• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSec interface not always get a routing entry

Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
3 Posts 1 Posters 908 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G Offline
    ggzengel
    last edited by Apr 2, 2013, 1:51 AM

    If I choose interface (em1=wan=static ip) as interface for an ipsec tunnel it didn't make a route for the destination ip.
    If I choose interface (em2=opt1=dhcp) or interface (em3=opt2=pppoe) I get a route to the destination ip.
    If I turn back to interface (em1=wan=static ip) the wrong route will still exist until reboot. After reboot there is no new route.

    A second pfsense don't have this problem.

    But they have both the problem not to add/delete a route if I use a GW group as an interface.

    1 Reply Last reply Reply Quote 0
    • G Offline
      ggzengel
      last edited by Apr 7, 2013, 11:17 PM

      I made a research on this.

      If a interface has dhcp there will be a host route to the ipsec destination.
      If a interface has a static IP there is no route.

      If you change the settings for ipsec from WAN1 (dhcp) to WAN2 (static ip) the route over WAN1 still exists and ipsec won't work until you reboot the pfsense and the route is deleted.

      I think the route for ipsec over a dhcp interface is no longer needed.
      If you still use a route failover won't work if the second pfsense route to local WAN1 which has already failed.

      1 Reply Last reply Reply Quote 0
      • G Offline
        ggzengel
        last edited by Apr 9, 2013, 4:23 PM

        That's a bug:

        If you change the settings for ipsec from WAN1 (dhcp) to WAN2 (static ip) the route over WAN1 still exists and ipsec won't work until you reboot the pfsense and the route is deleted.

        I don't know if this is still wanted, because if it's use gateway groups or static IPs no routes are made:

        If a interface has dhcp there will be a host route to the ipsec destination.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received