Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec Phase 1 and Phase 2 connected but no routing to tunnel

    Scheduled Pinned Locked Moved IPsec
    6 Posts 2 Posters 837 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      Greyhat
      last edited by

      I have established a IPsec to a Fortigate machine. The tunnel reports up and the SADs also report as up. SPDs are shown correctly. But traffic is not routed to the tunnel but to the default route.
      With opther IPsec Tunnels (to pfSense ans SonicWall) the problem does not exist.
      Is there any way to debug the creation of the kernel routs as the routes to IPsec do not appear in the routing tables.
      The only (possible) problem I identified is a spradic error message "IKE_SA checkout not successful"
      Any ideas welcome
      GreyHat

      1 Reply Last reply Reply Quote 0
      • G Offline
        Greyhat
        last edited by

        Further investigations show that it is not a problem of the fortigate as communications partner.
        I set up a tunnel with identical seetings to another pfSense and the effect war the same.
        The pfSense in question is a team with 2 pfs. I setup the tunnel on the fallback pfSense and it worked immediately. Including routing etc..
        So on a pfSense 2.4.4.p3 with8 GB memory 3 static tunnels with a total of 7 SAs (plus IPsec for mobile) it works fine.
        If anther tunnel with 1 SA is established the routing failes. Is this a problem of some table size?

        1 Reply Last reply Reply Quote 0
        • G Offline
          Greyhat
          last edited by

          Anybody any experience with a significant number of Tunnels and SAs?

          1 Reply Last reply Reply Quote 0
          • G Offline
            Greyhat
            last edited by

            Nobody ever tried to use more than 3 tunnels with 7 security associations?

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              Many, many, many people. Some have hundreds.

              The number of tunnels is a red herring.

              Chances are, your answer lies in the IPsec logs. With the information provided that is the best I can do.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • G Offline
                Greyhat
                last edited by

                I thought so, there have to be installations with many SAs.
                But who really knows. I transferred the settings to an alternative firewall and the tunnel was established immediately and the routing worked. I will try to reconstruct the problem and post the logs

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.