• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSec VTI P2 connection issues

Scheduled Pinned Locked Moved Plus 22.05 Development Snapshots (Retired)
5 Posts 2 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gabacho4 Rebel Alliance
    last edited by May 18, 2022, 3:40 AM

    I have a site to site IPSec VTI connection between two 5100s that has been having issues with the P2 either disconnecting randomly and not reconnecting, or the P2 fails to connect at all. In all cases manual intervention in which I tell pfsense to connect the P2 via the IPSec status interface works without an issue.

    I am running the most recent 22.05 beta but have noticed this issue on the last couple. Just now, when updating to the most current beta, the P2 failed to connect. The P1 connects each and every time without an issue but the P2 requires me to manually connect it. I don’t see anything immediately in the logs, however, the fact that the P2 connects immediately when I intervene would suggest it’s not a setting error. Not one that I see anyway. Anything I can do to troubleshoot or fix?

    G 1 Reply Last reply May 18, 2022, 4:00 AM Reply Quote 0
    • G
      gabacho4 Rebel Alliance @gabacho4
      last edited by May 18, 2022, 4:00 AM

      Realized maybe it was worth noting that the local router is the one running the 22.05 beta while the remote end is using 22.01.

      1 Reply Last reply Reply Quote 0
      • G
        gabacho4 Rebel Alliance
        last edited by gabacho4 May 18, 2022, 4:26 AM May 18, 2022, 4:21 AM

        Both sides have the P2 keep alive option enabled. Reading through the documentation, I have now set the local router to:

        Child SA Start Action to Initiate at start (VTI or Tunnel Mode)
        Child SA Close Action to Restart/Reconnect

        Will see if this makes a difference but welcome any other ideas.

        1 Reply Last reply Reply Quote 0
        • G
          gabacho4 Rebel Alliance
          last edited by May 18, 2022, 4:35 AM

          OK just restarted the local router and, once I could log in and view the status, the P1 was connected but the P2 was not. However, when I tried to access resources on the remote side, the P2 connected and everything functioned as needed. So I guess my last question/wonder is if this is just the nature of the VTI connection. Will the P2 not connect on its own?

          J 1 Reply Last reply May 24, 2022, 9:23 AM Reply Quote 0
          • J
            JeGr LAYER 8 Moderator @gabacho4
            last edited by JeGr May 24, 2022, 9:26 AM May 24, 2022, 9:23 AM

            @gabacho4 What happens when you set both Child SA actions to default and disconnect both sides, then on one side click the connect P1+P2 button in the UI. Do both P1/P2 come up or is it still only P1 that will show? Does the 22.05 side show other behavior then 22.01 with that button? Did you set ChildSA actions on both sides or only on one?

            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received