Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Something not quite right about IPsec…

    IPsec
    2
    4
    1817
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Timmeh last edited by

      Here is the setup:

      192.168.102.0/24 <-> Pfsense1 (84.83.82.81) <-> INET <-> (20.21.22.23) Pfsense2 <-> 192.168.1.0/24

      I have setup the IPsec tunnels on both ends, IPsec status shows the appropriate entries as expected.
      Pfsense1 can ping the 192.168.1.0/24 network from its LAN interface.
      Pfsense2 can ping the 192.168.102.0/24 network from its LAN interface.

      This suggests that the tunnel is established, up and running. However, when hosts on the 192.168.1.0/24 network try and ping hosts on the 192.168.102.0/24 network the ping times out.

      When I try a traceroute from the 192.168.1.0/24 network, traffic leaves the WAN interface of Pfsense2 and starts hitting ISP routers to a certain point before timing out / getting blocked. Surely traffic destined for that network should be encrypted and therefore we should only see one hop before getting to the 192.168.102.0/24 network (pfsense2 LAN address).

      Any input would be greatly appreciated.

      Thanks

      1 Reply Last reply Reply Quote 0
      • H
        hoba last edited by

        Are you using multiwan/loadbalancing? If yes you need some rules on top of your multiwanrules to exclude the ipsec destination subnets from the loadbalancing.

        1 Reply Last reply Reply Quote 0
        • T
          Timmeh last edited by

          We are making use of multi-wan. That fixed my problem. Thanks :)

          1 Reply Last reply Reply Quote 0
          • H
            hoba last edited by

            Good guess  ;D

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense Plus
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy