WAN <> OPT3 TUNNEL PROBLEMS
-
I HAVE THE FOLLOWING IPSEC WAN/OPT3 PROBLEM, WHEN I SWITCH THE LOCAL AND REMOTE GATEWAY OF TUNNEL FOR EXAMPLE WAN-TO-OPT3, OR VICEVERSA, MI OTHER OPT3 TUNNELS GET DOWN (ALSO TIMES AFTER REBOOT THE PFSENSE SOME OPT2 TUNNELS DON'T GET UP), I HAVE TO FISICALLY DISCONNECT MY OPT2 ROUTER (BRIDGED TO OPT2, WAN AND OPTT1 ARE ALSO BRIDGED) ABOUT 5 MIN. TO RECOVER THE CONNECTION, AT TIMES I DON'T RECOVER ALL THE TUNNELS AND I HAVE TO DELETE ALL THE SPD, SAVE AND REAPPLY THE IPSEC CONFIG, DISABLE/ENABLE IT, ETC, AND MAGICALLY THE TUNNELS RECOVER CONNECTION. AT TIMES THE REMOTE TUNNEL SAYS ESTABLISHED (DLINK DI804), I SEE THE KEYS CREATED (SAD AND SPD) OK, BUT I DONT GET TRAFFIC BETWEEN SITES. ???
ALSO ON A NOT WORKING OPT3 TUNNEL, IF I CHANGE THE INTERFACE TO WAN AND THE REMOTE GATEWAY ACORDLY, THE CONNECTION GET INSTANTANLY UP!? :o
I GET SOME LOG MESSAGES "…PACKET RETRANSMITTED BY....[500])"
SOMETIMES I HAVE TO RESTART THE REMOTE GATEWAYS ON OPT3 TO RECOVER CONNECTIVITY.
WITH THE TUNNELS ON WAN INTERFACE I DON'T HAVE PROBLEMS. ;)
HERE ARE TALKING ABOUT 15 TUNNELS ON WAN AND 8 TUNNELS ON OPT3.
HELP PLEASE!… :'(