Sit-to-site ipsec: Ping works but nothing else

  • I got a site-to-site ipsec vpn setup between two pfsense 2.1.5 firewalls.  The tunnel is up, debug logs look clean, and ping works fine across the tunnel.  The problem is anything else does not work.  Packet captures show that the source pfsense is sending the non-icmp traffic out over the wan interface instead of the ipsec interface.  I verified that the icmp traffic goes over the ipsec interface.  Not seeing any blocks in the firewall logs.  Has anyone else seen this?

