Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Ipsec die when no client is in the network

    IPsec
    3
    5
    674
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      l123456 last edited by

      I setup site2site ipsec vpn and whenever end of day when all client are shutdown ipsec vpn down too.
      Is this normal or is there any miss configuration ?
      Is it possible to make it live even no client is connected ?

      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        IPsec will connect a tunnel when traffic tries to use the tunnel. The tunnel will remain connected until the Phase 1 or Phase 2 lifetime expires. If there is still traffic, then it will renegotiate at that time.

        If you wish it to remain active, fill in the "Automatically Ping IP" setting in Phase 2 with an IP address in the far side of the tunnel.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • L
          l123456 last edited by

          Thanks jimp for your reply.

          Will try.

          1 Reply Last reply Reply Quote 0
          • L
            l123456 last edited by

            But the thing is when I try to ping from the pfsense box to central there is no response.
            So what shoould i ping in this case ?
            Why I couldn't ping from server to server ?
            Any misconfiguration ?
            Appreciate if you can help.

            1 Reply Last reply Reply Quote 0
            • P
              P3R last edited by

              @l123456:

              So what shoould i ping in this case ?

              I usually ping the LAN interface address of the remote box.

              Why I couldn't ping from server to server ?

              I'd think it is because something in your configuration prevents it.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post