Title: RE: [pfSense Support] Re: IPSec Broken in 95.8 Embedded?
I upgraded to 96.2 and ran the test again. I reloaded both boxes and cleared the ipsec.log.
Looks like it has trouble binding to the addresses on remote1.  Nothing in the logs on central 1 make it look like the connection is making it there.
 
Attached are the ipsec.log from remote1 and central1 (vip master).
The only things changed is remote1's wan ip is changed to 77.77.77.x and the Central1 Wan/vip range is change to 99.99.99.x
 
 
Currently the setup is as follows. (Remote1 also has another interface that has an ip but only used to link it to another lan)
 
 
172.16.10.0/24 remote1 ------>  VIP --/ Central 1\ -- VIP-- 172.16.0.0/24
                                                     \ Central 2/
 
Central 1 and 2 share VIP address via carp.
IPSec is setup for mobile clients
Mode - Aggressive
Identifier FQDN - [EMAIL PROTECTED]
Encryption - 3DES
Hash - SHA1
DH Key Group - 2
Lifetime 60
Auth Method - Pre-Share Key
 
Phase 2
Protocol - ESP
Encryption - 3DES, Blowfish
Hash - Sha1
PFS - Off
Lifetime - 60
 
 
Remote 1 is setup as a tunnel
 
Interface - WAN
Local Sub - 172.16.10.0 /24
Remote Sub - 172.16.0.0 /24
Remote Gateway - VIP of Central 1 & 2
 
Mode - Aggressive
Identifier FQDN - [EMAIL PROTECTED]
Encryption - 3DES
Hash - SHA1
DH Key Group - 2
Lifetime 60
Auth Method - Pre-Share Key
(preshare key is entered)
 
Phase 2
Protocol - ESP
Encryption - 3DES, Blowfish
Hash - Sha1
PFS - Off
Lifetime - 60
 
 
All devices have the same pre-shared keys / passwords are also the same
 
 
As I mentioned before I don't see anything in Status->IPSec->SPD where I did see the policy in versions like 94.10
 
Thanks
John


From: Holger Bauer [mailto:[EMAIL PROTECTED]
Sent: Tuesday, December 13, 2005 5:58 PM
To: [email protected]
Subject: AW: [pfSense Support] Re: IPSec Broken in 95.8 Embedded?

could you give us a mockup what kind of ipsec you are using and how it is set up? maybe even the ipsec config sections with removed secrets of both endpoints? Also, like scott said already, logs from both sides would be helpful. If you don't want to send it to the list send them offlist. I can try to simulate your setup here in my lab.
 
Holger
-----Ursprüngliche Nachricht-----
Von: John Cianfarani [mailto:[EMAIL PROTECTED]
Gesendet: Di 13.12.2005 20:57
An: [email protected]
Cc:
Betreff: RE: [pfSense Support] Re: IPSec Broken in 95.8 Embedded?

Is there any specific config/debug I can provide that might show why the
tunnels aren't coming up? Or what might be failing?

Thanks
John

-----Original Message-----
From: Scott Ullrich [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, December 13, 2005 12:18 PM
To: [email protected]
Subject: Re: [pfSense Support] Re: IPSec Broken in 95.8 Embedded?

Standard IPSEC.  Nothing fancy.


On 12/13/05, John Cianfarani <[EMAIL PROTECTED]> wrote:
> Out of curiousity what kind of configuration are they in? (Mobile
> client?, static ip?)
> As I still have problems as well in any 95+
> I've also tried to recreate stuff from scratch incase it was a config
> import problem.
>
> Thanks
> John
>
> -----Original Message-----
> From: Scott Ullrich [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, December 13, 2005 11:24 AM
> To: [email protected]
> Subject: Re: [pfSense Support] Re: IPSec Broken in 95.8 Embedded?
>
> Don't know what to say.  All my tunnels are up in 3 different
> locations (7 tunnels total).
>
> I am on 0.96.2
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [EMAIL PROTECTED]
> For additional commands, e-mail: [EMAIL PROTECTED]
>
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Attachment: gw-central1-ipsec.log
Description: gw-central1-ipsec.log

Attachment: gw-remote1-ipsec.log
Description: gw-remote1-ipsec.log

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to