Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    IPsec not reconnecting after site failure

    IPsec
    1
    1
    66
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kevindd992002 last edited by

      So I have two sites (main and remote) with both having a pfsense box and are connected via an site-to-site IPsec tunnel using routed VTI. The main site uses a public static IP but the remote site is behind a CGNAT (so private IP assigned to WAN interface). To make the tunnel work, I had to have a DDNS entry for the remote site WAN interface and put that as the peer identifier in the main site IPsec settings. I also had to check "Responder only" on the main site IPsec settings. I have DPD check on both sides.

      So to establish the connection, I have to click the Connect button under Status -> IPsec. After this, if I restart either of the pfsense boxes I don't have any issues with the remote pfsense box reconnecting and re-establishing the IPsec tunnel. The problem is when either of the site has an Internet outage for say more than an hour, the tunnel does not automatically get reconnected. I have to do the manual "Connect" process again under Status -> IPsec.

      I also don't use the "automatically ping host" feature in the phase 2 settings of both sides because I already have gateway monitoring (by pinging the IPsec interface IP on the far side) set. I read somewhere that this does the same thing with routed VTI.

      @jimp Any ideas how I can solve the reconnection failure?

      1 Reply Last reply Reply Quote 0
      • First post
        Last post

      Products

      • Platform Overview
      • TNSR
      • pfSense Plus
      • Appliances

      Services

      • Training
      • Professional Services

      Support

      • Subscription Plans
      • Contact Support
      • Product Lifecycle
      • Documentation

      News

      • Media Coverage
      • Press
      • Events

      Resources

      • Blog
      • FAQ
      • Find a Partner
      • Resource Library
      • Security Information

      Company

      • About Us
      • Careers
      • Partners
      • Contact Us
      • Legal
      Our Mission

      We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

      Subscribe to our Newsletter

      Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

      © 2021 Rubicon Communications, LLC | Privacy Policy