<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cannot ping DHCP clients]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Im running Pfsense 1.2.3 and im trying to configure IPSEC for mobile clients.<br />
I can ping/access all my clients with a static IP. The problem is that i cant connect to clients with an IP from the DHCP pool.</p>
<p dir="auto">I also recieve this messages in the IPSEC logs:<br />
x.x.x.x and y.y.y.y are IP's</p>
<p dir="auto">Feb 3 21:25:42 racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA established x.x.x.x[500]-y.y.y.y[500] spi:9d74558fb89b94e9:88d136cf26ff50c4<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: INFO: respond new phase 2 negotiation: x.x.x.x[0]&lt;=&gt;y.y.y.y[0]<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: INFO: no policy found, try to generate the policy : 192.168.50.10/32[0] 192.168.1.0/24[0] proto=any dir=in<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP y.y.y.y[0]-&gt;x.x.x.x.x[0] spi=69410748(0x4231fbc)<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP x.x.x.x[0]-&gt;y.y.y.y.y[0] spi=2750655360(0xa3f3ab80)<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.50.10/32[0] 192.168.1.0/24[0] proto=any dir=in"<br />
Feb 3 21:25:47 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.1.0/24[0] 192.168.50.10/32[0] proto=any dir=out"<br />
Feb 3 21:27:40 racoon: INFO: generated policy, deleting it.<br />
Feb 3 21:27:40 racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA expired x.x.x.x[500]-y.y.y.y[500] spi:9d74558fb89b94e9:88d136cf26ff50c4<br />
Feb 3 21:27:41 racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA deleted x.x.x.x[500]-y.y.y.y[500]</p>
]]></description><link>https://forum.netgate.com/topic/21222/cannot-ping-dhcp-clients</link><generator>RSS for Node</generator><lastBuildDate>Thu, 23 Apr 2026 03:21:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/21222.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 03 Feb 2010 21:04:26 GMT</pubDate><ttl>60</ttl></channel></rss>