Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.5 upgrade broke some, not all, IPSEC

    Scheduled Pinned Locked Moved IPsec
    16 Posts 5 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gtoger @jimp
      last edited by

      @jimp The service doesn't stop, even if doing manually from Status > Services. I click on the stop icon, and it just refreshes to another stop icon. The service never actually stops.

      The tunnels are verified to still be up as they're passing traffic (I can reach the private IPs on the other ends).

      Re the status page not appearing correctly, I actually have applied the following patches already:
      ead6515637a34ce6e170e2d2b0802e4fa1e63a00
      57beb9ad8ca11703778fc483c7cba0f6770657ac
      c09137ab4726dc492c658c27b6c46e25f0fbb55b

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Do you have something like Service Watchdog setup which might be restarting it when it shouldn't be?

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        G 1 Reply Last reply Reply Quote 0
        • G
          gtoger @jimp
          last edited by

          Nope. Nothing like that. It's pretty much a stock setup.

          I've been informed that in addition to this IPSEC issue, SIP traffic is not passing. Unrelated items, yes. But both issues came after the update.

          My concern is that there are things that have been mangled in the upgrade process, especially considering this box started as a MUCH earlier version of pfSense several years ago. We may have to simply export the config, spin up a fresh install and import the config across.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Before doing that you might want to reset your browser cache to make sure it isn't using outdated JS/CSS. Maybe something there is tripping up the service stop/start buttons.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            G 1 Reply Last reply Reply Quote 0
            • G
              gtoger @jimp
              last edited by

              @jimp Thanks Yeah, that wasn't it. I even switched browsers. Something is, I'm afraid, really wrong with this thing.

              H 1 Reply Last reply Reply Quote 1
              • H
                hescominsoon @gtoger
                last edited by

                @gtoger make a config backup and then reinstall from scratch..then try restoring the config..see if that helps.

                G 1 Reply Last reply Reply Quote 0
                • G
                  gtoger @hescominsoon
                  last edited by

                  @hescominsoon It's not what I wanted to do, but I did it.

                  Did it solve the problem? Nope. Still have a failure to connect this tunnel.

                  Could it be that we're going between a pfSense CE and a pfSense+ on a Netgate device? Would seem awfully dang strange. But I'm convinced there's a bug here someplace.

                  1 Reply Last reply Reply Quote 1
                  • M
                    mmichael
                    last edited by

                    Hello,

                    I can report the same problems with my VM - Hardware PFSense an Tunnels
                    BR
                    Martin

                    1 Reply Last reply Reply Quote 0
                    • viktor_gV
                      viktor_g Netgate
                      last edited by

                      Try to resave/reapply the Phase 1 parameters for your tunnels,
                      this could be related to https://redmine.pfsense.org/issues/11455

                      4 1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by jimp

                        This thread is getting out of hand like the previous one. We need to keep each thread for ONE issue only, not for multiple unrelated things that happen to be in IPsec.

                        See my previous response at https://forum.netgate.com/post/964752

                        Before reporting any issues, please look at the list of recent IPsec issues and apply fixes/workarounds from there to eliminate known causes.

                        You can install the System Patches package and then create entries for the following commit IDs to apply the fixes:

                        • ead6515637a34ce6e170e2d2b0802e4fa1e63a00 #11435
                        • 57beb9ad8ca11703778fc483c7cba0f6770657ac #11435
                        • 10eb04259fd139c62e08df8de877b71fdd0eedc8 #11442
                        • ded7970ba57a99767e08243103e55d8a58edfc35 #11486
                        • afffe759c4fd19fe6b8311196f4b6d5e288ea4fb #11487
                        • 2fe5cc52bd881ed26723a81e0eed848fd505fba6 #11488

                        Please refrain from replying to someone else's thread with a "me too" until there is confirmation that your issues are really the same and not just similar.

                        I'll split some of these off into their own threads if they don't already have them, but for now, this one is locked.

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.