<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Is VTI currently broken?]]></title><description><![CDATA[<p dir="auto">I've been trying to transition my IPSec VPNs from tunnel mode to VTI and hitting a number of issues. Examples:</p>
<ul>
<li>weird fragmentation/MTU problems causing dropped packets</li>
<li>after some time, VTI gateway shows status "unknown" until dpinger is restarted</li>
<li>speed/latency issues when moving large amounts of data (apples to apples vs tunnel mode)</li>
<li>traffic sometimes completely halts until IPsec is stopped/started</li>
</ul>
<p dir="auto">In general it feels much more unstable and so I was wondering: what is the current status &amp; recommendation for those of us running the latest versions of pfSense (2.6/22.01 or 22.05). Are there any settings that it's critical to apply for stability?</p>
<p dir="auto">I also am aware of <a href="https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=242744" target="_blank" rel="noopener noreferrer nofollow ugc">this long standing FreeBSD bug</a> and was wondering if this could be what I'm hitting? Seems like a patch was released for FreeBSD 14 but that's a long way off. I read the <a href="https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html#caveats" target="_blank" rel="noopener noreferrer nofollow ugc">caveats section of the Routed IPSec docs</a> but this isn't mentioned.</p>
]]></description><link>https://forum.netgate.com/topic/171968/is-vti-currently-broken</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 21:37:55 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/171968.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 05 May 2022 11:45:45 GMT</pubDate><ttl>60</ttl></channel></rss>