<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Pfsense IPsec: no traffic after WAN timeout.]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Currently I am experiencing some problems with VPN (IPsec) connections between Pfsense and other<br />
routers. The problem mainly occurs when there is a (slight) timeout between the VPN endpoints,<br />
after the connection is reestablished VPN on both sides are “up” but there is no traffic passing<br />
the tunnel. The problem can be solved by disabling and enabling IPsec (restarting Racoon) or by<br />
disabling en enabling the Phase 1 entry of the troubling connection.</p>
<p dir="auto">I am using the following router combinations and settings:</p>
<ul>
<li>Pfsense - Cisco 1921.</li>
<li>Pfsense - Bintec R3002.</li>
<li>Pfsense - Draytek 2930.</li>
<li>Pfsense - Juniper SSG5.</li>
</ul>
<p dir="auto">Phase 1:</p>
<ul>
<li>Encryption: 3DES/SHA1</li>
<li>Main mode</li>
<li>Lifetime: 28800</li>
<li>DH: 2</li>
</ul>
<p dir="auto">Phase 2:</p>
<ul>
<li>Encryption: 3DES/MD5</li>
<li>PFS: off</li>
<li>ESP</li>
</ul>
<p dir="auto">The most research is done with the Bintec R3002, both endpoints are connected directly to the<br />
internet without NAT networks between them.</p>
<p dir="auto">I’ve tried different settings with different outcomes:</p>
<ul>
<li>Tried Prefer older Ipsec SA’s, which does help when rekeying but doesn’t fix the problem.</li>
<li>Tried DPD on and off, no difference.</li>
<li>Tried forced NAT-T which seems to cause different behavior. With NAT-T enabled the Pfsense<br />
does detect when a Ipsec connection is “broken” without NAT-T the connection keeps the status<br />
“UP” even when the connection on the other side is disabled. In other words Pfsense doesn’t seem to detect a broken VPN connection (DPD doesn’t work??).<br />
With NAT-T enabled Pfsense does detect a broken VPN connection but when the connection is<br />
reestablished no traffic is passing the tunnel.</li>
</ul>
<p dir="auto">When I connect the Bintec to the Draytek (IPSEC) on the same WAN links the connections are stable.<br />
When I disconnect the WAN links on purpose the VPN traffic resumes some 30 seconds after the WAN link is connected again.<br />
For some reason this doesn’t seem to well in my scenario, does anyone have experience with this<br />
problem or have any idea how to solve this and how to create stable VPN connections with Pfsense?</p>
<p dir="auto">Kind regards,<br />
Luuk</p>
]]></description><link>https://forum.netgate.com/topic/54702/pfsense-ipsec-no-traffic-after-wan-timeout</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 09:08:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/54702.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 29 Mar 2013 15:31:20 GMT</pubDate><ttl>60</ttl></channel></rss>