Bug #1970


IPsec stops routing after a while

Added by c c about 10 years ago. Updated over 9 years ago.

Target version:
Start date:
Due date:
% Done:


Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:


Using the same setup as this bug:

It appears that after a while with no clear trigger, even Shrewsoft VPN client will stop routing traffic after a while. I have noticed that it seems to happen after I have been connected, then left and had my computer hibernate. Upon returning and reconnecting, the VPN will not route any traffic at all until I restart the pfsense box, at which point it starts working again.

It may be the same issue as the other bug above, but I cannot reliably trigger it by simply connecting and disconnecting (whereas with the Cisco client, the first connection breaks things).
EDIT: It looks like a connection interruption triggers this-- I can make it happen by disconnecting and reconnecting the wireless without properly disconnecting from the VPN.

As in the other bug, let me know if access to this test box would be useful-- I have no concerns about giving access to the interface, as it is simply a test box.

Configuration details:
pfSense 2.0 (release), i386
on a Dell Dimension 420

Using Mobile IPsec--
Providing a virtual IP and DNS

Phase 1 settings:
Interface: WAN
Auth Method: Mutual PSK + Xauth
Negotiation: Agressive
My identifier: My IP address
Peer identifier: UDN ()
preshared key: mypks
Policy Generation: on
Proposal checking: obey
Encryption: AES128, with MD5
DH key group 2
Nat Traversal enabled
DPD on, 5 seconds, 5 retries

Phase 2:
Mode: tunnel
Local network:
Protocol: ESP
Encryption: AES, 3des
Hash: md5
PFS off


broken_ipsec_connection.txt (3.89 KB) broken_ipsec_connection.txt Broken connection, 4 pings, disconnect. c c, 10/20/2011 05:12 PM
working_ipsec_connection.txt (4.07 KB) working_ipsec_connection.txt Working connection, 3-4 pings, disconnect c c, 10/20/2011 05:12 PM (1.04 KB) Shrewsoft vpn profile (IP and PSK hidden) c c, 10/20/2011 05:12 PM
Actions #1

Updated by c c almost 10 years ago

Attached are logfiles. First is a connection while racoon is in a hung state, followed by 4 pings to (all timed out), followed by a disconnection. Second log is the same thing after a restarting racoon (enabling and disabling racoon debug mode).

Both connections were done with Shrewsoft VPN client (configuration is attached). I have altered the IP and PSK in the profile, let me know if you need that info

As I said, issue can be triggered by simply connecting, and then disabling your network connection (unplugging, wifi disconnect, etc), which will break that connection for good until racoon is restarted.

Let me know if you wish to try the vpn connection for testing / have a login to the firewall.

Actions #4

Updated by Ermal Luçi over 9 years ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

Applied in changeset commit:d2a5443f5d0f9747be874a4f8787ca18348a8461.

Actions #5

Updated by Jim Pingle over 9 years ago

  • Status changed from Feedback to Resolved

Also available in: Atom PDF