• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPsec configuration files lost after reboot.

Scheduled Pinned Locked Moved IPsec
27 Posts 4 Posters 6.3k Views 3 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J Offline
    jimp Rebel Alliance Developer Netgate
    last edited by Dec 20, 2018, 2:52 PM

    pfSense puts the IPsec config in /var/etc/ipsec/. It shouldn't be looking in /usr/local/etc for anything.

    Are you starting it manually or with a custom script?

    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

    Need help fast? Netgate Global Support!

    Do not Chat/PM for help!

    1 Reply Last reply Reply Quote 1
    • A Offline
      artemis
      last edited by Dec 20, 2018, 2:58 PM

      Hello and thank you for you reply. From the Status->Systems Logs->IPsec there are these errors

      Dec 20 10:41:40 ipsec_starter 64519 Starting strongSwan 5.7.1 IPsec [starter]...
      Dec 20 10:41:40 ipsec_starter 64519 no files found matching '/usr/local/etc/ipsec.conf'
      Dec 20 10:41:40 ipsec_starter 64519 failed to open config file '/usr/local/etc/ipsec.conf'
      Dec 20 10:41:40 ipsec_starter 64519 unable to start strongSwan -- fatal errors in config

      When i try to start from the cli ipsec start these errors are coming up.

      no files found matching '/usr/local/etc/strongswan.conf'
      abort initialization due to invalid configuration
      Starting strongSwan 5.7.1 IPsec [starter]...
      no files found matching '/usr/local/etc/ipsec.conf'
      failed to open config file '/usr/local/etc/ipsec.conf'
      unable to start strongSwan -- fatal errors in config

      After i disable and enable phase 1 and phase 2 the configuration are creating and everything is ok. When i reboot the vm the configs are missing.
      Thank you very much

      1 Reply Last reply Reply Quote 0
      • J Offline
        jimp Rebel Alliance Developer Netgate
        last edited by Dec 20, 2018, 3:10 PM

        You don't need to start IPsec from the CLI. pfSense will start the IPsec service on its own if you have everything setup and enabled properly.

        You are most likely not passing the correct set of parameters for it to read the correct configuration.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • A Offline
          artemis
          last edited by Dec 20, 2018, 3:12 PM

          Ok so how can i ensure that i have setup it correctly and it will be able to start the service its own.

          1 Reply Last reply Reply Quote 0
          • J Offline
            jimp Rebel Alliance Developer Netgate
            last edited by Dec 20, 2018, 3:14 PM

            Use the GUI to set it up, and have at least one enabled P1+P2, the rest should happen naturally.

            Unless you are making manual modifications or trying to do something the GUI doesn't support, you shouldn't have to take any special steps here.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • A Offline
              artemis
              last edited by Dec 20, 2018, 3:16 PM

              But the configuration came from the gui. Enabling mobile clients phase 1 + phase 2 and last l2tp. Thats it. When i am restarting the vm i issue the command ipsec status and nothing is appear. Clearly something is worng.

              K 1 Reply Last reply Dec 21, 2018, 8:21 AM Reply Quote 0
              • K Offline
                Konstanti @artemis
                last edited by Dec 21, 2018, 8:21 AM

                @artemis Hay
                To help you answer the questions
                Sorry for my English

                1. during PF booting there is a message "Configuring IPsec VPN...done" ?
                2. After booting there is in the /var/etc/ipsec/ file strongswan.conf ?
                3. IFCONFIG shows that there is an enc0 interface after booting?
                1 Reply Last reply Reply Quote 0
                • A Offline
                  artemis
                  last edited by Dec 21, 2018, 10:35 AM

                  @Konstanti Hello and thank you for your reply.

                  1. It shows that the IPsec VTI interface is done( Nothing about IPsec VPN and i saw the L2TP vpn configured ok)
                    2)There is no ipsec folder inside etc :( (It shows the l2tp but not the ipsec)
                    3)Yes there is an enc0 after booting.
                  K 1 Reply Last reply Dec 21, 2018, 11:32 AM Reply Quote 0
                  • K Offline
                    Konstanti @artemis
                    last edited by Dec 21, 2018, 11:32 AM

                    @artemis enc0 UP or DOWN ?? after booting
                    0_1545391810670_f6bc823d-88d8-41fe-9ed3-f4e0708ea69f-image.png

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      artemis
                      last edited by Dec 21, 2018, 11:41 AM

                      It seems to be down.

                      K 1 Reply Last reply Dec 21, 2018, 11:45 AM Reply Quote 0
                      • K Offline
                        Konstanti @artemis
                        last edited by Dec 21, 2018, 11:45 AM

                        @artemis This means that IPSEC is not enabled at boot time

                        Or missing phase 1
                        Or phase 1 is disabled

                        K 1 Reply Last reply Dec 21, 2018, 11:50 AM Reply Quote 0
                        • A Offline
                          artemis
                          last edited by Dec 21, 2018, 11:47 AM

                          This post is deleted!
                          1 Reply Last reply Reply Quote 0
                          • K Offline
                            Konstanti @Konstanti
                            last edited by Konstanti Dec 21, 2018, 11:51 AM Dec 21, 2018, 11:50 AM

                            @konstanti Try to set IKEV2without the l2tp/IPSEC
                            From the documentation
                            We strongly recommend using another solution such as IKEv2 instead of L2TP/IPsec.

                            1 Reply Last reply Reply Quote 0
                            • A Offline
                              artemis
                              last edited by Dec 21, 2018, 11:50 AM

                              0_1545392899865_Capture.PNG

                              K 3 Replies Last reply Dec 21, 2018, 11:52 AM Reply Quote 0
                              • K Offline
                                Konstanti @artemis
                                last edited by Dec 21, 2018, 11:52 AM

                                @artemis Unfortunately, nothing is visible

                                1 Reply Last reply Reply Quote 0
                                • K Offline
                                  Konstanti @artemis
                                  last edited by Dec 21, 2018, 11:53 AM

                                  @artemis https://www.netgate.com/docs/pfsense/book/ipsec/mobile-ipsec.html

                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    artemis
                                    last edited by Dec 21, 2018, 11:54 AM

                                    Ok. To describe it, am showing you that the phase1 is enabled from the gui and the interface is not up.

                                    K 1 Reply Last reply Dec 21, 2018, 11:58 AM Reply Quote 0
                                    • K Offline
                                      Konstanti @artemis
                                      last edited by Konstanti Dec 21, 2018, 11:59 AM Dec 21, 2018, 11:58 AM

                                      @artemis
                                      When booting the PF checks whether it is enabled to initialize IPSEC
                                      If not , enc0 set to down
                                      And files strongswan.conf, ipsec.conf,..... not created

                                      Try to configure access using IKEV2 without l2tp

                                      1 Reply Last reply Reply Quote 0
                                      • A Offline
                                        artemis
                                        last edited by Dec 21, 2018, 12:05 PM

                                        Ok how can i say to my pfsense to check the IPsec on the boot, because as i told you before it doesnt check it. My remote hosts do not support ikev2

                                        1 Reply Last reply Reply Quote 0
                                        • K Offline
                                          Konstanti @artemis
                                          last edited by Konstanti Dec 21, 2018, 12:09 PM Dec 21, 2018, 12:05 PM

                                          @artemis he picture shows that phase 1 is disabled from gui (your configuration)
                                          Phase 1 is enabled (my configuration)
                                          0_1545394017218_8cfc48e2-ffaa-4b18-adf5-3f2af7ee8663-image.png

                                          0_1545394169959_828ded07-bbe7-408c-8b02-9bae37fc05b6-image.png

                                          1 Reply Last reply Reply Quote 0
                                          21 out of 27
                                          • First post
                                            21/27
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received