26.7 IPSEC Draytek

Started by MoonbeamFrame, July 16, 2026, 12:24:50 PM

Previous topic - Next topic

Post upgrade I'm seeing an issue with traffic between a firewall running 26.7 and four Draytek 286x routers.

The tunnels are showing as active at both ends, traffic is reported leaving the OPNsense firewall, but I'm not seeing it arrive at the Draytek end.

Anyone else seeing similar?

Quote from: MoonbeamFrame on July 16, 2026, 12:24:50 PMAnyone else seeing similar?
I guess so : https://forum.opnsense.org/index.php?topic=52410.0

Seems like a general bug related to IPSEC in 26.7 sadly...
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: MoonbeamFrame on July 16, 2026, 12:24:50 PMPost upgrade I'm seeing an issue with traffic between a firewall running 26.7 and four Draytek 286x routers.

The tunnels are showing as active at both ends, traffic is reported leaving the OPNsense firewall, but I'm not seeing it arrive at the Draytek end.

Anyone else seeing similar?


Kind of, as nero355 linked, I also have some problems with ipsec after the update. Do you use VTI or tunnel mode and does any traffic at all pass thru the tunnels now? I can get traffic passing but not multicast ospf that worked before.


All use tunnel mode.

These tunnels are configured to be uni-directional (for monitoring purposes), but I do see a few bytes (<500) coming into the OPNsense FW as reported on the VPN: IPsec: Status Overview page. Nothing reported going out.

The Firewall: Log Files: Live View does show outbound traffic being passed.

I was eventually able to see a message in the Draytek syslog explorer that may be useful:

Quote## IKEv2 DBG : Process Packet : Receive IKEv2_INFORMATIONAL but can't find state for iCookie = c46dbe5dad535841 rCookie = 9b374fd129951dbc from {IP_Address}

But I've not found much detail on it yet.


August 16, 2026, 02:18:24 PM #4 Last Edit: August 16, 2026, 02:42:42 PM by MoonbeamFrame
Just to note that after updating to 26.7.2_2 I am still seeing the same behavior.

Tunnels showing as up.

Outbound traffic:
Traffic going out in the Live log
IPSEC Status Overview reporting no bytes out

Inbound traffic:
IPSEC Status Overview reporting bytes coming in.



Last week I started building an OPNsense firewall which will be replacing one of the Drayteks currently using IPSEC. Doing so via a build network connected to my hub firewall.

As part of the build I configured a WireGuard tunnel to my hub firewall. When activated my monitoring system started reporting that I could see the remote site.

Looking in the hubs VPN: IPsec: Status Overview I could see bytes out being reported and, when tested, I had full access to the remote network.

On Monday I used my lab firewall to do the build for the next Draytek to be replaced. This time I configured three WireGuard VPN's to cover each of the remaining  Draytek's.

Again I now had access to the remaining sites.

This morning I disabled the spoke end of the WireGuard tunnels for all four of the Drayteks.

I still have access to the remote sites, which infers that this could be used as a temporary workaround.