Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec Tunneling

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 324 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thanosg
      last edited by

      IPsec.jpg

      I have the topology as shown in the diagram. I have established IPsec Connection from FW1 to FW3 and tunnels are UP.

      Also I have added rules in IPsec Interface to allow any-any in both firewalls.

      I have added rules in FW2 to allow ports 4500 and 500.

      The problem is that i cannot ping from one site to another (neither the PCs nor the FWs)

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @thanosg
        last edited by

        @thanosg
        Do you see your tunnels established properly in Status > IPsec > SPDs?

        If so probably your devices block the access. Remember that devices by default block access from outside of their local subnet. You will have to allow it in the PCs firewalls of each.

        T 1 Reply Last reply Reply Quote 0
        • T
          thanosg @viragomann
          last edited by

          @viragomann snip 1.png snip 2.png

          The screenshots show the tunnel status. In my eyes it seems ok.

          The PCs in both ends have a linux mint with no specific firewall rules.

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @thanosg
            last edited by

            @thanosg
            As well a Linux firewall blocks remote access by default.
            Disable it an try or sniff the traffic in pfSense on the involved interfaces to investigate the issue.

            T 1 Reply Last reply Reply Quote 0
            • T
              thanosg @viragomann
              last edited by

              @viragomann the mint firewalls on both ends are allow any any

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.