Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] IPSEC up but no traffic?

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chichin79
      last edited by

      Hello, just setup my first IPSEC tunnel and everything (I think) shows that it's up.

      I'm running latest version of pfsense, 2.3.2

      Under Status /IPsec /Overview it says "Established"

      Logs:

      Aug 12 09:34:21 charon 16[NET] <con1|4>received packet: from xx.xxx.xxx.xx[500] to xxx.xxx..xxx.x[500] (80 bytes)
      Aug 12 09:34:21 charon 16[ENC] <con1|4>parsed INFORMATIONAL response 818 [ ]
      Aug 12 09:34:31 charon 16[IKE] <con1|4>sending DPD request
      Aug 12 09:34:31 charon 16[ENC] <con1|4>generating INFORMATIONAL request 819 [ ]
      Aug 12 09:34:31 charon 16[NET] <con1|4>sending packet: from xxx.xxx.xx.xx[500] to xxx.xxx.xxx.xx[500] (80 bytes)
      Aug 12 09:34:31 charon 16[NET] <con1|4>received packet: from xxx.xx.xxx.xx[500] to xxx.xxx.xxx.xx[500] (80 bytes)
      Aug 12 09:34:31 charon 16[ENC] <con1|4>parsed INFORMATIONAL response 819 [ ]
      Aug 12 09:34:41 charon 12[IKE] <con1|4>sending DPD request
      Aug 12 09:34:41 charon 12[ENC] <con1|4>generating INFORMATIONAL request 820 [ ]

      I have opend up for IPSEC interface in firewall settings.

      The only thing i can find that for me seams strange is under:

      Status /IPsec /Leases

      It says "No IPsec pools"

      Settings for IPsec identical on both sides:

      Authentication Method / Mutual PSK

      Negotiation mode / Main

      My identifier / My IP adress

      Peer identifier / Peer IP adress

      Encryption Algorithm / AES 256

      Hash Algorithm / SHA256

      DH Group / 2 (1024)

      Lifetime seconds / 86400

      Phase two

      AES 256
      SHA1

      Under Phase two I have routed Servernetwork here at home in the settings on the other site. And here at home I have enterd the servernetwork subnet to route.

      Anyone have some suggestions I can try to get it working??

      SOLVED

      Forgot to let ICMP packets through firewall…</con1|4></con1|4></con1|4></con1|4></con1|4></con1|4></con1|4></con1|4></con1|4>

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.