<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec can not ping site B]]></title><description><![CDATA[<p dir="auto">Greetings to All,</p>
<p dir="auto">I've configured the IPsec</p>
<pre><code>Jun 28 17:31:30 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 440 [ ]
Jun 28 17:31:30 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:31:35 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:31:35 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 441 [ ]
Jun 28 17:31:35 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 441 [ ]
Jun 28 17:31:35 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:31:40 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:31:40 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 442 [ ]
Jun 28 17:31:40 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 442 [ ]
Jun 28 17:31:40 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:31:45 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:31:45 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 443 [ ]
Jun 28 17:31:45 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 443 [ ]
Jun 28 17:31:45 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:31:50 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:31:50 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 444 [ ]
Jun 28 17:31:50 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 444 [ ]
Jun 28 17:31:50 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:31:55 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:31:55 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 445 [ ]
Jun 28 17:31:55 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 445 [ ]
Jun 28 17:31:55 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:00 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:00 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 446 [ ]
Jun 28 17:32:00 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 446 [ ]
Jun 28 17:32:00 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:05 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:05 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 447 [ ]
Jun 28 17:32:05 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 447 [ ]
Jun 28 17:32:05 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:10 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:10 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 448 [ ]
Jun 28 17:32:10 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 448 [ ]
Jun 28 17:32:10 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:15 	charon 		11[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:15 	charon 		11[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 449 [ ]
Jun 28 17:32:15 	charon 		11[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 449 [ ]
Jun 28 17:32:15 	charon 		11[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:20 	charon 		10[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:20 	charon 		10[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 450 [ ]
Jun 28 17:32:20 	charon 		10[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 450 [ ]
Jun 28 17:32:20 	charon 		10[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:25 	charon 		10[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:25 	charon 		10[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 451 [ ]
Jun 28 17:32:25 	charon 		10[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 451 [ ]
Jun 28 17:32:25 	charon 		10[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)
Jun 28 17:32:30 	charon 		10[NET] &lt;con1000|1&gt; received packet: from 1x.20x.9.2x[500] to 1xx.2x.1x.2x[500] (80 bytes)
Jun 28 17:32:30 	charon 		10[ENC] &lt;con1000|1&gt; parsed INFORMATIONAL request 452 [ ]
Jun 28 17:32:30 	charon 		10[ENC] &lt;con1000|1&gt; generating INFORMATIONAL response 452 [ ]
Jun 28 17:32:30 	charon 		10[NET] &lt;con1000|1&gt; sending packet: from 1xx.2x.1x.2x[500] to 1x.20x.9.2x[500] (80 bytes)  
</code></pre>
<p dir="auto">Interface of My LAN Subnet is 172.16.1xx.0/20<br />
Interface of IPSEC : 192.168.xxx.xxx/30</p>
<p dir="auto">In phase-2 , I have added my LAN subent in<br />
Local Area Network : 172.16.1xx.0/20<br />
NAT/BINAT translation:  192.168.xxx.xxx/30</p>
<p dir="auto">When Im trying to ping 192.168.xxx.2/32</p>
<p dir="auto">Unable to ping network nor I'm able to trace that remote IP. IPsec status is showing connected but phase-2 0 bytes in/out .</p>
<h1><a class="anchor-offset" name="rule-in-ipsec"></a>Rule in IPSEC:</h1>
<p dir="auto"><img src="/assets/uploads/files/1624884250877-ipsec-rule.png" alt="-ipsec-rule.png" class=" img-fluid img-markdown" /></p>
<h1><a class="anchor-offset" name="rule-in-lan"></a>Rule in LAN:</h1>
<p dir="auto"><img src="/assets/uploads/files/1624884765132-screenshot_2021-06-28-pfsense-local-landomain-firewall-rules-lan.png" alt="Screenshot_2021-06-28 pfSense local landomain - Firewall Rules LAN.png" class=" img-fluid img-markdown" /><br />
Do I need to add any other rule as well?</p>
<p dir="auto">Regards</p>
]]></description><link>https://forum.netgate.com/topic/164723/ipsec-can-not-ping-site-b</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 02:23:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/164723.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Jun 2021 12:53:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec can not ping site B on Tue, 29 Jun 2021 04:29:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/scorpoin">@<bdi>scorpoin</bdi></a> Try to change the LAN rule to "any any" to include icmp in your rule. Ping is icmp.</p>
]]></description><link>https://forum.netgate.com/post/989858</link><guid isPermaLink="true">https://forum.netgate.com/post/989858</guid><dc:creator><![CDATA[pete35]]></dc:creator><pubDate>Tue, 29 Jun 2021 04:29:24 GMT</pubDate></item></channel></rss>