Re: [pfSense] client VPN on IOS

2015-09-25 Thread Jim Thompson
I use it.  

Note that iOS 9 has AES-GCM and IKEv2. 

We've recently (today) fixed a few bugs in hybrid auth mode. That might have 
stopped you, depending on how you have things setup. 

Also, with iOS 9, it appears that a tunnel with only IPv4 doesn't work. You 
have to config both v4 and v6.  If you don't, the tunnel appears to be up, but 
doesn't pass traffic. 

OpenVPN doesn't scale.  It's fine on a small scale, but the architecture is 
wrong for large deployments. I nearly always recommend IPSec.

-- Jim

> On Sep 15, 2015, at 8:18 AM, Ray Bagby  wrote:
> 
> Greetings,
> 
>Anyone have any luck connecting iphone via VPN?
> 
> Thanks
> 
> ___
> pfSense mailing list
> https://lists.pfsense.org/mailman/listinfo/list
> Support the project with Gold! https://pfsense.org/gold
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] client VPN on IOS

2015-09-25 Thread Kostas Backas
Openvpn client works really well.

Best regards

Kostas

Sent from my iPhone

> On 25 Σεπ 2015, at 20:46, Bryan D.  wrote:
> 
>> On 2015-Sep-15, at 6:18 AM, Ray Bagby  wrote:
>> 
>> Greetings,
>> 
>>   Anyone have any luck connecting iphone via VPN?
> 
> You can also see:
> 
> http://www.derman.com/blogs/Setting-Up-iOS-OnDemand-VPN
> 
> ___
> pfSense mailing list
> https://lists.pfsense.org/mailman/listinfo/list
> Support the project with Gold! https://pfsense.org/gold
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] client VPN on IOS

2015-09-25 Thread Bryan D.
On 2015-Sep-15, at 6:18 AM, Ray Bagby  wrote:

> Greetings,
> 
>Anyone have any luck connecting iphone via VPN?
> 

You can also see:

http://www.derman.com/blogs/Setting-Up-iOS-OnDemand-VPN

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] Routing some trafic throught OpenVPN

2015-09-25 Thread Bryan D.
On 2015-Sep-15, at 11:39 PM, Andrej Ferčič [PCklinika]  
wrote:

> Hello!
> 
> I am sure that this issue has been already discussed, but I can not find any 
> arhive. So, please give me some directions where to search or any link to 
> thread containig the following:
> 
> 1. Is there any routing throught IPSec VPN possible? (IpSec is solved in 
> kernel as I know)
> 2. How to use OpenVPN to route a specific trafic throught VPN? Let me explain 
> what I want to solve:

The following may also help -- this is the approach I use (along with some 
additional routing rules) to enable access of various systems from one site to 
another both through IPsec VPNs and OpenVPN VPNs ... though the blog is in 
reference to pfSense 2.1, we're now on 2.2.2 with the same setup but using Key 
Exchange v2 and a server-base pinger to keep IPsec connected [this is a known 
issue, search the list postings]):

http://www.derman.com/blogs/IPSec-VPN-Firewall-Setup#RouteOpenVPNthruIPsec

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold