Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec tunnel UP but unable to ping remote site

    Scheduled Pinned Locked Moved IPsec
    44 Posts 16 Posters 50.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      Brianwiz1
      last edited by

      @hongkonger:

      Hi,

      I have almost similar issue,

      i can RDP to the remote hosts, but cant ping or tracert,

      normally this wouldnt bug me much but i have a number of PCs that are unable to connect to the Domain controller on the remote network.

      IPsec rules on both pfboxes are pass on any to any.

      any thoughts?

      thanks

      EDIT, my bad I wasn't paying attention to rule in IPsec, its tcp/udp, for ICMP u need a specific rule on both side.

      Hi I had a similar issue so i created a rule on the LAN interface that allows any protocol on the specific network on both source and destination.

      1 Reply Last reply Reply Quote 0
      • D Offline
        drdoolittle
        last edited by

        I'm having a similar problem, but: I can ping the remote PFSense box and access it via web configurator, but all other hosts on the same subnet are not pingable or otherwise reachable. BUT the remote site can ping/reach everything on my local site.

        I also don't see anything being blocked on the firewall. I suppose my problem and possibly also the others mentioned here are some kind of routing problem?

        I'm running on pfsense 2.3.4 (remote site) and a Cisco Meraki MX400 (local).

        1 Reply Last reply Reply Quote 0
        • D Offline
          drdoolittle
          last edited by

          Hasn't anybody got an idea what the problem could be? :-\

          1 Reply Last reply Reply Quote 0
          • D Offline
            drdoolittle
            last edited by

            I finally found a solution!

            On the remote PFsense router I went to VPN -> IPSec -> Advanced Settings and disabled "Enable bypass for LAN interface IP" (scroll all the way down) and I finally can connect to the remote host! Check if your windows firewall on that host is on, as it likely will recognize the incoming traffic as non-private traffic and thus might filter it (to test it, shut down the firewall for public networks).

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.