Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Manual SAD disconnect required if internet connection hiccups

    IPsec
    2
    9
    4908
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kapara last edited by

      If the pfSense reboots…the Cisco VPN concentrator can re-establish the connection but if the Cisco VPN Concentrator reboots I have to manually disconnect the 2 SAD's for the VPN tunnel in order to get it to re-establish connectivity.  Is there a way to have it reset automatically after a specified amount of time like a timeout?  Cron job?  Any suggestions would be helpful.  Running 1.2.2 on Alix Box from Netgate.

      Thanks,

      Mark

      Skype ID:  Marinhd

      1 Reply Last reply Reply Quote 0
      • K
        kapara last edited by

        Using:  ESP  3des-cbc  hmac-sha1

        Skype ID:  Marinhd

        1 Reply Last reply Reply Quote 0
        • jimp
          jimp Rebel Alliance Developer Netgate last edited by

          What does your IPSec log show for the failed/failing connections?

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • K
            kapara last edited by

            Will force a failure and report back.  Also read that Dead Peer Detection is not a feature in the current build 1.2.2 and that a PHP script needs to be modified.  I will also post my configs incase I am missing something.  I read somewhere about the PF key needing to be 2 but that was also at 3 AM…kinda burry by then.

            Skype ID:  Marinhd

            1 Reply Last reply Reply Quote 0
            • K
              kapara last edited by

              Here is the pfsense config.  Cisco config will follow.




              Skype ID:  Marinhd

              1 Reply Last reply Reply Quote 0
              • K
                kapara last edited by

                Here is Cisco.  IKE and SA details to follow.


                Skype ID:  Marinhd

                1 Reply Last reply Reply Quote 0
                • K
                  kapara last edited by

                  Here is IKE and SA




                  Skype ID:  Marinhd

                  1 Reply Last reply Reply Quote 0
                  • K
                    kapara last edited by

                    The IPSEC log does not show anything after I reboot the other firewall.  Only when I delete the SAD entries does it come back.  I found this post but I am hestant to start playing with the code.  Is the following article the only way to deal with this type of issue?

                    http://forum.pfsense.org/index.php/topic,10371.0.html

                    Skype ID:  Marinhd

                    1 Reply Last reply Reply Quote 0
                    • K
                      kapara last edited by

                      Tried the suggestion and modified the vpn.inc file but it still is unable to bring the tunnel back up.

                      Skype ID:  Marinhd

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post