Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mobile VPN client (IPSec)

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      miken32
      last edited by

      Using the exact same settings as a 2.1.5 install, I get a connection but can't reach any local resources aside from the pfSense, or anything on the far end of a site-to-site VPN. Works fine getting out to the internet via the pfSense though.

      The only difference I see is under Status/IPSec/SPD the 2.1.5 shows routes between 4.5.6.7 (VPN client address) and 0.0.0.0/0. Under 2.2 I see routes between 4.5.6.7 and 192.168.1.0/24 (LAN subnet.)

      Does anyone have mobile VPN working such that they can connect and get access to other resources on the LAN?

      1 Reply Last reply Reply Quote 0
      • D
        dstroot
        last edited by

        I have been struggling mightily with mobile IPSEC on the 2.2 betas.  I assume you are talking about and IPSEC VPN because if I can get connected I see the same issue.  Now that we have an RC I hope more people try mobile IPSEC (I am particularly interested in iOS 8.x) and post their setups/configuration.  I'd be happy to document and share a good config once I have one.  :)

        1 Reply Last reply Reply Quote 0
        • M
          miken32
          last edited by

          So this is still not working for me. Exact same settings as 2.1.5; the connection sets up just fine but the only thing I can reach on the LAN over VPN is the pfSense itself.

          Does anyone have an IKE v1 IPSec VPN working with PSK? (Certificates are out of the question for 40-50 devices, so don't suggest it!)

          Edit: I can reach things over site to site VPN tunnels (e.g. there's a VPN tunnel between office A and office B. If I connect mobile VPN to office A, I can reach anything in office B, but nothing in office A.)

          I can reach the internet through the VPN, but only by setting local network to 0.0.0.0/0 in the mobile P2.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Setting the local network to 0.0.0.0/0 to reach the Internet is the right move. Technically that should have also been required in racoon as well, though at times with mobile it was all too happy to take whatever P2 network the client said it wanted, which is a tad insecure.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.