Project

General

Profile

Actions

Bug #12493

closed

IPsec continues to intercept traffic even after Phase II is removed

Added by Chaim Robinson almost 4 years ago. Updated almost 4 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

pfSense version:
pfSense community edition
Version 2.5.2-Release (amd64)
FreeBSD 12.2-Stable

The issue:
We are replacing an IPsec connection with a dataline. The dataline is active, and to relay the traffic from the IPsec to the dataline we added the necessary entry in the routing table, and then disconnected, disabled, and removed the Phase II entry. I'd like to add, this connection has activity on it, as it is used, amongst other things, for SNMP monitoring.

Even after removing the Phase II entry, the traffic was not routed through the dataline. Packet Capture showed the traffic coming, however, although firewall rules allow, the traffic didn't go out.

The only action we found so far to solve this is to add the necessary rule to "Additional IPsec bypass" under "VPN/IPSec - Advanced Settings".

Actions

Also available in: Atom PDF