Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec dropping

    Scheduled Pinned Locked Moved IPsec
    3 Posts 3 Posters 1.4k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jvangent100
      last edited by

      Hi,

      I have an IPsec tunnel between my PFsense and a Cisco ASA, that has worked absolutely fine for the last six months. About two weeks ago PFsense was updated using the webinterface to 2.4.4-RELEASE-p1 and since then the previously rock solid connection is dropping whilst I am actively working on systems behind the Cisco Asa. When I run a persistent ping, I see it periodicly dropping pings, and in such a way that RDP session drop. Now before the update to 2.4.4 P1 this literally never happened. The fiber connection on which I run the tunnel is never down, the ASA hasn't been changed, and also PFsense tunnel definition hasn't been changed, so that leaves this update.

      I noticed there is an update available, but the release note do not mention anything related to IPsec.

      To be honest, this problem is pretty major, as it prevents me from actually working, without periodic hickups and lost RDP session, so if the new update doesn't fix this, is there a way to downgrade ?

      1 Reply Last reply Reply Quote 0
      • M Offline
        mountainlion
        last edited by

        I too have intermittent IPSEC issues. Mine are related to VTI and BGP. But WHENEVER I have a BGP issues, I look at the "IPSEC status" and I see multiple "IPSEC ID's".
        Sometime, disconnected the "old" IDs works, sometimes not.
        A TS guide would be helpful.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          You mean like this?

          https://www.netgate.com/docs/pfsense/vpn/ipsec/ipsec-troubleshooting.html

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.