<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec tunnels passing no traffic showing green in status DPD]]></title><description><![CDATA[<p dir="auto">Just wondering if anyone else has come across this problem before. Running Pfsense 2.0.1 on 14 sites.</p>
<p dir="auto">Each site is setup with all default values, the only information I have filled in was the hostname and preshared key. Phase 2 is the same only information that is filled in is the network subnet and the IP address to ping (I used the remote sides internal PFsense box ip here). Works fantastic when up.</p>
<p dir="auto">So far I have had a few drops in where PFsense has no idea that the tunnel is actually dropped. Status shows green with no mention of any problems in the logs regarding the tunnel or DPD actually doing anything.</p>
<p dir="auto">I have DPD setup with all default values 10 seconds, 5 retry. How long does this actually take to detect a problem?</p>
<p dir="auto">These sites are connected with pretty reliable internet connections that rarely go down, most are even static sites. Is there better settings that could be used?</p>
<p dir="auto">When I reset the IPsec services on the device all seems to be restored. I have been doing this though a public IP port forward for testing. On each side it still shows green minutes after the connection goes down.</p>
<p dir="auto">I have done some googling and have come up with switching to main mode vs aggressive, disabling NAT-T and DPD. Has anyone had any luck with these suggestions?</p>
]]></description><link>https://forum.netgate.com/topic/45264/ipsec-tunnels-passing-no-traffic-showing-green-in-status-dpd</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 23:51:17 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/45264.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 24 May 2012 01:48:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPsec tunnels passing no traffic showing green in status DPD on Thu, 19 Jul 2012 09:02:36 GMT]]></title><description><![CDATA[<p dir="auto">PFSENSE, NANOBSD, 2.0.1<br />
I had the same problem, IPSEC tunnel was establised, all green, no traffic goes through.<br />
When you look at SAD, SAD (Status,Ipsec, SAD)shows me multiple connections.<br />
I think, the reason are short interrupts, Phase1 does not recognise the break, stays established, but Phase2 opens a new connection.<br />
But this does not work.<br />
My solution:<br />
Change Mode from aggressive to main on both sides. (even with dynamic IPs)</p>
]]></description><link>https://forum.netgate.com/post/347645</link><guid isPermaLink="true">https://forum.netgate.com/post/347645</guid><dc:creator><![CDATA[chia]]></dc:creator><pubDate>Thu, 19 Jul 2012 09:02:36 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec tunnels passing no traffic showing green in status DPD on Wed, 13 Jun 2012 19:16:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/themixer">@<bdi>themixer</bdi></a>:</p>
<blockquote>
<p dir="auto">These sites are connected with pretty reliable internet connections that rarely go down, most are even static sites. Is there better settings that could be used?</p>
</blockquote>
<p dir="auto">What is your setting of "Prefer older IPsec SAs" (System -&gt; Advanced -&gt; Miscellaneous -&gt; IPsec) ?</p>
<p dir="auto">Are you running PPTP server on the same machine ?</p>
]]></description><link>https://forum.netgate.com/post/341670</link><guid isPermaLink="true">https://forum.netgate.com/post/341670</guid><dc:creator><![CDATA[dhatz]]></dc:creator><pubDate>Wed, 13 Jun 2012 19:16:32 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec tunnels passing no traffic showing green in status DPD on Tue, 12 Jun 2012 13:51:37 GMT]]></title><description><![CDATA[<p dir="auto">Have you put Firewall rules in to allow traffic over the IPSec Interface at each site? I had this same issue the first time I set up IPSec tunnels with pfSense and it took a while to realize what needed to be done.</p>
<p dir="auto">–<br />
Seth</p>
]]></description><link>https://forum.netgate.com/post/341360</link><guid isPermaLink="true">https://forum.netgate.com/post/341360</guid><dc:creator><![CDATA[sethfeaganes]]></dc:creator><pubDate>Tue, 12 Jun 2012 13:51:37 GMT</pubDate></item><item><title><![CDATA[Reply to IPsec tunnels passing no traffic showing green in status DPD on Mon, 28 May 2012 12:46:11 GMT]]></title><description><![CDATA[<p dir="auto">Anyone?</p>
]]></description><link>https://forum.netgate.com/post/338744</link><guid isPermaLink="true">https://forum.netgate.com/post/338744</guid><dc:creator><![CDATA[themixer]]></dc:creator><pubDate>Mon, 28 May 2012 12:46:11 GMT</pubDate></item></channel></rss>