Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Automatically ping host (IPSEC) Don't work

    Scheduled Pinned Locked Moved IPsec
    11 Posts 2 Posters 8.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hoba
      last edited by

      I have some devices out that use that option to always establish the tunnel from the dynamic end towards the static end after IP change and to keep the tunnel up. What IP did you enter as keepalive IP?

      1 Reply Last reply Reply Quote 0
      • M
        martinc_77
        last edited by

        Use the IP deprived of firewall static and also it tries with the IP of a server located behind he himself firewall to which I arrive without problems.

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by

          Please tell me your tunneldefinitions (subnets on each side of the tunnel), the IP you enter as keepalive IP and which interfaces the subnets live on (LAN, OPTx).

          1 Reply Last reply Reply Quote 0
          • M
            martinc_77
            last edited by

            my configuration is the next:

            (192.168.0.1/32)                                                            (192.168.105.1/32)
            LAN SUBNET –------------------ PFSENSE --------------- INET ------------------------ PFSENSE2-------------LAN SUBNET 2 (STATIC IP)
            (192.168.0.0/24)                                                                                                        (192.168.105.0/24)

            if i ping from LANSUBNET to LANSUBNET2 have reply, include from pfsense1 diagnostics ping to pfsense2(192.168.105.1)
            but if i set automatically ping from pfsense1 to pfsense2 (192.168.105.1) this don't work and vpn down after some time.

            help me hoba, so far I maintain a server(192.168.0.20) doing ping towards pfsense2 but it does not seem to me the ideal

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              Why are your subnetmasks at both pfSense /32?

              1 Reply Last reply Reply Quote 0
              • M
                martinc_77
                last edited by

                I Use FOR VPN WAN Interfase in both pfsense.
                In pfsense 1 have load-balancer with opt-wan.
                PFSENSE 2 if movile client

                1 Reply Last reply Reply Quote 0
                • M
                  martinc_77
                  last edited by

                  no, it mistakes, to me it chewed it is 24 in both subnet. gateways is 192.168.0.1 and 192.168.105.1 respectively

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by

                    Do I get this right? if you ping the keepalive IP from the loadbalanced pfSense from the webgui using interface LAN  the tunnel comes up and the other end responds or not? Or only if you ing from a client behind the pfSense?

                    1 Reply Last reply Reply Quote 0
                    • M
                      martinc_77
                      last edited by

                      the other end response in both case. only don't work and vpn down if i only set automatically ping host and stop the others pings.
                      is more, i run "tcpdump -v -i fxp0 dst 192.168.105.1 and icmp" from my pfsense1. fxp0 is the lan interfase, and no packets exit from my pfsense if only set automatically ping host, but if i go to the diagnostic-ping and write the same ip set in automatically ping host, now packets exit from my pfsense and tunnel is up again.

                      :(

                      i don't understand whatts happend dear hoba

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        I'll try to test this option soon with the latest build.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.