<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSec: Established, SAs Up, Traffic somewhat strange or missing]]></title><description><![CDATA[<p dir="auto">Hello together,</p>
<p dir="auto">in our company main side, we have a Sophos UTM Appliance that is acting as gateway. (No NAT)<br />
Here at home, i'm doomed to stick to my ISPs default Router, so pfSense is behind that router.</p>
<p dir="auto">Until 3 days ago, I used the Home-Version of Sophos XG Firewall, to connect through an IPSec tunnel to the Sophos UTM. Everything was working, multiple subnets have been used.</p>
<p dir="auto">Then I had the bad Idea to give it a shot with that new firmware upgrade. New Version is broken, backup can't be used cause after restoring its losing its activation - and in THAT version, there was a bug, that all interfaces go offline, once not activated - so that backup is bricked as well.</p>
<hr />
<p dir="auto">So, searching for an alternative I found pfSense and it looks pretty solid. I installed it, everything wen't quite smooth and started to setup the IPSec tunnel with the Sophos. But now, i'm facing some issues I don't really understand, and hope somebody here has an idea which button to press.</p>
<p dir="auto">So, Situation Summary:</p>
<p dir="auto">Network at Home:</p>
<ul>
<li>10.10.20.0/22 (Network for all Clients on the green side of pfSense)</li>
<li>10.10.19.0/24 (Network on the red side, basically only my ISPs Router and the red side of pfSense)</li>
</ul>
<p dir="auto">Network at Work:</p>
<ul>
<li>192.168.136.0/22, Sophos acting as gateway, owning an external static IP.</li>
</ul>
<p dir="auto">Status:<br />
I configured the pfSense to have the both IPs 10.10.19.2 (red) and 10.10.20.1 (green). IPSec is configured to use PSK, AES 256, connection is established successully. Both Firewalls show the communication-logs, do key renewals etc.</p>
<p dir="auto">For now, I tried to get it working with only 1 SAD (192.168.136.0/22 &lt;=&gt; 10.10.20.0/22)<br />
That SAD establishes it's connection and pfSense is reporting Outgoing traffic. I can verify from the firewall logs, that connection attemps of various services are "leaving" through the red gate of pfSence (53 / UDP (DNS-Queries, caused by DNS Forwarders), TCP 5070 (VOIP-Phone trying to connect) and many more.)</p>
<p dir="auto">But then, the trace of that packages gets lost. The Sophos firewall - which I configured to log every dropped or successfull package - does not show any trace of incoming traffic.</p>
<p dir="auto">Trying to reach my subnet from the Sophos-side also reports all packages as "green" and allowed - none of them is reaching pfSence.</p>
<p dir="auto">So, I am highly out of ideas, because the "technical" route was working with 2 sophos appliances. (hence the router of the ISP does not block that / forwards and receives correctly i'd say)</p>
<p dir="auto">The only assumption I have is that it has to do something with the identifiers of the IPSec tunnel, so the firewalls in some way are thinking "hmm, that package is not for me" - but I think I tried every possible combination, and I'm not sure if it would manage Phase1 at all, if the identifiers are wrong?</p>
<p dir="auto">Here are some of the configuration screenshots, If you need any additional Logs or something, just let me know.</p>
<hr />
<p dir="auto">pfSense:</p>
<p dir="auto"><img src="/assets/uploads/files/1650985161071-1f1ca2ab-5ca8-4050-bef1-be15b9b65984-image.png" alt="1f1ca2ab-5ca8-4050-bef1-be15b9b65984-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Note the "Packets-In": 0<br />
<img src="/assets/uploads/files/1650985245051-cce1483a-9649-4d59-955f-d8cd887915ff-image.png" alt="cce1483a-9649-4d59-955f-d8cd887915ff-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Some "confirmed" Outgoing packets:<br />
<img src="/assets/uploads/files/1650985368115-252d861b-5a9b-4364-a3be-8c16f26f0650-image.png" alt="252d861b-5a9b-4364-a3be-8c16f26f0650-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Sophos-Side:<br />
<img src="/assets/uploads/files/1650985579390-16256212-4054-4315-9029-be3c33a869aa-image.png" alt="16256212-4054-4315-9029-be3c33a869aa-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Shows no trace of "incoming" packages from pfSense beside all the Phase1 Communication itself (UDP 500 / 4500)</p>
<p dir="auto">So, I have the feeling that packages are send out by pfSence, but somehow missrouted down the road.</p>
<p dir="auto">As said, the Sophos side was perfectly fine with the Sophos XG on my side, so I assume everything there (Routing, Firewall rules) are still fine and working.<br />
(No one but me is changing something there)</p>
<p dir="auto">Any Ideas where I could continue searching for issues?</p>
]]></description><link>https://forum.netgate.com/topic/171775/ipsec-established-sas-up-traffic-somewhat-strange-or-missing</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Apr 2026 10:26:40 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/171775.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 26 Apr 2022 15:30:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSec: Established, SAs Up, Traffic somewhat strange or missing on Tue, 26 Apr 2022 17:26:01 GMT]]></title><description><![CDATA[<p dir="auto">Figured it out thx to a post in the UTM-Forums that is ... ehm... 5 years old :)</p>
<p dir="auto">The Sophos has an Issue with AES 256 along with SHA 256. Dropping to SHA-1 and it starts to work out of a sudden.</p>
<p dir="auto">(Not to mention it does not support IKEv2)</p>
<p dir="auto">We'll, we are looking for a new Appliance on the HQ-Side anyway, so i'm now going to look deeper into pfSense <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61c.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--stuck_out_tongue_winking_eye" style="height:23px;width:auto;vertical-align:middle" title=":stuck_out_tongue_winking_eye:" alt="😜" /></p>
<p dir="auto">https://community.sophos.com/sophos-xg-firewall/f/discussions/89213/ipsec-vpn-with-utm-not-passing-traffic?ReplyFilter=Answers&amp;ReplySortBy=Answers&amp;ReplySortOrder=Descending</p>
]]></description><link>https://forum.netgate.com/post/1039613</link><guid isPermaLink="true">https://forum.netgate.com/post/1039613</guid><dc:creator><![CDATA[dognose]]></dc:creator><pubDate>Tue, 26 Apr 2022 17:26:01 GMT</pubDate></item><item><title><![CDATA[Reply to IPSec: Established, SAs Up, Traffic somewhat strange or missing on Tue, 26 Apr 2022 16:33:01 GMT]]></title><description><![CDATA[<p dir="auto">I've just read about issues with IPsec and the 2.6 version.</p>
<p dir="auto">So, I quickly setup another vm, installed the 2.5.2 release, configured the connection - but it behaves exactly the same way.</p>
<ul>
<li>Connection established</li>
<li>SAs are up</li>
<li>Traffic outgoing</li>
</ul>
<p dir="auto">but nothing happening. So, it has to be an Issue with the confiuguration.</p>
<p dir="auto">ps.:<br />
Since the red side of pSence is basically a mini network behind the ISPs Router, I disabled the Options "Block private networks and loopback addresses" and "Block bogon networks", since i'm expecting to see IP addresses of the private range on that side.</p>
<p dir="auto">Also, Firewall-Wise:</p>
<p dir="auto">The LAN-Rule is recording Outgoing traffic for the subnets:</p>
<p dir="auto"><img src="/assets/uploads/files/1650990725707-b6594118-d770-4741-b964-5f87b0a31277-image.png" alt="b6594118-d770-4741-b964-5f87b0a31277-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">where the IPSec rule doesn't record anyting:</p>
<p dir="auto"><img src="/assets/uploads/files/1650990758063-7fc2d5ba-14e9-4d9f-98ec-c21519e8bd94-image.png" alt="7fc2d5ba-14e9-4d9f-98ec-c21519e8bd94-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1039604</link><guid isPermaLink="true">https://forum.netgate.com/post/1039604</guid><dc:creator><![CDATA[dognose]]></dc:creator><pubDate>Tue, 26 Apr 2022 16:33:01 GMT</pubDate></item></channel></rss>