Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ever since I had a bad Phase 2, routing is messed up. I do not understand why!

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wil
      last edited by

      Before I asked my other question, I was trying out a lot of different configs.

      I set up a Phase 2 of 192.168.0.x/21 on Site A, and 192.168.10.x/24 on Site B - this worked great and all hosts could ping all hosts without any issue.

      When trying to add the second phase 2, one of the combinations I tried adding was the local subnet as the remote (I believe, but can't honestly remember). Ever since then, the tunnel has been "screwed".

      Right now, it is in a state where:

      Anything on Site B can ping/access anything on Site A
      Nothing on Site A can ping/access anything on Site B - With the exception of:
          PFSense Box from Site A can ping PFSense Box on Site B… but nothing else on Site B.

      To try and fix:

      I deleted the second rule.
      I deleted the entire phase one and two on both ends and recreated.
      I have backed up PFSense Config and done a restore. (And looked through a text editor/saw nothing non-normal).
      Restarted Racoon, deleted all SAD/SPDs, along with restarting the server after each config change on the hopes it will fix!
      I have done everything else short of factory resetting the box (which I believe should fix it since it did work before!), but, I really don't want to do this - I want to understand what has gone wrong.

      Does anyone have any idea what is wrong here?

      1 Reply Last reply Reply Quote 0
      • C
        craigduff
        last edited by

        Yea i do! Just ring me!! :-)

        Kind Regards,
        Craig

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.