Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
ipsec is working but no communication is possible
« previous
next »
Print
Pages: [
1
]
Author
Topic: ipsec is working but no communication is possible (Read 830 times)
Kisters
Newbie
Posts: 2
Karma: 0
ipsec is working but no communication is possible
«
on:
March 29, 2023, 07:41:10 am »
Hi,
i have a opensense with 5 ipsec tunnels, everything works fine. But after 2 - 3 days, communication is no longer possible within one of the tunnels. However, the tunnel is still established. Reestablishing the VPN connection or restarting the ipsec service does not solve the problem.
After restarting the opensense, everything works again for a few days.
All other tunnels work permanently.
Anyone have an idea what this could be?
Regards Tim
Logged
juere
Jr. Member
Posts: 91
Karma: 8
Re: ipsec is working but no communication is possible
«
Reply #1 on:
March 29, 2023, 09:01:40 am »
Hard to tell unless you provide additional information about the tunnels involved
I had a similar situation (tunnel up, no traffic, restarting ipsec service did not help, restarting my gateway did) with tunnels where two conditions were both met:
the remote gateway had a dynamic IPv4 adress
on my side I was using manual SPD entries
The reason was, that whenever the IPv4 address of the remote gateway changed, the manual SPD entries didn't get updated in the kernel security database. Deleting them in the webinterface (/ui/ipsec/spd) and restarting the tunnel made the tunnel work again.
This is a somewhat exotic situation and possibly not yours, but maybe it helps.
Logged
Kisters
Newbie
Posts: 2
Karma: 0
Re: ipsec is working but no communication is possible
«
Reply #2 on:
March 29, 2023, 11:15:07 pm »
Hi,
the other side of the tunnel is a Sophos SG105 with a dynamic IP address. If the communication in the tunnel is no longer possible, the ddns name can still be pinged, so I do not assume that we have a problem with the changing IP address.
Also a restart of the remote gateway does not lead to the connection enabling communication again.
Only the reboot of the OpenSense itself fixes the problem temporarily.
There are more VPN tunnels with the same setup on the same OpenSense and there the problem does not occur.
Regards Tim
«
Last Edit: March 30, 2023, 10:26:35 pm by Kisters
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
ipsec is working but no communication is possible