Netgate Logo Netgate Docs
  • Appliances
  • Platforms
  • Support
  • Training
latest
  • Preface
  • Introduction
  • Releases
  • Product Manuals
  • Networking Concepts
  • IPv6
  • Hardware
  • Installing and Upgrading
  • Configuration
  • Netgate® Nexus
  • Backup and Recovery
  • Interface Types and Configuration
  • User Management and Authentication
  • Certificate Management
  • Firewall
  • Network Address Translation
  • Routing
  • Bridging
  • Virtual LANs (VLANs)
  • Multiple WAN Connections
  • Virtual Private Networks
  • IPsec
  • L2TP VPN
  • OpenVPN
  • WireGuard
  • Services
  • DHCP
  • DNS
  • Dynamic DNS
  • NTPD
  • Traffic Shaper
  • Captive Portal
  • High Availability
  • System Monitoring
  • Monitoring Graphs
  • System Logs
  • Diagnostics
  • Packages
  • Virtualization
  • Wireless
  • Cellular Wireless
  • Troubleshooting
    • Troubleshooting Asymmetric Routing
    • Troubleshooting Authentication
    • Troubleshooting Boot Issues
    • Troubleshooting Multiple Disks
    • Troubleshooting “No buffer space available” Errors
    • Troubleshooting Captive Portal
    • Troubleshooting Cisco VPN Pass Through
    • Troubleshooting Network Connectivity
    • Troubleshooting GUI Connectivity
    • Troubleshooting OS Issues with a Debug Kernel
    • Troubleshooting Offline DHCP Leases
    • Troubleshooting DHCPv6 Client XID Mismatches
    • Troubleshooting DMA and LBA Errors
    • Troubleshooting DNS Resolution Issues
    • Troubleshooting the DNS Cache
    • Troubleshooting DNS Queries
    • Troubleshooting Disk and Filesystem Issues
    • Troubleshooting Full Filesystem or Inode Errors
    • Troubleshooting Filesystem Capacity Shrinking
    • Troubleshooting Disk Lifetime
    • Troubleshooting Disk Writes
    • Troubleshooting Thread Errors with Hostnames in Aliases
    • Troubleshooting Firewall Rules
    • Troubleshooting Bogon Network List Updates
    • Troubleshooting FTP Connections
    • Troubleshooting Gateway Monitoring
    • Troubleshooting High Availability DHCP Failover
    • Troubleshooting the HAProxy Package
    • Troubleshooting VPN Connectivity to a High Availability Secondary Node
    • Troubleshooting High Availability
    • Troubleshooting High Availability Clusters in Virtual Environments
    • Troubleshooting High CPU Load
    • Troubleshooting Installation Issues
    • Troubleshooting IPsec VPNs
      • Troubleshooting IPsec Connections
      • Troubleshooting IPsec Traffic
      • Troubleshooting IPsec Logs
      • Troubleshooting Duplicate IPsec SA Entries
    • Troubleshooting L2TP
    • Troubleshooting Access when Locked Out of the Firewall
    • Troubleshooting Blocked Log Entries for Legitimate Connection Packets
    • Troubleshooting ARP Move Log Messages
    • Troubleshooting “login on console as root” Log Messages
    • Troubleshooting “promiscuous mode enabled” Log Messages
    • Troubleshooting Low Interface Throughput
    • Troubleshooting Multi-WAN
    • Troubleshooting NAT
    • Troubleshooting 1:1 NAT
    • Troubleshooting NAT Port Forwards
    • Troubleshooting NAT Reflection
    • Troubleshooting OpenVPN
    • Troubleshooting Windows OpenVPN Client Connectivity
    • Troubleshooting OpenVPN Internal Routing (iroute)
    • Troubleshooting Lost Traffic or Disappearing Packets
    • Troubleshooting a Broken pkg Database
    • Troubleshooting Routes
    • Troubleshooting in Single User Mode
    • Troubleshooting Snort Rule Updates
    • Troubleshooting the Squid Package
    • Troubleshooting Hardware Shutdown and Power Off
    • Troubleshooting Clock Issues
    • Troubleshooting Time Zone Configuration
    • Troubleshooting Traceroute Output
    • Troubleshooting Traffic Shaping
    • Troubleshooting Traffic Shaping Graphs
    • Troubleshooting Unexpected Reboots
    • Troubleshooting Upgrades
    • Troubleshooting Upgrades on Netgate 1100 and Netgate 2100 Devices
    • Troubleshooting Website Access
    • Troubleshooting Wireless Connections
    • General
    • Authentication / User Manager
    • Connectivity / Networking
    • DNS
    • Hardware
    • High Availability
    • Installation / Upgrades
    • Rules/NAT
    • Routing / Multi-WAN
    • VPN
    • Packages
  • pfSense® software Configuration Recipes

References

  • Menu Guide
  • Glossary of Terms
  • Development
  • References
  • Licensing

Recipes

  • pfSense® software Configuration Recipes
The pfSense Documentation
  • Docs »
  • pfSense® software »
  • Troubleshooting
  • Give Feedback

Next
Troubleshooting IPsec Connections
Previous
Troubleshooting Installation Issues

Troubleshooting IPsec VPNs¶

Due to the finicky nature of IPsec it is not unusual for trouble to arise with tunnels when creating them initially or over time.

Follow the troubleshooting advice in this section to diagnose and solve most common problems with IPsec tunnels on pfSense® software.

Troubleshooting IPsec

  • Troubleshooting IPsec Connections
    • IPsec connection names
    • Manually connect IPsec from the shell
    • Tunnel does not establish
    • “Random” tunnel disconnects/DPD failures on low-end routers
    • Tunnels establish and work but fail to renegotiate
    • DPD is unsupported and one side drops while the other remains
    • Tunnel establishes when initiating but not when responding
    • Tunnel establishes at start but not when disconnected
    • Tunnel stops attempting connections after timeout
  • Troubleshooting IPsec Traffic
    • Tunnel establishes but no traffic passes
    • Some hosts work but not all
    • Connection hangs
    • Disappearing traffic
  • Troubleshooting IPsec Logs
    • IPsec log interpretation
    • Successful connections
    • Failed connection examples
  • Troubleshooting Duplicate IPsec SA Entries
    • Current version (2.5.0 and later)
    • Version 2.4.5-p1 and older
    • Other notes

Next
Troubleshooting IPsec Connections
Previous
Troubleshooting Installation Issues
Was this page helpful?

Documentation Feedback

For assistance in solving software problems, please post your question on the Netgate Forum. If you see anything that's wrong or missing with the documentation, please suggest an edit by using the feedback button in the upper right corner so it can be improved.


© 2025 Electric Sheep Fencing LLC and Rubicon Communications LLC. All Rights Reserved. | Privacy Policy | Legal

This page was last updated on Jul 06 2022.

    Other Resources
  • Platforms Overview
  • TNSR Solutions
  • pfSense Solutions
  • Appliances
  • Find a Partner
  • Support Plans
  • Training
  • Professional Services
  • Blog
  • Resource Library
  • Security Information
  • About Us
  • Careers
  • Contact Us
Our Mission

We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

Subscribe to our Newsletter

Product information, software announcements, and special offers. See our newsletter archive for past announcements.

Additional Resources v: latest
Languages
en
Versions
latest

Software Documentation
pfSense
TNSR
Product Manuals