Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec such policy does not already exist

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 7.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      ameno_123
      last edited by

      Hi,
      I have this erreur in my log :

      racoon: ERROR: such policy does not already exist: "192.168.0.0/24[0] 192.168.1.10/32[0] proto=any dir=out"
      racoon: ERROR: such policy does not already exist: "192.168.1.10/32[0] 192.168.0.0/24[0] proto=any dir=in"

      My lan office : 192.168.0.0
      Pfsense IP : 192.168.0.1
      My IP home : 192.168.1.10

      I want connect to my office with IPsec.
      I ping Pfsense, i dont ping my server office : 192.168.0.100

      firewall log :
      block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1599, length 40
      4. 996311 rule 74/0(match): block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1600, length 40
      4. 995961 rule 74/0(match): block in on enc0: 192.168.1.10 > 192.168.0.100: ICMP echo request, id 1, seq 1601, length 40

      what is the solution!?

      nb: excuse my bad english (:

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That error is normal, especially if your tunnels are using main mode.

        It looks like you need to add firewall rules on the IPsec tab under Firewall > Rules. If you want to allow everything add a rule to allow all protocols from any to any. Be sure you set the protocol to "any" because it defaults to TCP.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • A
          ameno_123
          last edited by

          :) work fine.. tnks
          I ping only ip dhcp on remote network, and i dont ping de fixed ip…

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.