Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense with pfsense site to site - cannot "see" each other

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yce_kelvin
      last edited by

      Hi all, I successfully created IPSEC vpn tunnel for 2 pfsense box. The problem now is can "ping" each other but cannot "see" each other ini My Network Place. Both site clients is using the same Window XP Home SP2  and the machines are "cloned" PC. It is i missing some step on forwarding or service setting??

      Anyone know pls help… I m noob.

      Thank you.

      IT Computer System - I love it. Hope that every day is a happy day and the world is peace and green environment always.

      1 Reply Last reply Reply Quote 0
      • Y
        yce_kelvin
        last edited by

        last few raw log files:
        Jun 21 12:29:06 racoon: [Metro Net]: INFO: IPsec-SA established: ESP/Tunnel 60.5x.xxx.xxx[0]->60.xx.xxx.xxx[0] spi=164xxxx39(0x9ca9617)
        Jun 21 12:29:06 racoon: [Metro Net]: INFO: IPsec-SA established: ESP/Tunnel 60.5x.xxx.xxx[0]->60.xx.xxx.xxx[0] spi=158xxx270(0x96f5d16)
        Jun 21 12:29:06 racoon: [Metro Net]: INFO: initiate new phase 2 negotiation: 60.5x.xxx.xxx[500]<=>60.xx.xxx.xxx[500]
        Jun 21 12:29:05 racoon: [Metro Net]: INFO: ISAKMP-SA established 60.5x.xxx.xxx[500]-60.xx.xxx.xxx[500] spi:1b657501a8c8c9d3:2xxxxxxxxxxxx504dc
        Jun 21 12:29:05 racoon: WARNING: No ID match.
        Jun 21 12:29:05 racoon: INFO: received Vendor ID: DPD
        Jun 21 12:28:45 racoon: INFO: begin Aggressive mode.

        It seem the tunnel establish.

        IT Computer System - I love it. Hope that every day is a happy day and the world is peace and green environment always.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          You cannot "see" them in your network places because of the same reason you cannot play games over a VPN.
          The discovery of windows shares works via UDP broadcasts which dont get routed.

          If you want to access a windows share on the other side of a tunnel, you can do that directly via the IP of the destination computer.
          Another possibility would be to set up a WINS server on the other side of the tunnel, which resolves your SMB-names into IP's.

          You really should read up on how routing works and what it means, since you seem to run into the same problems over and over again.

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.