<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DHCP for IPSEC Clients]]></title><description><![CDATA[<p dir="auto">Hi, i have a tiny problem with my cisco vpn client.</p>
<p dir="auto">When I try to connect to my pfsense box, no ip address are given to my client.</p>
<p dir="auto">When i see my logs i have something like that :</p>
<p dir="auto"><img src="http://img91.imageshack.us/img91/4995/capture5mi8.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">So maybe if i make a rule to have dhcp on ipsec it will work.</p>
<p dir="auto">How can I do that ?</p>
]]></description><link>https://forum.netgate.com/topic/8740/dhcp-for-ipsec-clients</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 04:06:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/8740.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 05 May 2008 09:58:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DHCP for IPSEC Clients on Tue, 06 May 2008 19:29:55 GMT]]></title><description><![CDATA[<p dir="auto">Your Cisco client needs to specify a local subnet for his end of the tunnel (from the pfSense point of view this is the remote subnet behind the tunnel). As this is a single client ist should be a /32. I don't know the cisco client so I can't tell you how to set it up.</p>
]]></description><link>https://forum.netgate.com/post/173091</link><guid isPermaLink="true">https://forum.netgate.com/post/173091</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Tue, 06 May 2008 19:29:55 GMT</pubDate></item><item><title><![CDATA[Reply to DHCP for IPSEC Clients on Tue, 06 May 2008 08:10:25 GMT]]></title><description><![CDATA[<p dir="auto">my remote subnet ?</p>
<p dir="auto">Can you advice me about my setting :</p>
<p dir="auto">10.56.146.0/23 –--- internet ---modem with PfSenseon DMZ 128.162.49.0/24 ----- LAN : 192.168.1.0/24</p>
<p dir="auto">So my remote subnet it the first : 10.56.146.0/23 ?</p>
]]></description><link>https://forum.netgate.com/post/173031</link><guid isPermaLink="true">https://forum.netgate.com/post/173031</guid><dc:creator><![CDATA[morgan14]]></dc:creator><pubDate>Tue, 06 May 2008 08:10:25 GMT</pubDate></item><item><title><![CDATA[Reply to DHCP for IPSEC Clients on Mon, 05 May 2008 19:52:14 GMT]]></title><description><![CDATA[<p dir="auto">You don't do DHCP for IPSEC-Clients. The client has to specify the local subnet for mobile clients. You probably think the "unknown gateway/dynamic" is a bug but it just tells you that the endpoint that this log message is about is a mobile client and not a statically configured tunnel.</p>
<p dir="auto">Your mainproblem is that you don't have proper authentication settings and from what it looks like don't have an appropriate remote subnet set in the client either.</p>
]]></description><link>https://forum.netgate.com/post/172988</link><guid isPermaLink="true">https://forum.netgate.com/post/172988</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Mon, 05 May 2008 19:52:14 GMT</pubDate></item></channel></rss>