Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    [SOLVED] losing connection in ipsec phase 2

    IPsec
    3
    6
    2175
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kopie0123 last edited by

      Hi all,

      we are currently having big problems losing phase 2 connections on some of our ipsec tunnels.

      Our systems: pfsense 2.2.6 on SG-2240, SG-4680 1U, C2758 1U

      Several times a day the tunnels are going down, phase 1 is still connected, phase 2 is disconnected. It can be restartet manually or after some it restarts automatically.
      In the web configuration (Status -> IPSec) the tunnel is connected, but there are no child SA entries anymore.

      Configuration on both ends is exactly the same (lifetime, protocols…).

      Does anyone having the same problems can give a hint solving this?

      Regards!

      1 Reply Last reply Reply Quote 0
      • P
        papa_joe last edited by

        I have similar problem. We have two phase 2 connections defined. Sometimes one of the two (randomly) is lost and not established again.
        Restart the VPN tunnel and all is ok.

        Also we have V 2.2.6 running.

        1 Reply Last reply Reply Quote 0
        • K
          kopie0123 last edited by

          our config:

          IKEv1

          phase 1:
          PSK
          main
          AES 256
          SHA256
          DH group 5
          Lifetime 7800
          NAT-T Auto
          Enable DPD (10/5)

          phase 2:
          ESP
          AES 256
          SHA256
          Dh group 5
          Lifetime 3600
          Ping host

          1 Reply Last reply Reply Quote 0
          • K
            kopie0123 last edited by

            On friday we switched on IKEv2 - no problems since then

            1 Reply Last reply Reply Quote 0
            • G
              GAITii last edited by

              @kopie0123:

              On friday we switched on IKEv2 - no problems since then

              Hi,

              i have the same issue, but how you can change from IKEv1 to IKEv2?
              Is that option show at the Phase 1 entry or the Phase 2 entry?

              1 Reply Last reply Reply Quote 0
              • P
                papa_joe last edited by

                You can change this on the Phase 1 page.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post

                Products

                • Platform Overview
                • TNSR
                • pfSense
                • Appliances

                Services

                • Training
                • Professional Services

                Support

                • Subscription Plans
                • Contact Support
                • Product Lifecycle
                • Documentation

                News

                • Media Coverage
                • Press
                • Events

                Resources

                • Blog
                • FAQ
                • Find a Partner
                • Resource Library
                • Security Information

                Company

                • About Us
                • Careers
                • Partners
                • Contact Us
                • Legal
                Our Mission

                We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                Subscribe to our Newsletter

                Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                © 2021 Rubicon Communications, LLC | Privacy Policy