PFsense 2.01 cisco anyconnect from lan to wan doesn't work



  • Hello,

    I am using pfsense on alix 1d3 and PPTP dialup in Austria with the MTU of 1460 settings…
    Why pfsense blocking the cisco anyconnect if I want to connect tot he company network from home?
    I try to set the firewall Firewall Optimization Options to conservative but this doesn't help.

    Is this because the MTU is set to 1460?

    KR

    Pbk



  • Hello,

    is there no Firewall Expert out there who knows to setup the PFsense for VPN pass through?
    The old PFsense 1.23 VPN pass through works, and also there is no hacking for the WAN PPTP needed…

    KR

    PbK



  • push…



  • ppppuuuuuusssssshhhhhhh!!!!



  • I'm using Cisco Anyconnect to connect to my work VPN with no issue… didn't do anything special to allow it. What debugging steps did you go through? How do you know that pfsense is blocking the connection?


  • Rebel Alliance Global Moderator

    So what is not working the TLS portion or the DTLS portion.  There should really be nothing to do on pfsense to allow this traffic, unless you have modified your outbound rules.

    I do believe your going to make a connection over tcp 443, and then it will try and switch to DTLS which is UDP over 443.



  • Hello,

    I use PfSense 2.01 on an Alix hardware.

    I use all three hardware interfaces and the wifi module, the wifi setup is done that it is using the same IP range for lan and wifi (bridged interface).

    How i debug it –> when I use the mobile hotspot of my smartphone cisco anyconnect is connecting and the connection is up as long as I want it, but through the PfSense the connection dropped after one second, so the client reconnect and the connection dropped again and again....

    There is no specific outbound rule --> what exactly to you mean?

    KR

    PbK


  • Rebel Alliance Global Moderator

    And again - what type of connection are you making..  Anyconnect should work over just a TCP 433 connection just like any website, it will try and use DTLS (udp) – is this where its failing?

    Do you see anything in the firewall log about something blocked - what does the anyconnect client say??


Locked