Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No traffic, tunnels in the green

    Scheduled Pinned Locked Moved IPsec
    28 Posts 9 Posters 14.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      AH traffic is not encrypted, only authenticated. I would fix the device that supposedly requires AH, as otherwise you're sending all of this traffic with no protection.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • H
        htgtech
        last edited by

        Unfortunately we can't dictate to the 3rd party how they should set up their VPN tunnel, they get to dictate to us what we have to set up in order to connect to them.

        1 Reply Last reply Reply Quote 0
        • B
          bkm
          last edited by

          htgtech
          You do know that you need to set up separate tunnels, right? The tunnels to your routers could have the ESP setting and the tunnel to the third party could use AH. I apologize if this answer is beneath you. I don't know anyone's experience level.

          1 Reply Last reply Reply Quote 0
          • H
            htgtech
            last edited by

            I realize the need for seperate tunnels, as I have 5 tunnels already set up on the main router to go to the other routers. However, the problem still remains that the AH protocol is not allowing traffic which would still be an issue on the other tunnel to the 3rd party. Unless the problem is only with 2 pfsense routers trying to use AH.

            1 Reply Last reply Reply Quote 0
            • V
              Visseroth
              last edited by

              I just realized something. I am getting traffic from 192.168.0.0 to 10.0.0.0 but not from 10.0.0.0 to 192.168.0.0 which is how I want it. How can I change the order so that traffic from 10.0.0.0 can get to 192.168.0.0. If  I can get that traffic to flow then what I am trying to connect to should work as I can ping from 192.168.0.0 but not from 10.0.0.0

              1 Reply Last reply Reply Quote 0
              • V
                Visseroth
                last edited by

                I also just noticed that I'm getting a sendfromto failed error on 192.168.0.0

                " racoon: ERROR: sendfromto failed"

                1 Reply Last reply Reply Quote 0
                • V
                  Visseroth
                  last edited by

                  Well in new news I setup a tunnel between me and another local location and it was working fine then went down. I brought the tunnels back up but again I can't get traffic through the tunnels.

                  1 Reply Last reply Reply Quote 0
                  • I
                    ISCGDave
                    last edited by

                    @Visseroth:

                    Well in new news I setup a tunnel between me and another local location and it was working fine then went down. I brought the tunnels back up but again I can't get traffic through the tunnels.

                    Can I ask what version you have at both locations?

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.