Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Version 2.4.1 Breaks IPsec Status Screen ?

    Scheduled Pinned Locked Moved IPsec
    4 Posts 3 Posters 814 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      barnettd
      last edited by

      I updated to 2.4.1 on an SG-2440 with a dual wan failover config, and am no longer able to connect or disconnect IPsec tunnels. This was a critical function as IPsec does not seem to rebuild on the active WAN in a tiered failover config after a wan failure.

      In the attached screenshot the IPsec status page now shows 2 entries for the same tunnel using the local IP for each WAN interface. Clicking Show child SA entries, Disconnect, or Connect VPN all have no effect.

      I thought it might be a cache or browser issue, but its the same in IE, Chrome, and Firefox. Anyone else experiencing this?
      ![2.4.1 IPsec Status Screen.PNG](/public/imported_attachments/1/2.4.1 IPsec Status Screen.PNG)
      ![2.4.1 IPsec Status Screen.PNG_thumb](/public/imported_attachments/1/2.4.1 IPsec Status Screen.PNG_thumb)

      1 Reply Last reply Reply Quote 0
      • W
        wickeren
        last edited by

        Yup, see my post here:
        https://forum.pfsense.org/index.php?topic=138775.0

        1 Reply Last reply Reply Quote 0
        • B
          barnettd
          last edited by

          Wow, bummer :(
          Glad I haven't updated any production boxes, guess we just have to wait for the fix.

          I did some quick testing on the WAN failover. It seems that now if a tier goes down, the IPsec tunnel can be rebuilt by clicking the stop service button, and then starting it back up a few seconds later.

          1 Reply Last reply Reply Quote 0
          • ExordiumE
            Exordium
            last edited by

            @barnettd:

            I thought it might be a cache or browser issue, but its the same in IE, Chrome, and Firefox. Anyone else experiencing this?

            Confirmed. -> https://forum.pfsense.org/index.php?topic=139163.0

            - pfSense Gold Subscriber -

            Sense 1: Shuttle DS57U3 (private)
            Sense 2: Supermicro Atom Barebone (Company Test)
            Sense 3 : 2 x Supermicro SYS-5018D-FN8T (Company Office)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.