Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dead Peer Detection

    IPsec
    3
    4
    4.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pesh
      last edited by

      I don't know if everyone else has encountered this, but I recently had a problem where if one of my pfSense firewalls was restarted for whatever reason, the other pfSenses on the other ends of the VPN tunnels wouldn't recognise this. They would keep the old SA up and not negotiate any new ones, causing a failure to pass any traffic over the VPN. The only fix was to manually delete the entries from the SAD on these other firewalls so it would make a fresh tunnel again.

      After reading around a bit, I saw an option for the racoon.conf that would turn on Dead Peer Detection, and figured I'd give that a try. In /etc/inc/vpn.inc, after each line saying proposal_check obey;, I added a line dpd_delay 20;. Then restarted racoon on each firewall, restarted one of the firewalls on its own and found that it renegotiated the tunnels straight away!

      Anyway just a suggestion, I think this would be a useful option to add to pfSense.

      1 Reply Last reply Reply Quote 0
      • G
        geoff2010
        last edited by

        Do you know if PfSense will overwrite your modifications if you change anything through the GUI?  I would love to implement this feature, but I am afraid it will get destroyed on the first GUI change…

        1 Reply Last reply Reply Quote 0
        • G
          geoff2010
          last edited by

          after further review I see that vpn.inc is NOT a configuration file, but a PHP script… please disregard my last post.

          thanks,
          Geoff

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            Check out IPSec config on the new 1.3AlphaAlpha builds- It has DPD and more.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.