• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPsec tunnel established but hosts cannot ping each other

Scheduled Pinned Locked Moved IPsec
14 Posts 4 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • X
    xAgamemnon
    last edited by Mar 28, 2024, 11:30 AM

    Hello everyone, I have a problem with a VPN connection using IPsec. For better illustration, I show below how I would like to connect two sites to each other. After the proper configuration as you can see from the PfSense screenshot everything seems to be fine. The connection is established, but if I want to ping from host 192.168.69.2 to host 192.168.138.4 it is impossible, I get no response. Could someone please help me to solve this problem?

    2024-03-27 20_42_30-topology _ Visual Paradigm Online.png
    Establsihed.png
    Nie pinguje.png

    M F 2 Replies Last reply Mar 28, 2024, 11:44 AM Reply Quote 0
    • M
      michmoor LAYER 8 Rebel Alliance @xAgamemnon
      last edited by Mar 28, 2024, 11:44 AM

      @xAgamemnon
      Is there a phase 2 entry?
      Are there firewall rules permitting hosts to ping?
      Are there logs to show?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      X 1 Reply Last reply Mar 28, 2024, 12:17 PM Reply Quote 0
      • X
        xAgamemnon @michmoor
        last edited by Mar 28, 2024, 12:17 PM

        @michmoor I will provide you some screenshot for this. Below it is another screen of IPsec established because my WAN changed on both sides:
        establishedddddd.png

        1. Here is the answer for your first question:
          entry.png
        2. Here is the answer for your second question:
          LAN PING.png
          ping WAN.png
        3. Here is the answer for your third question:
          logi.png
        X M 2 Replies Last reply Mar 28, 2024, 12:27 PM Reply Quote 0
        • X
          xAgamemnon @xAgamemnon
          last edited by Mar 28, 2024, 12:27 PM

          @xAgamemnon Yes i know there is a mismatch in Phase 2 remote network i changed it to 192.168.138.0 but it also doesn't work

          X 1 Reply Last reply Mar 28, 2024, 12:38 PM Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @xAgamemnon
            last edited by michmoor Mar 28, 2024, 12:39 PM Mar 28, 2024, 12:38 PM

            @xAgamemnon
            I didn’t mean a screenshot of logs but the actual IPsec logs maybe from console or ssh you can grab it
            Secondly I don’t see any firewall rules. There should be a firewall rule on the IPsec interface I believer. What do the firewall logs show? Any drops?

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            X 1 Reply Last reply Mar 28, 2024, 12:45 PM Reply Quote 0
            • X
              xAgamemnon @xAgamemnon
              last edited by Mar 28, 2024, 12:38 PM

              I changed once again to options shown below:
              stablisheddddededeede.png
              tunelowanie ipsec.png
              Now I can ping the WAN and Gateway but host cannot see each other:
              pingowanie 2.png

              1 Reply Last reply Reply Quote 0
              • X
                xAgamemnon @michmoor
                last edited by Mar 28, 2024, 12:45 PM

                @michmoor Here are the logs:
                Logs IPSEC Site A.txt
                Log IPSEC site B.txt
                Here are the rules on IPSEC:
                ipsec rules.png

                V 1 Reply Last reply Mar 28, 2024, 1:51 PM Reply Quote 0
                • V
                  viragomann @xAgamemnon
                  last edited by Mar 28, 2024, 1:51 PM

                  @xAgamemnon
                  Do both host use the pfSense in in their LAN as default gateway?

                  Do the hosts themself allow access from outside of their local network?
                  Maybe disable their firewalls and reboot them then.

                  X 1 Reply Last reply Mar 28, 2024, 2:04 PM Reply Quote 0
                  • X
                    xAgamemnon @viragomann
                    last edited by xAgamemnon Mar 28, 2024, 2:05 PM Mar 28, 2024, 2:04 PM

                    @viragomann yes both host use pfsense as default gateway and everything is allowed in firewall as i shown above

                    V 1 Reply Last reply Mar 28, 2024, 2:07 PM Reply Quote 0
                    • V
                      viragomann @xAgamemnon
                      last edited by Mar 28, 2024, 2:07 PM

                      @xAgamemnon
                      I was talking about the firewalls on the host behind pfSense.

                      X 1 Reply Last reply Mar 28, 2024, 2:19 PM Reply Quote 0
                      • X
                        xAgamemnon @viragomann
                        last edited by Mar 28, 2024, 2:19 PM

                        @viragomann That's what I've figured out, after disabling the microsoft defender firewall I can ping between sites without any problem now I just need to add a rule so that this network traffic is allowed. Thanks a lot for help, I don't know why I haven't come across this before

                        V 1 Reply Last reply Mar 28, 2024, 2:30 PM Reply Quote 1
                        • V
                          viragomann @xAgamemnon
                          last edited by Mar 28, 2024, 2:30 PM

                          @xAgamemnon
                          The Windows firewall allows basic access like pings from within the local subnet by default, but not from outside.
                          So access normally works as long as it doesn't pass a router.

                          1 Reply Last reply Reply Quote 1
                          • F
                            fcostars @xAgamemnon
                            last edited by Apr 1, 2024, 9:11 PM

                            @xAgamemnon
                            Estou com o mesmo problema, eu configurei dois pfsenses um matriz e outro filial, mas eu só consigo pingar o pfsense do outro lado e mais nada!
                            dentro da mesma rede pinga normal, mas tanto da matriz como da filial eu nao consigo pingar nenhum micro a não ser o pfsense do outro lado.

                            nas configurações de firewall esta tudo liberado entre os tuneis...

                            alguém tem alguma ideia?

                            F 1 Reply Last reply Apr 2, 2024, 11:28 AM Reply Quote 0
                            • F
                              fcostars @fcostars
                              last edited by Apr 2, 2024, 11:28 AM

                              @fcostars Resolvido!
                              Estava clonando configuração ipsec para não digitar tudo novamente e dessa forma o firewall se perde!

                              Segue a dica! Nunca clone uma regra e sim reescreva novamente!

                              1 Reply Last reply Reply Quote 0
                              14 out of 14
                              • First post
                                14/14
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                This community forum collects and processes your personal information.
                                consent.not_received