Re: [pfSense Support] inconsistent handling of VPN remote endpoints

2010-11-15 Thread Vick Khera
On Thu, Nov 11, 2010 at 1:26 PM, Jim Pingle wrote: > IPsec does not route, OpenVPN does. That's one fundamental difference > here. Another is that the policy route exclusion code can find the IPsec > Could you explain the difference in behavior of the static IPsec endpoints vs. the roaming IPsec

Re: [pfSense Support] inconsistent handling of VPN remote endpoints

2010-11-11 Thread Jim Pingle
On 11/11/2010 8:48 AM, Vick Khera wrote: [snip] > I think it would be really nice if the VPN endpoints would all behave > like the fixed endpoint IPsec connections so I did not need to add > rules to the LAN filter to avoid the failover pool rule. Barring > that, it would be really handy to have o

[pfSense Support] inconsistent handling of VPN remote endpoints

2010-11-11 Thread Vick Khera
Yesterday I was diving into why I could not connect *to* openvpn clients from the office, and discovered that having a rule that sends all LAN traffic to our WAN failover pool was interfering with that traffic. Ultimately it dawned on me that this is also the cause that I cannot originate connecti