IPSec behind ISP Router
-
Has there been any solution to this problem as 5 years later i am experiencing the same problem.
-
@Stixdee01 set pfSense as the ISP router DMZ, or else forward the desired ports to pfSense.
-
said in IPSec behind ISP Router:
Has there been any solution to this problem as 5 years later i am experiencing the same problem.
Here is my connection diagram, how do i setup IPSec in this scenario because when i try its failing, how to double NAT successfully.

-
i have forwarded ports 500 and 4500 without any luck. and tried the DMZ Feature still not connecting.
-
Jul 29 08:47:23 WAN Default deny rule IPv4 (1000000103) 33.333.333.76:40029 10.0.0.2:16589
I see this entry in the firewall and when i set to pass, its not making any difference, i also have my firewall rules to allow all lan segments to pass to each other. NB: i changed the public Ip, for security reasons.
-
@Stixdee01 I don't know what port 16589 is. by default pfSense logs all connection attempts on WAN even though they will be denied, so expect a lot of noise in the logs.
forwarded ports 500 and 4500
UDP?
IPSec needs ESP protocol also. However pfSense allows what it needs for IPSec by default. So your issue is the ISP router. Have you asked them if they allow IPSec/VPN connections?
Your public IP is a real IP and not CGNAT?
-
Usually this is related to ALG, make sure IPSEC is ticked at the ISP router.
pfSense WAN IP should be in DMZ also. -
@SteveITS Thank you for the heads up, i've done all as you asked above and still no luck, i have opted to request ISP to change and allow the router to work in bridge mode, and use PfSense as the public interface.
Privacy Policy · Cookie Policy