Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Mobile IPsec works only on second try

    IPsec
    1
    1
    31
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marcol last edited by

      Hi,
      we are currently running two pfSenses SG-4860 wit HA-sync and have mobile IPsec configured on it. Since we thought using the integrated IPsec client in Windows would be nice, we also configured radius-authentication towards our AD in addition to the certificate based authentication on pfSense.
      We are experiencing a strange behaviour though, when connecting to the VPN. The first time you connect it all looks good, but no traffic is flowing. After some research I found out that actually two P2 tunnels get created, one with PFS and one without. After disconnecting and connecting the VPN, this behaviour is not shown and the tunnel works fine. The behaviour reappears after restarting the Client (Win 10 or Win 7 does not matter) or disabling and re-enabling wifi for example. The connection was created using Powershell and adding the "use windows-credentials" parameter afterwards, since it does not accept it when creating IKEv2 tunnels with Powershell.

      I've attached three screenshots where you can see the creation of the connection and the two P2s getting created.

      Connection with the error happening:
      Screenshot_P1_P2.jpg
      Log_m_Fehler_part1.jpg
      Log_m_Fehler_part2.jpg

      Connection without the error:
      Log_o_Fehler.jpg

      Any suggestions how he may mitigate this error?

      Thanks in advance

      Marco

      1 Reply Last reply Reply Quote 0
      • First post
        Last post