• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC connection failed with SYN_SENT:CLOSED message

Scheduled Pinned Locked Moved IPsec
2 Posts 1 Posters 933 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    alejjime
    last edited by Dec 7, 2021, 8:36 PM

    I have an IPSEC tunnel configured between my Azure network and a customer's private network. Phase-1 of the tunnel is established between fixed/public IP addresses. Phase-2 is established between local/internal IP addresses; there are 3 Phase-2 connections, one of them is used only for file read connection via SFTP. An interesting detail is that the Phase-2 connection for SFTP, on my client's side, is defined using a public IP address (in the range 200.xx.xx.xx.xx) on their side, to a local IP address on my side.

    A client application needs to get a file from a server on my network using SFTP protocol, but when trying to connect, his application does not reach my server (receives a time-out), because my pfSense Firewall stops the connection with a SYN_SENT:CLOSED message.

    The Internet connection to my Azure network goes all through the VM with pfSense (version 2.5.2), where the VPN tunnel is configured, and which is assigned the public IP address used for the Phase-1 connection. In this Azure network, and behind the firewall, I have a Windows server with a SFTP application, with the internal firewall turned off. The Azure NSG assigned to that virtual machine has all ports open.

    What fault could be causing the communication failure? I understand that the SYN_SENT message occurs when there is an asynchronous connection problem, but no Phase-1 or Phase-2 parameter has any odd value or refers to synchronization.

    Please, I would appreciate any help you can give me with this problem.

    A 1 Reply Last reply Dec 7, 2021, 8:40 PM Reply Quote 0
    • A
      alejjime @alejjime
      last edited by Dec 7, 2021, 8:40 PM

      @alejjime Reviewing the pfSense configuration of my Azure network, I noticed the time zone was different than that of my client's servers, and I have already changed it, as well as that of my Windows server with the SFTP application, so they are already synchronized with my client's servers.
      I made that adjustment thinking that the date/time difference might generate an asynchrony problem, but the problem persists.

      1 Reply Last reply Reply Quote 0
      1 out of 2
      • First post
        1/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received