<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSec]]></title><description><![CDATA[<p dir="auto">Using Cisco IPSec for VPN under OS X or iOS, DNS server settings are no longer being handled properly by the client.  This was working properly in 2.1, but in 2.2 something broke.  Oddly, I can see the server settings in the VPN on OS X, but it seems not to send lookups for the domain to the configured DNS server.</p>
<p dir="auto">The other odd thing is that with scutil –dns, the search domains are "my.domain.comp", not "my.domain.com".  That's definitely weird.</p>
]]></description><link>https://forum.netgate.com/topic/79190/ipsec</link><generator>RSS for Node</generator><lastBuildDate>Wed, 20 May 2026 04:21:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/79190.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 03 Feb 2015 09:35:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSec on Mon, 09 Feb 2015 00:08:21 GMT]]></title><description><![CDATA[<p dir="auto">Thanks all.  I do have DNS set in phase 2.  It simply does not work.</p>
<p dir="auto">See https://forum.pfsense.org/index.php?topic=88226.0 for an identical example with more thorough logs.</p>
<p dir="auto">I suspect a possible migration or upgrade issue, but I would need to find the time to do a clean install.</p>
]]></description><link>https://forum.netgate.com/post/517315</link><guid isPermaLink="true">https://forum.netgate.com/post/517315</guid><dc:creator><![CDATA[rkuo]]></dc:creator><pubDate>Mon, 09 Feb 2015 00:08:21 GMT</pubDate></item><item><title><![CDATA[Reply to IPSec on Tue, 03 Feb 2015 21:12:52 GMT]]></title><description><![CDATA[<p dir="auto">check /var/etc/ipsec/strongswan.conf for what it's setting. Should be something like:</p>
<pre><code># Search domain and default domain
			28674 = example.com
			28675 = example.com
</code></pre>
<p dir="auto">The problem with DNS server reachability is probably with Ermal noted, the P2 local network in strongswan is strictly enforced where racoon may not have.</p>
]]></description><link>https://forum.netgate.com/post/515240</link><guid isPermaLink="true">https://forum.netgate.com/post/515240</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Tue, 03 Feb 2015 21:12:52 GMT</pubDate></item><item><title><![CDATA[Reply to IPSec on Tue, 03 Feb 2015 11:59:08 GMT]]></title><description><![CDATA[<p dir="auto">Check the RELEASE notes on the phase2 setting for mobile clients.<br />
Probably your dns servers are not in the phase2 definition.</p>
]]></description><link>https://forum.netgate.com/post/515003</link><guid isPermaLink="true">https://forum.netgate.com/post/515003</guid><dc:creator><![CDATA[eri--]]></dc:creator><pubDate>Tue, 03 Feb 2015 11:59:08 GMT</pubDate></item></channel></rss>