<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC - RC1 and RC2]]></title><description><![CDATA[<p dir="auto">Just wondering if something changed between RC1 and RC2?  When I was running RC1 I could ping either way from the customer site to my site and from mysite to the customer.  With the lastest verison of RC2 I can ping to the customer but the customer can't ping back to me.  I was wondering wht minght have changed?  and if I have to create a rule to allow traffic from that network back to mine now.<br />
RC</p>
]]></description><link>https://forum.netgate.com/topic/5825/ipsec-rc1-and-rc2</link><generator>RSS for Node</generator><lastBuildDate>Tue, 09 Jun 2026 00:05:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/5825.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 18 Sep 2007 13:35:32 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Thu, 08 Nov 2007 10:28:33 GMT]]></title><description><![CDATA[<p dir="auto">Problem still exist in RC3. I really like the new IPsec connection status symbols and the IPsec highlighting in the log files. It would be great if the mobile clients could be shown also.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/IPsec.png" alt="IPsec.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/IPsec.png_thumb" alt="IPsec.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/161560</link><guid isPermaLink="true">https://forum.netgate.com/post/161560</guid><dc:creator><![CDATA[heureka]]></dc:creator><pubDate>Thu, 08 Nov 2007 10:28:33 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 08 Oct 2007 01:23:08 GMT]]></title><description><![CDATA[<p dir="auto">I have my pfsense firewall offline due to two issues.</p>
<p dir="auto">1.  If I enable the rule for IPSEC the firewall reboots every 5 minutes.<br />
2.  IPSEC passthrough quit.</p>
<p dir="auto">Let me know what I can due to give you all any information.  I will even let you in the firewall remotely so that you can pull logs or any information.</p>
<p dir="auto">RC</p>
]]></description><link>https://forum.netgate.com/post/160367</link><guid isPermaLink="true">https://forum.netgate.com/post/160367</guid><dc:creator><![CDATA[fastcon68]]></dc:creator><pubDate>Mon, 08 Oct 2007 01:23:08 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Fri, 05 Oct 2007 07:04:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cmb">@<bdi>cmb</bdi></a>:</p>
<blockquote>
<p dir="auto">Can you post a screenshot of that error?</p>
</blockquote>
<p dir="auto">Since no one posted this screenshot and the problem still exists in recent builds here we go:</p>
<p dir="auto">![pfSense IPsec overview error.png](/public/<em>imported_attachments</em>/1/pfSense IPsec overview error.png)<br />
![pfSense IPsec overview error.png_thumb](/public/<em>imported_attachments</em>/1/pfSense IPsec overview error.png_thumb)</p>
]]></description><link>https://forum.netgate.com/post/160260</link><guid isPermaLink="true">https://forum.netgate.com/post/160260</guid><dc:creator><![CDATA[jahonix]]></dc:creator><pubDate>Fri, 05 Oct 2007 07:04:54 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 24 Sep 2007 21:21:19 GMT]]></title><description><![CDATA[<p dir="auto">Yeah, mine is up again as well but still shows those errors.<br />
Took about half an hour or so with pfSense on both ends. Dunno why.</p>
]]></description><link>https://forum.netgate.com/post/159973</link><guid isPermaLink="true">https://forum.netgate.com/post/159973</guid><dc:creator><![CDATA[jahonix]]></dc:creator><pubDate>Mon, 24 Sep 2007 21:21:19 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 24 Sep 2007 19:02:06 GMT]]></title><description><![CDATA[<p dir="auto">you are right, i can duplicate…...</p>
<p dir="auto">but the tunnel is up...., strange</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/ScreenShot001.jpg" alt="ScreenShot001.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ScreenShot001.jpg_thumb" alt="ScreenShot001.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/159969</link><guid isPermaLink="true">https://forum.netgate.com/post/159969</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Mon, 24 Sep 2007 19:02:06 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 24 Sep 2007 18:12:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cmb">@<bdi>cmb</bdi></a>:</p>
<blockquote>
<p dir="auto">ssbaksa:  Can you post a screenshot of that error?</p>
</blockquote>
<p dir="auto">No luck there. Only one thing but that is GUI, tabs on IPSec log page change to BIG font and only on that tab - table is unafected.</p>
]]></description><link>https://forum.netgate.com/post/159967</link><guid isPermaLink="true">https://forum.netgate.com/post/159967</guid><dc:creator><![CDATA[ssbaksa]]></dc:creator><pubDate>Mon, 24 Sep 2007 18:12:05 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 24 Sep 2007 14:00:09 GMT]]></title><description><![CDATA[<p dir="auto">I can second what ssbaksa observed.<br />
After upgrading pfSense at my office to current snapshot:  1.2-RC2 built on Mon Sep 24 06:37:23 EDT 2007<br />
the IPsec tunnel between home and office will not come up, instead I have these messages in the Diagnostics: System logs: IPSEC VPN:</p>
<blockquote>
<p dir="auto">Last 500 IPSEC log entries<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.100.0/24[0] 192.168.2.0/24[0] proto=any dir=out"<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.2.0/24[0] 192.168.100.0/24[0] proto=any dir=in"<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP/Tunnel 217.x.y.z[0]-&gt;62.a.b.c[0] spi=223941049(0xd5911b9)<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP/Tunnel 62.a.b.c[0]-&gt;217.x.y.z[0] spi=234153441(0xdf4e5e1)<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: INFO: no policy found, try to generate the policy : 192.168.2.0/24[0] 192.168.100.0/24[0] proto=any dir=in<br />
Sep 24 15:35:11 racoon: [Unknown Gateway/Dynamic]: INFO: respond new phase 2 negotiation: 217.x.y.z[0]&lt;=&gt;62.a.b.c[0]<br />
Sep 24 15:35:10 racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA established 217.x.y.z[500]-62.a.b.c[500] spi:8bb2affd47f2274b:42ee99b4ee3f2066<br />
Sep 24 15:35:10 racoon: INFO: received Vendor ID: DPD<br />
Sep 24 15:35:10 racoon: INFO: begin Aggressive mode.<br />
Sep 24 15:35:10 racoon: [Unknown Gateway/Dynamic]: INFO: respond new phase 1 negotiation: 217.x.y.z[500]&lt;=&gt;62.a.b.c[500]<br />
Sep 24 15:24:03 racoon: INFO: unsupported PF_KEY message REGISTER<br />
Sep 24 15:24:03 racoon: INFO: fe80::…%fxp0[500] used as isakmp port (fd=24)<br />
Sep 24 15:24:03 racoon: <strong>[Self]</strong>: INFO: 10.0.1.1[500] used as isakmp port (fd=23)<br />
Sep 24 15:24:03 racoon: INFO: fe80::…%xl0[500] used as isakmp port (fd=22)<br />
Sep 24 15:24:03 racoon: <strong>[Self]</strong>: INFO: 192.168.100.99[500] used as isakmp port (fd=21)<br />
Sep 24 15:24:03 racoon: INFO: fe80::…%fxp1[500] used as isakmp port (fd=20)</p>
</blockquote>
<p dir="auto">Actually, it worked before - had just used it and saw the same message as SSBAKSA on the newly created IPsec tab: Overview.<br />
Since the tunnel doesn't come up there is no entry to show any more.<br />
It was right underneath the 'Overview' tab on top of the following table header.</p>
]]></description><link>https://forum.netgate.com/post/159957</link><guid isPermaLink="true">https://forum.netgate.com/post/159957</guid><dc:creator><![CDATA[jahonix]]></dc:creator><pubDate>Mon, 24 Sep 2007 14:00:09 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Mon, 24 Sep 2007 01:42:00 GMT]]></title><description><![CDATA[<p dir="auto">fastcon68: Can you still replicate the problem where it starts rebooting when you add ipsec rules? If so, it's panic'ing and I'd like to have you get us a backtrace.</p>
<p dir="auto">ssbaksa:  Can you post a screenshot of that error?</p>
]]></description><link>https://forum.netgate.com/post/159944</link><guid isPermaLink="true">https://forum.netgate.com/post/159944</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Mon, 24 Sep 2007 01:42:00 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Sat, 22 Sep 2007 15:44:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/heiko">@<bdi>heiko</bdi></a>:</p>
<blockquote>
<p dir="auto">try the newest snapshot<br />
http://snapshots.pfsense.com/FreeBSD6/RELENG_1_2/updates/pfSense-Full-And-Embedded-Update-1.2-RC2.tgz<br />
and test it again</p>
</blockquote>
<p dir="auto">It is working now. Now there is only one error on Overview page: Warning: Invalid argument supplied for foreach() in /usr/local/www/diag_ipsec.php on line 103 but SAD and SPD view are OK.</p>
]]></description><link>https://forum.netgate.com/post/159913</link><guid isPermaLink="true">https://forum.netgate.com/post/159913</guid><dc:creator><![CDATA[ssbaksa]]></dc:creator><pubDate>Sat, 22 Sep 2007 15:44:49 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Fri, 21 Sep 2007 13:48:26 GMT]]></title><description><![CDATA[<p dir="auto">try the newest snapshot</p>
<p dir="auto">http://snapshots.pfsense.com/FreeBSD6/RELENG_1_2/updates/pfSense-Full-And-Embedded-Update-1.2-RC2.tgz</p>
<p dir="auto">and test it again</p>
]]></description><link>https://forum.netgate.com/post/159876</link><guid isPermaLink="true">https://forum.netgate.com/post/159876</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Fri, 21 Sep 2007 13:48:26 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Fri, 21 Sep 2007 11:02:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fastcon68">@<bdi>fastcon68</bdi></a>:</p>
<blockquote>
<p dir="auto">I am using the build that was create on Aug 20.  I enable the IPSEC rules and as soon as I did that, the firewall started every 10 to 15 mintutes.  I disabled the rules and the server has been been up and running for over a hour.</p>
</blockquote>
<p dir="auto">Mine is not restarting but when client connects there is no sign of connection in SAD and SPD and no traffic is going trough (Firewall is set to allow all). RC1 works OK. I have tried this on 3 different computers - same result.</p>
]]></description><link>https://forum.netgate.com/post/159871</link><guid isPermaLink="true">https://forum.netgate.com/post/159871</guid><dc:creator><![CDATA[ssbaksa]]></dc:creator><pubDate>Fri, 21 Sep 2007 11:02:37 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Thu, 20 Sep 2007 03:07:21 GMT]]></title><description><![CDATA[<p dir="auto">I am using the build that was create on Aug 20.  I enable the IPSEC rules and as soon as I did that, the firewall started every 10 to 15 mintutes.  I disabled the rules and the server has been been up and running for over a hour.</p>
<p dir="auto">any thoughs?<br />
RC</p>
]]></description><link>https://forum.netgate.com/post/159795</link><guid isPermaLink="true">https://forum.netgate.com/post/159795</guid><dc:creator><![CDATA[fastcon68]]></dc:creator><pubDate>Thu, 20 Sep 2007 03:07:21 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Wed, 19 Sep 2007 12:28:27 GMT]]></title><description><![CDATA[<p dir="auto">I will give it a try when I get home, thanks.<br />
RC</p>
]]></description><link>https://forum.netgate.com/post/159755</link><guid isPermaLink="true">https://forum.netgate.com/post/159755</guid><dc:creator><![CDATA[fastcon68]]></dc:creator><pubDate>Wed, 19 Sep 2007 12:28:27 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC - RC1 and RC2 on Tue, 18 Sep 2007 14:30:13 GMT]]></title><description><![CDATA[<p dir="auto">you need to create a firewall rule to allow traffic.<br />
firewall –&gt; rules --&gt; ipsec tab</p>
]]></description><link>https://forum.netgate.com/post/159724</link><guid isPermaLink="true">https://forum.netgate.com/post/159724</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Tue, 18 Sep 2007 14:30:13 GMT</pubDate></item></channel></rss>