<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Response SA packets getting droped (GRE over IPSec tunnel)]]></title><description><![CDATA[<p dir="auto">Didn't know where to put this so i ended up here.</p>
<p dir="auto">Being having a little problem with one setup (diag.jpg attached). Its a GRE tunnel over ipsec but it have the a need to use nat inside it.</p>
<p dir="auto">If i try to connect to the remote server, the packet capture on the gre interface shows ACK from the other side (tcpdump-gre.jpg), but it seems that when the packet leaves the tunnel it gets droped by the firewall (fw-drop.jpg) for (i guess) being out of state.</p>
<p dir="auto">Any help on this will be appreciated cause i'm lost here.</p>
<p dir="auto">PS: if i posted this in the wrong place, feel free to move it where it belongs.</p>
<p dir="auto">Edit: added NAT-OUT rules screen shot just in case, cause its more likely the culprit.<br />
<img src="/public/_imported_attachments_/1/fw-drop.JPG" alt="fw-drop.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/fw-drop.JPG_thumb" alt="fw-drop.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/tcpdump-gre.JPG" alt="tcpdump-gre.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/tcpdump-gre.JPG_thumb" alt="tcpdump-gre.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Diag.jpg" alt="Diag.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Diag.jpg_thumb" alt="Diag.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/NAT.JPG" alt="NAT.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/NAT.JPG_thumb" alt="NAT.JPG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/86979/response-sa-packets-getting-droped-gre-over-ipsec-tunnel</link><generator>RSS for Node</generator><lastBuildDate>Wed, 16 Sep 2026 10:10:23 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/86979.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Jul 2015 21:31:41 GMT</pubDate><ttl>60</ttl></channel></rss>