<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC is giving package errors in &quot;Middle&quot; subnet]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">We have the following scenario:<img src="/assets/uploads/files/1705620909747-captura-de-tela-de-2024-01-18-19-34-58.png" alt="Captura de tela de 2024-01-18 19-34-58.png" class=" img-fluid img-markdown" /><br />
We have the following IPSEC:<br />
Phase 1:</p>
<ul>
<li>IKEv2<br />
Phase 2:</li>
<li>Local Subnet: 172.24.44.0/22</li>
<li>Remote Subnet: 172.16.0.0/12</li>
</ul>
<p dir="auto">Look, the local firewall (172.24.44.0/24) is within 172.24.44.0/22 subnet, as 172.14.1.3/22 (remote firewall) is within 172.16.0.0/12.</p>
<p dir="auto">So there is a static route within 172.24.44.70 to fix IPSEC routing:</p>
<pre><code>172.16.0.0/12 via 172.24.44.2 (172.24.44.0/22 gw)
</code></pre>
<p dir="auto">It's funny that when 172.24.44.51 pings to 172.24.3.1 (at same subnet of FW 172.24.1.3) it returns serveral package errors:</p>
<pre><code>Ping statistics for 172.24.3.1:
    Packets: Sent = 41, Received = 15, Lost = 26 (63% loss),
Approximate round trip times in milli-seconds:
    Minimum = 59ms, Maximum = 59ms, Average = 59ms
</code></pre>
<p dir="auto">meanwhile when it pings 172.16.3.1, that at other side of a MPLS (WAN link), it does not so many package errors:</p>
<pre><code>Ping statistics for 172.16.3.1:
    Packets: Sent = 75, Received = 74, Lost = 1 (1% loss),
Approximate round trip times in milli-seconds:
    Minimum = 74ms, Maximum = 107ms, Average = 79ms
</code></pre>
<p dir="auto">It's weird! I added a static route like this:</p>
<pre><code>172.24.0.0/16 via 172.24.44.2 
</code></pre>
<p dir="auto">but it not solve this issue.</p>
<p dir="auto">That's 172.16.3.1 route:</p>
<pre><code>Tracing route to SRVDC1-TRF1.trf1.gov.br [172.16.3.1]
over a maximum of 30 hops:

  1     *        *        *     Request timed out.
  2    &lt;1 ms    &lt;1 ms    &lt;1 ms  fw-bag.jfmt.jus.br [172.24.44.70]
  3    59 ms    59 ms    58 ms  172.24.1.3
  4    60 ms    60 ms    60 ms  172.24.0.2
  5    59 ms    59 ms     *     router-eth1.mt.trf1.gov.br [172.24.1.1]
  6     *        *        *     Request timed out.
  7     *        *        *     Request timed out.
  8    74 ms    79 ms    88 ms  172.16.180.22
  9    76 ms    94 ms    76 ms  SRVDC1-TRF1.trf1.gov.br [172.16.3.1]
</code></pre>
<p dir="auto">and that's 172.24.3.1 route:</p>
<pre><code>Tracing route to SRVDC1-MT.mt.trf1.gov.br [172.24.3.1]
over a maximum of 30 hops:

  1     *        *        *     Request timed out.
  2    &lt;1 ms    &lt;1 ms    &lt;1 ms  fw-bag.jfmt.jus.br [172.24.44.70]
  3    58 ms    58 ms    58 ms  172.24.1.3
  4     *        *       59 ms  SRVDC1-MT.mt.trf1.gov.br [172.24.3.1]
</code></pre>
<p dir="auto">Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/185630/ipsec-is-giving-package-errors-in-middle-subnet</link><generator>RSS for Node</generator><lastBuildDate>Tue, 09 Jun 2026 23:32:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/185630.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 18 Jan 2024 23:46:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC is giving package errors in &quot;Middle&quot; subnet on Fri, 19 Jan 2024 17:17:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> It wasn't necessary. The issue was happening at the other peer, a Blockbit with two boxes, but the slave box, though operating, has not the redundancy enabled (cabling). When we turned off the slave box, the problem was solved.</p>
]]></description><link>https://forum.netgate.com/post/1148664</link><guid isPermaLink="true">https://forum.netgate.com/post/1148664</guid><dc:creator><![CDATA[Redbob]]></dc:creator><pubDate>Fri, 19 Jan 2024 17:17:52 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC is giving package errors in &quot;Middle&quot; subnet on Fri, 19 Jan 2024 10:06:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/redbob">@<bdi>Redbob</bdi></a> said in <a href="/post/1148572">IPSEC is giving package errors in "Middle" subnet</a>:</p>
<blockquote>
<p dir="auto">We have the following IPSEC:<br />
Phase 1:</p>
<pre><code>IKEv2
Phase 2:
Local Subnet: 172.24.44.0/22
Remote Subnet: 172.16.0.0/12
</code></pre>
</blockquote>
<p dir="auto">These subnets are overlapping.</p>
<p dir="auto">You can configure BINAT to circumvent collisions though, but is there really a /12 needed at the remote site?</p>
]]></description><link>https://forum.netgate.com/post/1148610</link><guid isPermaLink="true">https://forum.netgate.com/post/1148610</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 19 Jan 2024 10:06:06 GMT</pubDate></item></channel></rss>