Ipsec die when no client is in the network



  • I setup site2site ipsec vpn and whenever end of day when all client are shutdown ipsec vpn down too.
    Is this normal or is there any miss configuration ?
    Is it possible to make it live even no client is connected ?


  • Rebel Alliance Developer Netgate

    IPsec will connect a tunnel when traffic tries to use the tunnel. The tunnel will remain connected until the Phase 1 or Phase 2 lifetime expires. If there is still traffic, then it will renegotiate at that time.

    If you wish it to remain active, fill in the "Automatically Ping IP" setting in Phase 2 with an IP address in the far side of the tunnel.



  • Thanks jimp for your reply.

    Will try.



  • But the thing is when I try to ping from the pfsense box to central there is no response.
    So what shoould i ping in this case ?
    Why I couldn't ping from server to server ?
    Any misconfiguration ?
    Appreciate if you can help.



  • @l123456:

    So what shoould i ping in this case ?

    I usually ping the LAN interface address of the remote box.

    Why I couldn't ping from server to server ?

    I'd think it is because something in your configuration prevents it.


Log in to reply