<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC Changes Require Reboot]]></title><description><![CDATA[<p dir="auto">Any changes to an IPSEC tunnel requires a reboot to take effect.  Why?</p>
<p dir="auto">System Netgate SG-2440<br />
BIOS Vendor: coreboot<br />
Version: ADI_RCCVE-01.00.00.12-nodebug<br />
Version 2.3.4-RELEASE-p1 (amd64)<br />
built on Fri Jul 14 14:52:43 CDT 2017<br />
FreeBSD 10.3-RELEASE-p19</p>
]]></description><link>https://forum.netgate.com/topic/120714/ipsec-changes-require-reboot</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 13:16:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/120714.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 Sep 2017 12:15:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC Changes Require Reboot on Thu, 28 Sep 2017 21:10:09 GMT]]></title><description><![CDATA[<p dir="auto">Nothing special about them, just adding another host or network to the tunnel.  I haven't stopped and started the IPSEC service, just used the icon that shows restart service.  We'll try that.</p>
<p dir="auto">This config has been running around 7 years and this behavior started around 2 years ago.</p>
]]></description><link>https://forum.netgate.com/post/724322</link><guid isPermaLink="true">https://forum.netgate.com/post/724322</guid><dc:creator><![CDATA[khancock]]></dc:creator><pubDate>Thu, 28 Sep 2017 21:10:09 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC Changes Require Reboot on Thu, 28 Sep 2017 15:37:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khancock">@<bdi>khancock</bdi></a>:</p>
<blockquote>
<p dir="auto">If I add another Phase 2 entry I have to reboot.</p>
</blockquote>
<p dir="auto">I make P2 changes all the time and they take effect when expected, you'll have to be more specific. Do these new P2s get added to only a single tunnel? Do they overlap anything else? Anything special about them?</p>
<p dir="auto">Since this doesn't appear to be happening to anyone else, there must be something distinct about your setup that is triggering the behavior</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khancock">@<bdi>khancock</bdi></a>:</p>
<blockquote>
<p dir="auto">I tried to restart just IPSEC but it does not work</p>
</blockquote>
<p dir="auto">Did you use the "restart" button or did you actually stop and then start the service as I suggested? A restart doesn't restart IPsec, it only tells strongSwan to reload the configuration file.</p>
]]></description><link>https://forum.netgate.com/post/724233</link><guid isPermaLink="true">https://forum.netgate.com/post/724233</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Thu, 28 Sep 2017 15:37:55 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC Changes Require Reboot on Wed, 27 Sep 2017 22:44:03 GMT]]></title><description><![CDATA[<p dir="auto">If I add another Phase 2 entry I have to reboot.  I tried to restart just IPSEC but it does not work.  I thought this was due to old hardware so I upgraded to NetGate and the problem persists.</p>
]]></description><link>https://forum.netgate.com/post/724084</link><guid isPermaLink="true">https://forum.netgate.com/post/724084</guid><dc:creator><![CDATA[khancock]]></dc:creator><pubDate>Wed, 27 Sep 2017 22:44:03 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC Changes Require Reboot on Wed, 27 Sep 2017 15:20:21 GMT]]></title><description><![CDATA[<p dir="auto">What changes, specifically? I haven't ever seen that happen that I can recall.</p>
<p dir="auto">Next time, instead of a reboot, if the changes do not apply then go to Status &gt; Services and stop the IPsec service and then start it again. Do not use the restart button.</p>
]]></description><link>https://forum.netgate.com/post/724007</link><guid isPermaLink="true">https://forum.netgate.com/post/724007</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 27 Sep 2017 15:20:21 GMT</pubDate></item></channel></rss>