Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Mobile IPSec IKEv2 tunnel stops working

    IPsec
    1
    3
    113
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RMB
      RMB last edited by RMB

      Hi,

      I have an Atom C3758 appliance with pfsense 2.5.0 CE installed and just configured a Mobile IPSec IKEv2 tunnel as outlined in the following document:
      https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html

      I am connecting with an iOS device and a macOS device, both latest OS versions. I noticed the connection is working fine for several seconds or sometimes minutes before it seems to die. It seems depending on the amount of data transferred I guess. Some SSH sessions were working fine for minutes, but when I started to surf via the tunnel, or do some file transfer, then the connection stops sending data almost immediately.
      When I reconnect the tunnel the data was flowing again for a short time.

      I have MSS Clamping configured on 1360, based on some site-to-site tunnel needs.
      I have tried a lot of different settings, and it did not change anything for the dying tunnel. Finally I disabled "Asynchronous Cryptography" and the tunnel was a bit more stable. It took more time before the tunnel was hanging again.

      Any ideas?

      1 Reply Last reply Reply Quote 0
      • RMB
        RMB last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • RMB
          RMB last edited by

          I have found the problem;

          https://redmine.pfsense.org/issues/11524

          It is related to the combination of AES-NI and P2 SHA256.

          Temporary workaround: disable AES-NI

          I hope this will be fixed soon!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy