Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» IPsec» ipsec
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: ipsec  (Read 751 times)
0 Members and 1 Guest are viewing this topic.
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« on: February 08, 2010, 07:48:46 pm »

hello i have been trying to setup ipsec
i used this to setup my vpn
http://doc.pfsense.org/index.php/IPsec_Road_Warrior/Mobile_Client_How-To

it looks like i can connect to me pfsense but i cant ping any of my computers please help

config loaded for site 'XXXXXXXXXX'
configuring client settings ...
attached to key daemon ...
peer configured
iskamp proposal configured
esp proposal configured
client configured
local id configured
pre-shared key configured
bringing up tunnel ...
network device configured
tunnel enabled

see dont have any problems there
Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 3750



View Profile
« Reply #1 on: February 08, 2010, 10:21:00 pm »

Did you add firewall rules under Firewall > Rules, on the IPsec tab?
Logged

Co-Author of pfSense: The Definitive Guide.

Need help fast? Try Commercial Support.

Also check the Doc Wiki for additional information.
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #2 on: February 09, 2010, 01:39:33 am »

do you mean this

Logged
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #3 on: February 09, 2010, 02:34:03 am »

also i hope this helps you to help me thank you

Feb 8 15:48:26    racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA established 67.49.xxx.xxx[500]-12.173.xxx.xxx[472] spi:ea5a84ca885ca505:c542fcd1decf936c
Feb 8 15:48:26    racoon: [Unknown Gateway/Dynamic]: INFO: respond new phase 2 negotiation: 67.49.xxx.xxx[0]<=>12.173.xxx.xxx[0]
Feb 8 15:48:26    racoon: [Unknown Gateway/Dynamic]: INFO: no policy found, try to generate the policy : 192.168.4.32/32[0] 192.168.1.0/24[0] proto=any dir=in
Feb 8 15:48:27    racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP 12.173.xxx.xxx[0]->67.49.xxx.xxx[0] spi=161391074(0x99ea1e2)
Feb 8 15:48:27    racoon: [Unknown Gateway/Dynamic]: INFO: IPsec-SA established: ESP 67.49.xxx.xxx[0]->12.173.xxx.xxx[0] spi=1085753737(0x40b74989)
Feb 8 15:48:27    racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.4.32/32[0] 192.168.1.0/24[0] proto=any dir=in"
Feb 8 15:48:27    racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.1.0/24[0] 192.168.4.32/32[0] proto=any dir=out"
Feb 8 15:54:16    racoon: INFO: generated policy, deleting it.
Feb 8 15:54:16    racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA expired 67.49.xxx.xxx[500]-12.173.xxx.xxx[472] spi:ea5a84ca885ca505:c542fcd1decf936c
Feb 8 15:54:17    racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA deleted 67.49.xxx.xxx[500]-12.173.xxx.xxx[472] spi:ea5a84ca885ca505:c542fcd1decf936c
Feb 8 16:13:26    racoon: [Unknown Gateway/Dynamic]: INFO: respond new phase 1 negotiation: 67.49.xxx.xxx[500]<=>12.173.xxx.xxx[489]
Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 3750



View Profile
« Reply #4 on: February 09, 2010, 07:49:35 am »

do you mean this

The protocol on that rule is set for only TCP. Change that to "Any"
Logged

Co-Author of pfSense: The Definitive Guide.

Need help fast? Try Commercial Support.

Also check the Doc Wiki for additional information.
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #5 on: February 09, 2010, 01:17:36 pm »

i tryed that but no lock here are more pic
i have been reading the book and i still dont get it please help its making me go crazy i think im missing some rules or something
« Last Edit: February 09, 2010, 05:23:45 pm by rana » Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 3750



View Profile
« Reply #6 on: February 10, 2010, 08:48:34 pm »

That all looks right.

Are you seeing any entries in the firewall log for the times you have tried to ping?

Is pfSense the default gateway for the PCs you are trying to ping?
Logged

Co-Author of pfSense: The Definitive Guide.

Need help fast? Try Commercial Support.

Also check the Doc Wiki for additional information.
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #7 on: February 10, 2010, 10:12:12 pm »

nothing in the firewall logs and yes its on the default gateway
Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 3750



View Profile
« Reply #8 on: February 12, 2010, 12:14:54 am »

Do you have the Dashboard package installed on pfSense? There is an IPsec status widget there which can report the status of mobile tunnels. I wonder if it shows as up/green in that view when the client is connected.
Logged

Co-Author of pfSense: The Definitive Guide.

Need help fast? Try Commercial Support.

Also check the Doc Wiki for additional information.
rana
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #9 on: February 12, 2010, 01:47:03 am »

Active Tunnels     Inactive Tunnels
        0                           0

and nothing under
 Tunnel Status
Logged
rkelleyrtp
Full Member
***
Offline Offline

Posts: 112


View Profile
« Reply #10 on: February 22, 2010, 08:54:22 pm »

Can you please tell us exactly what you are trying to accomplish?  Are you configuring a site-to-site ipsec tunnel, or are you configuring mobile ipsec clients?  Your screenshots seem to indicate you are doing a site-to-site tunnel.  If so, what device is at the other end of the tunnel (Cisco, pfSense, etc)?
Logged
rkelleyrtp
Full Member
***
Offline Offline

Posts: 112


View Profile
« Reply #11 on: February 22, 2010, 08:57:51 pm »

Sorry, my mistake.  Your screen grabs looked just like the site-to-site tunnel config screen.

What kind of logs does your client get during tunnel negotiation?  What kind of client are you using?
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.166 seconds with 20 queries.