Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec & Openvpn client conflict

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 580 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DonKjeldsen
      last edited by

      Hi

      I have a issue i am hoping someone would have a good input for.

      I have the following setup with two internal vlan , two ISP connections, and a OpenVPN connection which routes one vlan to a distant provider.

      I am having problems with setting up a site 2 site IPsec connection.

      my issue is that, when I stop my OpenVPN client connection, the site to site IPsec connection works. however if the OpenVPN client is running, the IPsec connection gets a timeout in phase2 and wont establish

      2021-04-11 12_05_57-Tegning1.vsdx - Visio Professional.png

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @DonKjeldsen
        last edited by

        @donkjeldsen

        Just a hunch ...

        Do you have "default gateway" out of the OpenVPN gateway ?
        That would prob. route your packages towards the ipsec dest. , out via the Ovpn. And stop when the OVPN is not active.

        /Bingo

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        D 2 Replies Last reply Reply Quote 1
        • D
          DonKjeldsen @bingo600
          last edited by

          @bingo600

          a good hunch, but unfortunately no

          the default route is the primary ISP directly

          i have a gateway group where the primary ISP is tier 1 and the secondary Tier 2, which is used for one of the vlan

          the sec vlan use the OpenVPN connection as its connection

          the IPsec and OpenVPN are sat to use the primary ISP interface directly

          1 Reply Last reply Reply Quote 0
          • D
            DonKjeldsen @bingo600
            last edited by

            @bingo600
            Your thought about gateway prompted me to look over the config and compare with input from my ISP.

            my primary IPv4 Upstream gateway was empty. I am not sure why it only worked temporary, when I closed the OpenVPN connection, it might be a route going wrong, like with a missing default gateway .

            right now it looks stable :)

            Thanks for the input

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.