<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Feature request: a LISA (&quot;Log Interpretation System &amp; Action&quot;) to make live easier :)]]></title><description><![CDATA[<p dir="auto">Hi all,</p>
<p dir="auto">I am new to the whole VPN thing and it took me a day to get my first IPsec VPN up and running, so many little things, so many log files.</p>
<p dir="auto">The pages about <a href="https://docs.netgate.com/pfsense/en/latest/vpn/index.html" target="_blank" rel="noopener noreferrer nofollow ugc">Virtual Private Networks</a> and <a href="https://docs.netgate.com/pfsense/en/latest/troubleshooting/ipsec.html" target="_blank" rel="noopener noreferrer nofollow ugc">Troubleshooting IPsec VPNs</a> are really helpful and should be read up front <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /></p>
<p dir="auto">But I am wondering, why do we need those written troubleshooting pages, why are we slaves to the endless log files? <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f615.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--confused" style="height:23px;width:auto;vertical-align:middle" title=":confused:" alt="😕" /></p>
<p dir="auto"><strong>Feature request: a LISA (Log Interpretation System &amp; Action)</strong></p>
<p dir="auto">Marketing speak: "<em>The LISA (Log Interpretation System &amp; Action) is a brand new feature of pfSense, it abstracts log files, filters relevant information, presents it to the user with context, recommendations and actions</em>".</p>
<p dir="auto">Some examples of LISA when a user is trying to set up and connect an IPsec VPN:</p>
<ol>
<li>
<p dir="auto">"pfSense can not connect to the remote gateway IP address (1.2.3.4). Please ensure 1) the IP address (1.2.3.4) is correct, 2) you enabled the relevant in-coming and outgoing connections in the firewall &lt;Click here to automatically create the rules&gt;, 3) the remote gateway has enabled your IP in their firewall"</p>
</li>
<li>
<p dir="auto">"pfSense discovered a NO_PROPOSAL_CHOSEN error. Please make sure both sides of the VPN share a common hash algorithm for IPsec Phase 1. You enabled "SHA256", the remote side only "SHA1".</p>
</li>
<li>
<p dir="auto">"pfSense discovered an AUTHENTICATION_FAILED error. Please make sure your PSK ("<em>Pre-Shared Key</em>") of IPsec Phase 1 are identical with the remote side."</p>
</li>
<li>
<p dir="auto">"pfSense discovered a INVALID_ID_INFORMATION error. Please ensure your network settings in IPsec Phase 2 (Local: 1.2.3.4, Remote:5.6.7.8/16) are identical with the remote side."</p>
</li>
<li>
<p dir="auto">"pfSense discovered the remote IPsec internal IP is not reachable. Please ensure the firewall for IPsec is configured accordingly. &lt;Click here to enable any connection on the IPsec network for testing&gt;"</p>
</li>
</ol>
<p dir="auto">Just some food for thought, open for discussion. I started with LIS, now it became LISA <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f606.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--laughing" style="height:23px;width:auto;vertical-align:middle" title=":laughing:" alt="😆" /></p>
<p dir="auto">Cheers<br />
bluepuma</p>
]]></description><link>https://forum.netgate.com/topic/161134/feature-request-a-lisa-log-interpretation-system-action-to-make-live-easier</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 18:18:43 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/161134.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 20 Feb 2021 12:40:35 GMT</pubDate><ttl>60</ttl></channel></rss>