Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    IPSec behind ISP Router

    Scheduled Pinned Locked Moved IPsec
    8 Posts 3 Posters 188 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Stixdee01
      last edited by

      Re: IPSEC behind ISP router

      Has there been any solution to this problem as 5 years later i am experiencing the same problem.

      SteveITSS S 3 Replies Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @Stixdee01
        last edited by

        @Stixdee01 set pfSense as the ISP router DMZ, or else forward the desired ports to pfSense.

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote ๐Ÿ‘ helpful posts!

        1 Reply Last reply Reply Quote 0
        • S Offline
          Stixdee01 @Stixdee01
          last edited by

          said in IPSec behind ISP Router:

          Re: IPSEC behind ISP router

          Has there been any solution to this problem as 5 years later i am experiencing the same problem.

          Here is my connection diagram, how do i setup IPSec in this scenario because when i try its failing, how to double NAT successfully.Ipsec Behind Router.png

          1 Reply Last reply Reply Quote 0
          • S Offline
            Stixdee01 @Stixdee01
            last edited by

            i have forwarded ports 500 and 4500 without any luck. and tried the DMZ Feature still not connecting.

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              Stixdee01 @Stixdee01
              last edited by

              Jul 29 08:47:23 WAN Default deny rule IPv4 (1000000103) 33.333.333.76:40029 10.0.0.2:16589

              I see this entry in the firewall and when i set to pass, its not making any difference, i also have my firewall rules to allow all lan segments to pass to each other. NB: i changed the public Ip, for security reasons.

              SteveITSS 1 Reply Last reply Reply Quote 0
              • SteveITSS Offline
                SteveITS Rebel Alliance @Stixdee01
                last edited by

                @Stixdee01 I don't know what port 16589 is. by default pfSense logs all connection attempts on WAN even though they will be denied, so expect a lot of noise in the logs.

                forwarded ports 500 and 4500

                UDP?

                IPSec needs ESP protocol also. However pfSense allows what it needs for IPSec by default. So your issue is the ISP router. Have you asked them if they allow IPSec/VPN connections?

                Your public IP is a real IP and not CGNAT?

                To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                Only install packages for your version of pfSense.
                Upvote ๐Ÿ‘ helpful posts!

                S 1 Reply Last reply Reply Quote 0
                • M Offline
                  mcury Rebel Alliance
                  last edited by mcury

                  Usually this is related to ALG, make sure IPSEC is ticked at the ISP router.
                  pfSense WAN IP should be in DMZ also.

                  dead on arrival, nowhere to be found.

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    Stixdee01 @SteveITS
                    last edited by

                    @SteveITS Thank you for the heads up, i've done all as you asked above and still no luck, i have opted to request ISP to change and allow the router to work in bridge mode, and use PfSense as the public interface.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                    Privacy Policy · Cookie Policy