21.02.2-RC IPSEC Status Widget
-
IPSEC between two DDNS hosts with FQDN identifiers works again and Status/IPSEC pages is also ok. However dashboard widget for IPSEC shows incorrect status:
All three tunnels are up and working fine. -
Got a little more info about how that tunnel is setup?
Is it IKEv1 or IKEv2?
Split connections on or off?
VTI or tunnel mode? -
@jimp Two IKEv1 tunnels, first has 1 P2 in tunnel mode, the other 2 P2 also in tunnel mode. Sorry, I could not find Split connection setting.
Other ends are also pfSense hosts, SG-1000 runs still on 2.4.5-RELEASE-p1 and SG-4860 runs on 21.02-RELEASE, which has broken IPSEC status widged and status page. All three firewalls have DDNS setup on WAN and tunnels are negotiated with Distinguished name. (Love this feature)
-
My widget does the same. My tunnels are actually UP and i can traverse them, but they all report from the widget as down.
2.5.0-RELEASE (amd64)
built on Tue Feb 16 08:56:29 EST 2021
FreeBSD 12.2-STABLE -
@tve said in 21.02.2-RC IPSEC Status Widget:
@jimp Two IKEv1 tunnels, first has 1 P2 in tunnel mode, the other 2 P2 also in tunnel mode. Sorry, I could not find Split connection setting.
Fixed in the latest snapshot,
see https://redmine.pfsense.org/issues/11435#note-6