Outbound packets being dropped after egressing IPSec
-
In short, replies to ping/TCP work perfectly in Site A servers, but sending ping/TCP from Site A servers is silently dropped mid-tunnel.
Setup: vti IPSec with BGP route exchange
- Site A (pfsense): BGP Peer 169.254.0.66 - Advertises 192.168.10.5/32
- Site B (Fortigate): BGP Peer 169.254.0.65 - Advertises 10.200.0.0/21
- In Site A, NAT is used to translate original server IP of 192.168.1.5 to 192.168.10.5 before egressing over IPSec - 1:1 NAT and Outbound NAT matching on IPSec
- Outbound firewall rules for LAN and inbound firewall rules for IPSec are fully permissive

IPSec establishes without error, BGP route exchange is okay, when sending from a server on site B (say 10.200.0.41), request and reply traffic transits the tunnel without issue. The only problem is when requests are made from site A servers to site B servers. In this case the traffic appears to egress correctly (can be seen in packet captures on both the source server and the IPSec interface) but packet captures and counters on the remote side do not reflect this.

Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
Privacy Policy · Cookie Policy
Privacy Policy · Cookie Policy