Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    how to enable continuous IPsec S2S reconnection retries?

    IPsec
    2
    6
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      boi
      last edited by

      after probably not more than a hour offline at the other end (fortigate), this side (pfsense) of VPN tunnel goes to "disconnected" status and won't do reconnect attempts ( even other side will eventually return online).
      how to enable continuous (neverending) reconnect retries?
      on the page "ipsec status" I see just manual reconnect:
      pfsense ipsec - Screenshot 2021-12-13 012113.png

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If it's tunnel mode IPsec, you can fill in a keep-alive host in the P2 options, that will periodically try to send some traffic across the VPN which would initiate it.

        There is a better option coming on 22.01/2.6.0 that works for VTI and tunnel mode: https://redmine.pfsense.org/issues/12169

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        B 2 Replies Last reply Reply Quote 0
        • B
          boi @jimp
          last edited by

          @jimp why pfsense doesn't respond to other side requests when other side returns online?
          is it by design (can't find answer anywhere in the docs)?
          *sorry i'm quite to pfsense, previous experience with cisco mainly

          jimpJ 1 Reply Last reply Reply Quote 0
          • B
            boi @jimp
            last edited by

            @jimp sorry for double posting, couldn't update previous post.

            which source address will be used in keep-alive host?
            af1a53b9-b45a-440e-92e3-028e475046be-image.png

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate @boi
              last edited by

              @boi said in how to enable continuous IPsec S2S reconnection retries?:

              @jimp why pfsense doesn't respond to other side requests when other side returns online?
              is it by design (can't find answer anywhere in the docs)?
              *sorry i'm quite to pfsense, previous experience with cisco mainly

              If the remote side initiates properly, it should respond. If it doesn't, that suggests maybe you have a settings mismatch somewhere. It's not uncommon for that to happen since IPsec implementations will generally accept more strict values from peers but reject less secure options. So if they don't match, you mind find it initiates one way but not both.

              @boi said in how to enable continuous IPsec S2S reconnection retries?:

              @jimp sorry for double posting, couldn't update previous post.

              which source address will be used in keep-alive host?

              The firewall tries to source it from an address inside the local part of the P2, assuming there is an address on the firewall in that subnet. If there isn't an address on the firewall in the P2 then it can't send any traffic that would trigger the tunnel to initiate.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              B 1 Reply Last reply Reply Quote 1
              • B
                boi @jimp
                last edited by

                @jimp said in how to enable continuous IPsec S2S reconnection retries?:

                If the remote side initiates properly, it should respond.

                6f8e4b12-d9e8-434f-b595-0411d595e9a5-image.png

                if other side's offline time not really long pfsense responds to IPsec tunnel requests as I can said from status page above.

                @jimp said in how to enable continuous IPsec S2S reconnection retries?:

                The firewall tries to source it from an address inside the local part of the P2, assuming there is an address on the firewall in that subnet. If there isn't an address on the firewall in the P2 then it can't send any traffic that would trigger the tunnel to initiate.

                thanks for this information, doing this immediately!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.