Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense 2.5 -> IPSec Widgets shows wrong state

    Scheduled Pinned Locked Moved IPsec
    13 Posts 6 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • viktor_gV
      viktor_g Netgate @MarcO42
      last edited by

      @marco42 you need to apply some patches,
      see https://forum.netgate.com/topic/161159/client-ipsec-eap-vpn-does-not-work-after-upgrade-to-2-5release/6

      M P 3 Replies Last reply Reply Quote 1
      • M
        MarcO42 @viktor_g
        last edited by

        @viktor_g Many thx for the hint. This solved my problem with the widget. :) Stay save and healthy:)

        1 Reply Last reply Reply Quote 0
        • P
          peterzy @viktor_g
          last edited by

          @viktor_g

          I can confirm applying patches:

          https://github.com/pfsense/pfsense/commit/95a4e1a0e42392fe4523bf769589f74864446f8c.patch
          https://github.com/pfsense/pfsense/commit/4e5857b656c7bfd59efadbb9a124876a5516c7df.patch

          Solves the problem.

          However, please note that, status pages of both ipsec and openvpn became extremely slow in 2.5 if you have a little more tunnels. In my case around 10 ipsec and around 150 openvpn

          1 Reply Last reply Reply Quote 0
          • M
            MarcO42 @viktor_g
            last edited by

            @viktor_g Hi, I had installed all the patches and it worked .... until I setup another VPN tunnel. now both are shown as offline. :(
            Any ideas?
            Cheers
            Marco

            1 Reply Last reply Reply Quote 0
            • K
              kitdavis @MarcO42
              last edited by kitdavis

              @marco42 I am seeing something similar on the IPSec status page. I have 18 IPSec connections that are all working. However on the status page, 50% of these connections show up twice. First the connection shows up with a blank name but shows there is a connection:
              427f14d7-69fd-46a7-a310-91bbcbc03bc3-image.png

              Then the connection shows up at the bottom of the status screen using the title and shows it is disconnected:
              0ddf545e-83ab-4205-a72d-15e4b1dfab8b-image.png

              1 Reply Last reply Reply Quote 0
              • M
                MarcO42
                last edited by

                Currently I have only one of two connections online but yes. It looks like this:
                ipsecOnline.png ipsecOffline.png

                G 1 Reply Last reply Reply Quote 1
                • G
                  Gianluca 0 @MarcO42
                  last edited by

                  @marco42 same issue. I've got only one Ipsec Vpn displayed correctly, and I don't know why.

                  1 Reply Last reply Reply Quote 0
                  • bingo600B
                    bingo600
                    last edited by

                    On 2.4.5-p1 some of my OpenVPN Status'es also show up as down.
                    Seems to occur after short ouages , but only for some of them.

                    I have added the "Gateway widget" , and trust that instead. You'll get latency time and loss ,as a "Bonus" on the Gateway widget.

                    /Bingo

                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    M 1 Reply Last reply Reply Quote 0
                    • P
                      peterzy
                      last edited by

                      I hope 2.5-p1 will come up soon :)

                      1 Reply Last reply Reply Quote 2
                      • M
                        MarcO42 @bingo600
                        last edited by MarcO42

                        @bingo600 said in PFSense 2.5 -> IPSec Widgets shows wrong state:

                        I have added the "Gateway widget" , and trust that instead. You'll get latency time and loss ,as a "Bonus" on the Gateway widget.

                        Hi Bingo,
                        but how do you get the IPSec conntections to the Gateway widget? I can only see my "Internet Gateways" (IPv4 and IPv6)
                        /Marco

                        bingo600B 1 Reply Last reply Reply Quote 0
                        • bingo600B
                          bingo600 @MarcO42
                          last edited by bingo600

                          @marco42
                          Aren't those Lan to Lan tunnels ?

                          I don't have any IPSec tunnels , only OpenVPN with an interface per tunnel.
                          But I did expect IPSec L2L tunnels to use gateways too. And they would show up there.

                          I might have misunderstood how pfSense handles IPSec L2L

                          /Bingo

                          Edit:
                          Here's how my GW's look , 1 x OpenVPN L2L , and 3 x RoadWarrior servers
                          7ed02e3d-40ab-45a8-8d96-85519ff73c0f-image.png

                          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                          pfSense+ 23.05.1 (ZFS)

                          QOTOM-Q355G4 Quad Lan.
                          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            MarcO42 @bingo600
                            last edited by

                            @bingo600 said in PFSense 2.5 -> IPSec Widgets shows wrong state:

                            Bingo

                            Hi,
                            yes, its a side2side or lan2lan configuration and its not so nicely shown in the Getaway widget.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.