Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense 2.1.5, when phase 1 drops, phase 2 does NOT

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 633 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      snm777
      last edited by

      we have a situation where somone has MPLS behind a pfsene firewall, and all their MPLS sites ALSO have Internet connectivity for use as a backup to the MPLS ONLY.

      When a remote office has an MPLS link drop, it VPN's in to the pfsense firewall to get access to the rest of the MPLS.  When the remote MPLS connection comes back up, the phase 1 entry in PFsense drops as expected, but the phase 2 entires don't.  As a result, the remote MPLS site can no longer get throught he LAN interface on the pfsense box out to the Internet, because the phase 2 entry basically acts like a blackhole.

      How can I force pfsense to drop phase 2 entires associated with a phase 1 entry that drops?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.