• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense 2.5.2 - split-tunneling issue using windows clients

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 854 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    serhiil
    last edited by Oct 27, 2021, 7:41 AM

    Hi,

    I am trying to configure IKEv2 with split-tunneling on pfSense and to use the Windows client. But when I set "Local Network" in Phase 2 to "LAN subnet" or to any "Network", the Windows client gets only the 10.0.0.0/8 route.

    In the Pfsense 2.2.4 - split-tunneling using windows clients - missing route to vpn topic was mentioned:

    • Looking over the IPsec daemon documentation it appears what you are after may not be possible in a way that is both usable and desirable. It's a limitation of the Windows VPN client and not pfSense or IKEv2. The Windows client has no mechanism to receive routes/subnets over IKEv2 other than the VPN tunnel network itself. Unfortunately that's how the Windows client has always worked even with PPTP.

    But when I configure IKEv2 with split-tunneling, for example, on Mikrotik, the Windows client can get multiples routes. So where is the issue with pfSense or the Windows client? Maybe I do something wrong?

    Thanks.

    1 Reply Last reply Reply Quote 0
    • S
      serhiil
      last edited by Oct 27, 2021, 8:24 AM

      I think I found why the Windows client works with Mikrotik. It's from the Mikrotik documentations:

      • Here is a list of known limitations by popular client software IKEv2 implementations.
        • Windows will always ignore networks received by split-include and request policy with destination 0.0.0.0/0 (TSr). When IPsec-SA is generated, Windows requests DHCP option 249 to which RouterOS will respond with configured split-include networks automatically.

      Did you think to add this feature to pfSense?

      Thanks.

      P 1 Reply Last reply Nov 1, 2021, 3:01 AM Reply Quote 0
      • P
        periko @serhiil
        last edited by Nov 1, 2021, 3:01 AM

        @serhiil but what u want to achieve here?

        Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
        www.bajaopensolutions.com
        https://www.facebook.com/BajaOpenSolutions
        Quieres aprender PfSense, visita mi canal de youtube:
        https://www.youtube.com/c/PedroMorenoBOS

        S 1 Reply Last reply Nov 1, 2021, 3:21 PM Reply Quote 0
        • S
          serhiil @periko
          last edited by Nov 1, 2021, 3:21 PM

          @periko I would like to know if it is planned to add route pushing to Windows clients using DHCP option?

          Thanks.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received