Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ikev2 with ipsec but client side internet is not working

    Scheduled Pinned Locked Moved IPsec
    9 Posts 3 Posters 805 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      prasanth
      last edited by

      I have configured Ikev2 VPN with IPSec on pfsense firewall and configured client setup on the client machine as well, It getting connected successfully. But no internet access on the client machine. Please, anyone, Suggest what I need to do further?

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Look at your phase 2 settings.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 1
        • P
          prasanth
          last edited by

          This is my Phase 2 settings, Is there anything i need to change? for client can access the Internet ?
          phase2.PNG

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            That looks fine, it was the 0.0.0.0 that people sometimes miss.

            Do you have any rules on the IPsec interface ?

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • P
              prasanth
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • P
                prasanth
                last edited by prasanth

                Sorry, This is my firewall rule under the IPsec. (If I configured multiple WAN, client machine got the access to the internet). So I need it can work with Single WAN

                Inkedipsec_LI.jpg

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  What client?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • P
                    prasanth
                    last edited by

                    Windows 10 machine, Not using any third-party software.

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      The client decides what traffic to send over. I think there's a checkbox in the VPN settings. Some people use powershell.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.