems to be down.

                    K 1 Reply Last reply Reply Quote 0
                    • K
                      Konstanti @artemis
                      last edited by

                      @artemis This means that IPSEC is not enabled at boot time

                      Or missing phase 1
                      Or phase 1 is disabled

                      K 1 Reply Last reply Reply Quote 0
                      • A
                        artemis
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • K
                          Konstanti @Konstanti
                          last edited by Konstanti

                          @konstanti Try to set IKEV2without the l2tp/IPSEC
                          From the documentation
                          We strongly recommend using another solution such as IKEv2 instead of L2TP/IPsec.

                          1 Reply Last reply Reply Quote 0
                          • A
                            artemis
                            last edited by

                            0_1545392899865_Capture.PNG

                            K 3 Replies Last reply Reply Quote 0
                            • K
                              Konstanti @artemis
                              last edited by

                              @artemis Unfortunately, nothing is visible

                              1 Reply Last reply Reply Quote 0
                              • K
                                Konstanti @artemis
                                last edited by

                                @artemis https://www.netgate.com/docs/pfsense/book/ipsec/mobile-ipsec.html

                                1 Reply Last reply Reply Quote 0
                                • A
                                  artemis
                                  last edited by

                                  Ok. To describe it, am showing you that the phase1 is enabled from the gui and the interface is not up.

                                  K 1 Reply Last reply Reply Quote 0
                                  • K
                                    Konstanti @artemis
                                    last edited by Konstanti

                                    @artemis
                                    When booting the PF checks whether it is enabled to initialize IPSEC
                                    If not , enc0 set to down
                                    And files strongswan.conf, ipsec.conf,..... not created

                                    Try to configure access using IKEV2 without l2tp

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      artemis
                                      last edited by

                                      Ok how can i say to my pfsense to check the IPsec on the boot, because as i told you before it doesnt check it. My remote hosts do not support ikev2

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        Konstanti @artemis
                                        last edited by Konstanti

                                        @artemis he picture shows that phase 1 is disabled from gui (your configuration)
                                        Phase 1 is enabled (my configuration)
                                        0_1545394017218_8cfc48e2-ffaa-4b18-adf5-3f2af7ee8663-image.png

                                        0_1545394169959_828ded07-bbe7-408c-8b02-9bae37fc05b6-image.png

                                        1 Reply Last reply Reply Quote 0
                                        • A
                                          artemis
                                          last edited by

                                          Right now i am feeling that i want to dig a hole and put myself in. I thought that green (Enabled) was the status of the phase 1. Omg and the worst part is that i am a network engineer(CCNP). OMG. Thank you very much.

                                          GrimsonG K 2 Replies Last reply Reply Quote 0
                                          • GrimsonG
                                            Grimson Banned @artemis
                                            last edited by

                                            @artemis said in IPsec configuration files lost after reboot.:

                                            I thought that green (Enabled) was the status of the phase 1.

                                            There is a big difference between Enable and Enabled.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.