Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Make Before Break - Which Firewalls Support it

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      paraffin
      last edited by

      Hi

      I run PFSense and have always been worried about enabling make-before-break on IKEV2 IPSEC VPN's as the warning is that the other endpoint must support it otherwise there could be issues.

      I do not generally control the other side of the VPN and would like to use this feature but it's hard to judge if the other side does support it, looking for make-before-break details on Google for Palo Alto or Checkpoint doesn't yield any results, are these firewalls using different terminology?

      If anyone has any detail or can point me at the terminology to google that would be fantastic.

      Cheers everyone

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        I'm not aware of any list, but if you are using IKEv2, you are better off switching to Rekey instead of using Reauth+Make-before-break. On 2.4.x, uncheck Disable Rekey and check Disable Reauth. On 2.5.0, put the lifetime value in the rekey box and leave reauth empty.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.