Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A pfSense IPsec site-to-site tunnel can show as established even when the intended LAN traffic is blocked, using the wrong Phase 2 networks, or taking an incorrect route. Start by checking the firewall rules and logs on the destination site, then verify both peers’ Phase 2 selectors and trace the packet path in each direction.

1. Check the destination site’s IPsec rules and firewall logs

When a device at Site A initiates traffic to Site B, inspect Site B first: it is the receiving firewall that must allow the traffic. Reverse the check when Site B initiates traffic to Site A. In pfSense, IPsec rules are under Firewall > Rules > IPsec; labels can vary by software version.

  • Look for blocked packets in the firewall logs and check traffic on both the IPsec (enc0) and internal interfaces.
  • Confirm that a pass rule allows the protocol and destination you are actually testing. A rule allowing only TCP will not allow an ICMP ping or DNS traffic that uses UDP or TCP, as applicable.
  • For a ping test, explicitly allow ICMP. A failed ping does not establish that all tunnel traffic is broken if the rule does not permit ICMP.

Netgate’s pfSense IPsec troubleshooting documentation treats an established tunnel with no passing traffic as a separate problem from tunnel establishment.

2. Compare the Phase 2 networks at both ends

Check the Phase 2 local and remote networks on both peers against the actual LAN subnets. Each peer’s local network should correspond to the other peer’s remote network, and vice versa. A tunnel can establish even if these selectors do not describe the networks whose traffic you are testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

Netgate documents an example in which a subnet was entered with a host address and a /24 mask on one side instead of the corresponding network address. As Netgate puts it, “The tunnel established, but traffic would not pass until the subnet was corrected.” Compare the definitions on both peers rather than relying on the connected status alone. See Netgate’s IPsec troubleshooting guide and IPsec VPN documentation.

3. Find where the packet leaves the expected path

Test to a reachable host on the remote LAN, and use firewall logs and packet captures to determine whether the packet reaches the source firewall, enters IPsec, and appears on the destination LAN. Run traceroute (or tracert on Windows) from both sites. Netgate notes that traffic failing to enter the tunnel may appear to leave over the WAN.

Rank #2
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
  • SECURE - Your best pfSense+ Firewall, Router, and VPN solution. #1 ranked "best firewalls" solution on PeerSpot (June 2025). 10+ million installations around the world. Flexible to solve your specific networking needs.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • PRIVATE - Enterprise-grade VPN without breaking the bank. Virtual private network protocols including IPsec, OpenVPN and WireGuard VPN.
  • BUSINESS READY - Free pfSense+ software updates, free training, free forums, free comprehensive documentation, free technical assistance included for the LIFETIME of the appliance. One year hardware warranty included.
  • POWERFUL - A 1.2 GHz ARM Cortex-A53 processor delivers 2.20 Gbps of routing for common iPerf3 traffic and over 964 Mbps of firewall throughput for added security and high-performance service for your small business network.
  • Traffic does not reach the source pfSense firewall: Check whether that firewall is the host’s gateway. A host using a different gateway may send the packet elsewhere.
  • Traffic reaches the firewall but does not enter IPsec: Recheck the remote Phase 2 subnet, policy-routing rules, and whether the tunnel is enabled.
  • Traffic enters IPsec but is blocked at the destination: Check the receiving firewall’s IPsec rules, logs, and internal-interface path.
  • The destination receives traffic but the source gets no reply: Investigate the return route and destination host’s firewall.

Traceroute can omit intermediate hops on a working IPsec path, so missing hops alone do not prove the tunnel is failing. Interpret the result alongside captures and logs.

4. Verify the return path and destination host

A successful outbound path is only half the connection. The destination host must be able to send its reply back toward the remote subnet. Check that it has a default gateway and that the gateway is the correct router—often the pfSense firewall—or that it has another valid route to the remote network. Also verify that the endpoint’s own firewall permits the test protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • POWERFUL - Experience multi-gigabit throughput. 4-Core 2.1 GHz Intel Atom C1110 CPU, 4GB LPDDR5 RAM - Delivers 9.28 Gbps routing for IMIX traffic and 8.61 Gbps of firewall throughput.
  • FLEXIBLE - 4 discrete, unswitched 2.5 Gbps ports, re-configurable as WAN or LAN ports. Supports dual WAN configurations.
  • SECURE - Flexible virtual private network protocols including IPsec, OpenVPN and WireGuard VPN. Includes Intel Advanced Vector Extensions 2 (AVX2) instructions that support faster encryption and cryptographic processing.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.

Run a test in both directions where possible. If one side can initiate a connection and the other cannot, compare the rules and routes for each direction rather than assuming the tunnel behaves identically for both tests.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Use outbound NAT only when the design calls for it

Ordinary LAN-to-LAN access across a site-to-site tunnel does not, by itself, establish a need for outbound NAT. First verify the Phase 2 networks, firewall filtering, and routing. Netgate documents outbound NAT for a different design: sending Internet traffic through the other site. Apply that approach only when it matches the intended traffic flow, not as a generic remedy for a connected tunnel that cannot pass LAN traffic. See Netgate’s IPsec VPN documentation.

Quick Recap

Bestseller No. 1
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$299.00
Bestseller No. 2
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 2100 TAA pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$679.00
Bestseller No. 3
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 4200 MAX pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$829.00
SaleBestseller No. 5
Best Value
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Rank #4
Firewall Mini PC, Intel J1900 4-Port i210 Router, 4GB RAM 64GB SSD
  • 【CPU Optimized for Firewall Mini PCs】This firewall appliance is powered by Intel Quad-Core Celeron J1900, 64-bit, up to 2.0 GHz, supporting software-based encryption. Energy-efficient and reliable, it runs 24/7 for home or small office networks, handling VPNs, multi-WAN routing, and basic firewall tasks efficiently.
  • 【4×Intel i210 Ports】Equipped with four Intel i210 network controllers, each delivering up to 1 GbE for reliable multi-WAN routing, VPN connections, VLAN management, and stable performance in small office or home firewall deployments
  • 【Memory & Storage】This Firewall Mini PC comes with 4 GB DDR3L RAM and a 64 GB mSATA SSD, providing reliable performance for basic networking tasks. AMI BIOS with ACPI support ensures stable system operation and energy-efficient 24/7 use
  • 【Flexible System Compatibility】Compatible with Windows 10, Linux, and professional firewall systems such as pfSense, OPNsense, and VyOS, ensuring stable network management for home or small office use
  • 【After-Sales Support:】This compact, fanless, and silent firewall keeps your network secure. Includes lifetime technical support and a 30-day money-back guarantee!

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.