Project

General

Profile

Actions

Bug #12587

closed

Ipsec lost trafic and status failed

Added by Ricardo ot over 2 years ago. Updated over 2 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.2.5
Affected Architecture:
arm64

Description

I have a problem with an Ipsec tunnel.
I have a tunnel established between a Pfsense 2.5.2 and a Checkpoint and when establishing the connection it works but when it renegotiates, many times it happens that there is no traffic in the direction of the pfsense. Example, when making a PING from lan of the Pfsense, the destination host responds but the Pfsense does not receive the packets. The are packet out but not in and no problem on the Checkpoint extreme.

On the other hand, I have seen that there are times when "phase 2" and "Connect Childrens" are seen because they are not established. If this button is pressed, it happens that all Ipsec connections stop showing status and the following is seen on the console:

swanctl --list-sas
connecting to 'unix:///var/run/charon.vici' failed: Connection refused

And the only way to recover normal ipsec funtion is reboot Pfsense.

Actions

Also available in: Atom PDF