Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Your documentation and wiki are broken.

    IPsec
    4
    8
    3.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      joako
      last edited by

      I tried to setup pfSense-to-pfSense IPSEC VPN. For almost a week I kept on re-configuring it, deleting, reinstalling, checking and re-checking. Everything i could think of, because "when you follow the 'official' instructions on a stock/default system 'it has to work', no?"

      Well turns out the instructions here are flawed: http://doc.pfsense.org/index.php/VPN_Capability_IPSec

      The VPN tunnel will not respond to firewall rules at the time of this writing, so you will not be able to limit which hosts can be accessed by users across the VPN connection. If a worm would get into the network you are connected to via VPN, it could easily spread to your network. If a system on the remote network is compromised by an attacker, he could easily hop over the VPN to attack your systems without any firewall protection.

      That is ENTIRELY WRONG! Not only do the IPSEC VPN respond to firewall rules, by default there is none. The only issue with my configuration was that there was no firewall rulle (under Firewall -> Rules -> IPSEC) to pass traffic. Setup the rule and bang it all works.

      I try to edit the wiki page to add the firewall rules information but there is no way to register on the page and my forum login does not work there.

      1 Reply Last reply Reply Quote 0
      • J
        joako
        last edited by

        Anyone? The documentation is still wrong. I will gladly update it if I can login to the wiki…

        1 Reply Last reply Reply Quote 0
        • R
          ryall
          last edited by

          I agree, this is a major hurdle for people to stumble upon.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            I wasn't aware that documentation was so far out of date. I fixed that reference, and will need to go over it in finer detail soon.

            Thanks for the heads-up.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • F
              focalguy
              last edited by

              Yea, thanks for bringing it up! I know I ran into that but I think I forgot where I read that when I finally figured out I did need some rules.

              1 Reply Last reply Reply Quote 0
              • R
                ryall
                last edited by

                Thanks jimp  ;D

                I think most people would jump to the firewall rules when things didn't work, but the docs were a bit misleading. Anyway, much appreciated to all you guys contributing to this awesome project!

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  A little late, but better late than never:

                  I rewrote the core of that IPSec document to be more in line with the current options and configuration. I hope it's a little easier to read now, too.

                  It had a lot of references to material that was not in that document. I'm not sure if it was copied and pasted from somewhere else or if it was just left unfinished.

                  It may still need a little more work, so suggestions are welcome.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • F
                    focalguy
                    last edited by

                    @jimp:

                    A little late, but better late than never:

                    Yup!

                    I read over it briefly. It looks good to me. It's been a while since I set it up from scratch and maybe some things have changed since 1.2.2 but everything seems to be there.

                    Thanks for updating.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.