Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense blocking VPN access?

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 4 Posters 6.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      Mif
      last edited by

      I have recently installed a pfsense router. I can no longer connect to my work's VPN. Whats odd, is when I do a traceroute from the router to the VPN, it resolves correctly. When attempting to do the same on a system on the network, it times out at the next to last hop to the destination.

      Firewall logs don't show any thing of note to the issue.

      Any ideas on why this is?

      1 Reply Last reply Reply Quote 0
      • C Offline
        cmb
        last edited by

        What kind of VPN?

        1 Reply Last reply Reply Quote 0
        • M Offline
          Mif
          last edited by

          They are all Cisco VPN units I am trying to connect to.

          1 Reply Last reply Reply Quote 0
          • Cry HavokC Offline
            Cry Havok
            last edited by

            That's the brand, what technology?  That I know of Cisco have IPsec, PPTP and SSL products.

            1 Reply Last reply Reply Quote 0
            • E Offline
              EddieA
              last edited by

              Hmmmmmm.  This sounds familiar.

              Cheers.

              1 Reply Last reply Reply Quote 0
              • M Offline
                Mif
                last edited by

                Thanks for that Eddie. It does sound familiar.

                Was there ever a result to that issue?

                I did confirm, we are using Cisco Client  under ipsec to a cisco VPN on the server side.

                Does going back to 1.2.2 work?

                Thanks! :)

                1 Reply Last reply Reply Quote 0
                • E Offline
                  EddieA
                  last edited by

                  @Mif:

                  Was there ever a result to that issue?

                  Yes, my wife's company changed their VPN Client software, while I was still trying to resolve it.  ;D

                  You can check if it's the same issue, by running a packet trace.  As I mentioned, mine broke when the Client sent out a UDP packet bigger than the MTU size, of 1500, which resulted in a fragmented packet.  The server never responded to that packet.

                  There was also, on the same thread, a report that the em driver was possibly corrupting fragmented UDP packets.  I was at the point, where my next trace, was to be with a different NIC, and hence different driver, to see if that conjecture was correct.  But alas, the VPN Client was changed before I could do that.

                  Cheers.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.