Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Packets in But Not Out

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 489 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MeCJay12
      last edited by

      Hello! I have a route that I'm building up from scratch in a VM. I'm setting up an IPsec tunnel (VTI) from an existing router to the new router. I setup the two phases on both sides and the tunnel comes up but the new router doesn't send traffic. So far I have tried pfSense 2.4.4p3, 2.4.5p1, rebuilding the tunnels, and rebooting. I've had this issue before but never found the problem it just sometimes fixes itself. I'm using Vultr if it makes a difference.

      IPsec_No_Traffic.png

      1 Reply Last reply Reply Quote 0
      • JeGrJ
        JeGr LAYER 8 Moderator
        last edited by

        If you set it up to use VTI (and a transfer network) you have to setup your routes via System/Routing for yourself. Did you do that?

        Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 0
        • M
          MeCJay12
          last edited by MeCJay12

          Right. The plan is to use FRR to distribute routes but auto ping can't get through so we aren't to that point yet. The packets in here are the auto ping from the old router and there should be packets out for the auto ping in the other direction. If I add FRR now the neighbor adjacency doesn't form. Setting up FRR, I can see pings and the OSPF hello packets coming in on the new router (on the IPsec interface not the tunnel specific interface) and on the old router I can see the pings and hellos flowing out (from the tunnel specific interface) but nothing in response. I think this is a pfSense bug but I don't know how to fix it.

          1 Reply Last reply Reply Quote 0
          • JeGrJ
            JeGr LAYER 8 Moderator
            last edited by

            AFAIR, there were already multiple posts from people using FRR / OSPF with VTI interfaces but sadly I ain't one of them. Only have FRR/OSPF running cleanly with a OVPN shared key /30 tunnel and that works like a charm!

            Perhaps @jimp or someone more experimental can help :)

            Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            1 Reply Last reply Reply Quote 0
            • M
              MeCJay12
              last edited by

              This shouldn't be an issue with OSPF/FRR. I'm having this issue prior to even installing FRR. The tunnel being up generates traffic that should be showing.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.