Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec tunnels going down and some not coming up again…

    Scheduled Pinned Locked Moved IPsec
    4 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sup3rior
      last edited by

      Seeing som behavior I'd like get some input on…

      Running around 30 IPsec tunnels where some of them apparentley are sitting on lines that from time to time can be unstable.
      If the tunnel go down, the pfSense doesn't always detect this (in the sense that it is still shown as up in the Status\IPsec.

      The odd part here is that this problem only occurs when the remote peer is a pfSense device. Other devices are running primarily Zyxel devices, which seems to be able to re-establish the tunnel by themselves, where on the tunnels with both endpoints being pfSense the tunnel has to be forcebly closed to re-establish. Have tried enabling DPD on both sides of the tunnel, but it still exhibits this behavior.

      Any suggestions?

      1 Reply Last reply Reply Quote 0
      • S
        SeventhSon
        last edited by

        Turn on DPD on both ends?

        1 Reply Last reply Reply Quote 0
        • S
          Sup3rior
          last edited by

          @SeventhSon:

          Turn on DPD on both ends?

          Have tried that already…

          1 Reply Last reply Reply Quote 0
          • S
            SectorNine50
            last edited by

            Try setting the "automatically ping host" setting in the pfSense box to a client on the other side of the tunnel.  I was having a similar issue and this kept the tunnel alive.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.