
Closed
Posted
Paid on delivery
My site-to-site IPsec tunnel was built following best-practice guides, yet the link keeps dropping for reasons I can’t see. The firewall on my side is an Opnsense appliance, and each time the tunnel fails the logs simply show that the connection drops intermittently without any clear error codes. I may have tweaked something recently, but I’m honestly not sure which setting—so I need a fresh, expert pair of eyes. You should be comfortable working with Opnsense and, ideally, have experience on Checkpoint or other enterprise firewalls so you can think through the usual Phase 1 / Phase 2, NAT-T, lifetime, and crypto-profile culprits quickly. I can give you full access to the existing configuration, live logs, and packet captures through a remote session. The job is complete when you: • identify the root cause of the dropouts, • apply and document the corrective changes, and • confirm the tunnel stays up under sustained traffic. If additional monitoring or rule cleanup is required, let me know and we can extend the scope. Looking forward to having this link rock-solid again.
Project ID: 40586817
17 proposals
Remote project
Active 5 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
17 freelancers are bidding on average $24 USD for this job

Hello Dear, I am a VPN expert and i have hands-on experience with OpenVPN, WireGuard, IPsec, L2TP, PPTP, SSL, etc. I have a Cisco CCNP certificate. I have great experience in various network technologies such as VLAN, STP, OSPF, EIGRP, BGP, MPLS, etc. Also, I have great hands-on experience in, - Cisco Routers ASR 9k&1k, ISR 4K, 2900, 2800, 878, 888, Switches Nexus 9K, Cat 6500, 3850, 2900 and ASA 5505, 5506x, 5508. - Juniper Routers (M7, M10, MX 480, MX 960) and SRX (300, 500). - Palo Alto 220, 550, 850 and 3200 and Fortigate 100E, 200E and 800E Firewalls. - Huawei routers NE-40, NE5000E and Switches Quidway S2700 and S5300. - HP Switches procurve 3500 and procurve 5900. - Mikrotik RB2011 and CCR1009. Regards, Ahmed Fakkar
$30 USD in 1 day
7.8
7.8

Having spent over a decade in the IT and services industry, I've amassed valuable experience across prominent brands like Cisco, Checkpoint, and Opnsense. This exposure has granted me an astute understanding of network administration and cybersecurity that will prove pivotal in resolving your IPsec tunnel issues effectively. I remember well the frustration of having a critical link consistently fail for mind-boggling reasons and I'd love to take on this challenge for you. In my career, I've garnered robust skills in troubleshooting complex network problems, precisely discerning where issues are occurring, even if evident error codes are lacking. Furthermore, my expertise extends into examining critical areas such as Phase 1/Phase 2, NAT-T, lifetime, and crypto-profiles - all necessary undertaking as we diagnose the root cause and work to ensure stability under sustained traffic. Above all skills and expertise though, what sets me apart is my reputation for diligently working according to best-practices. Given access to your configuration logs and packet captures through remote sessions, I'll leave no stone unturned whilst exploring potential causes, making corrective changes judiciously and documenting them comprehensively for future reference. Whether it's additional monitoring or rule cleanup - included or extended -I'm ready to adapt the further scope of the project to guarantee a rock-solid connection for you.
$30 USD in 2 days
7.3
7.3

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
$20 USD in 1 day
6.6
6.6

Hi there! My name is Muhammad and I'm a Freelance Network and Security Professional specializing in the deployment and management of enterprise-level firewalls such as Opnsense, Checkpoint, Palo Alto, Cisco ASA, Fortinet, and more. With over a decade of experience in the field, I've had extensive exposure to diagnosing complex IPsec tunnel issues just like yours. I understand the frustration that comes with intermittent connectivity drops, especially when the cause is not immediately clear. That's why I'm confident that my expertise in Phase 1/Phase 2 configurations, NAT-T, lifetime management, and crypto-profile identifications will be instrumental in getting your tunnel functioning flawlessly again. Furthermore, my proficiency with packet captures and log analysis will enable me to pinpoint the root cause of the disruptions and implement sustainable solutions. Moreover, my skills reach beyond merely diagnosing and resolving this specific issue. I am well-versed in network monitoring and troubleshooting; so if there are any additional problems or fine-tuning required during our engagement or even beyond it, know that you're in good hands. Let's start tackling this issue together — I assure you we'll have your site-to-site IPsec tunnel working seamlessly shortly!
$50 USD in 1 day
6.0
6.0

Hi! I have hands-on experience troubleshooting IPsec VPNs on OPNsense and enterprise firewalls, including Phase 1/Phase 2 mismatches, NAT-T, lifetimes, crypto settings, and routing issues. I'll identify the root cause of the tunnel dropouts, implement the necessary fixes, and verify the VPN remains stable under sustained traffic. I'll also document all changes made and recommend any additional optimizations if needed.
$20 USD in 1 day
4.1
4.1

Hi there! I understand you need support finding software engineering opportunities and creating strong proposals that improve your chances of getting interviews. The main challenge is presenting your skills properly and matching each proposal with the client’s needs. We have experience writing technical proposals for web, mobile, and software development projects. We know how to highlight skills, project experience, and technical value in a clear way. Our focus is on creating personalized proposals that make a strong impression. We will research suitable software engineering projects, review requirements, and prepare customized proposals for each opportunity. We will highlight your strengths, explain your experience clearly, and maintain a professional application process to improve your chances. check our work [https://www.freelancer.com/u/ayesha86664](https://www.freelancer.com/u/ayesha86664) Could you share your main software skills and the type of projects you want to target? Let me know if you’re interested & we can discuss it. Best Regards Ayesha
$15 USD in 3 days
2.4
2.4

The bid amount and timeline above are rough placeholders, we'll sharpen both once we've had a look at the config and logs. Intermittent tunnel drops on an OPNsense site-to-site setup are frustrating precisely because the logs rarely hand you a clean error. From what you've described, the usual suspects are a Phase 1 or Phase 2 lifetime mismatch with the remote peer, a NAT-T or DPD setting that's slightly off, or a crypto profile that drifted after a recent tweak. The goal here is a tunnel that stays up under real traffic, fully documented so you're not guessing the next time something changes. Here's how we'd approach it: - Phase 1 audit: Pull the IKE proposals on both sides and compare lifetimes, encryption, hashing, and DH group. Mismatches here are a common silent killer. - Phase 2 and PFS check: Verify the child SA settings match, confirm Perfect Forward Secrecy is consistent, and check that the traffic selectors aren't too broad or too narrow. - NAT-T and DPD review: Look at keep-alive intervals and dead peer detection config, since an aggressive DPD timeout can cause drops that look random in the logs. - Packet capture analysis: Walk through the captures you have during a drop event to pinpoint exactly where the handshake breaks down. - Fix, test, document: Apply the corrective changes live in the remote session, run sustained traffic through the tunnel, and hand you a written summary of what was wrong and what was changed. After the session we can put together a short written summary of the findings and changes for your records. Want to set up a remote session this week so we can get eyes on the live config and logs? Best, 96 Studio
$30 USD in 2 days
1.1
1.1

Hi, this is Joshua from Davis. I have worked on network and firewall troubleshooting for a range of environments. You need a stable site to site IPsec tunnel and a clear answer on why it drops. I would start by checking Phase 1 and Phase 2 settings, NAT-T behavior, lifetimes, and any recent config change that may have shifted the tunnel state. I would review the OPNsense VPN logs, compare the crypto profiles on both ends, inspect rules and states, and use packet captures to trace where the negotiation breaks. If needed, I would also test traffic flow under load to confirm the tunnel stays up after the fix. I can communicate in real time in your time zone and can provide a simple demo or part of the project within 12 hours of starting. Q1: Are you seeing the drop during renegotiation, or only when traffic is passing? Q2: Have both sides kept matching Phase 1 and Phase 2 lifetimes and proposals? Q3: Did the recent tweak involve NAT, firewall rules, or VPN advanced settings? Best regards.
$15 USD in 1 day
0.0
0.0

It sounds like you've already put in considerable effort to set up the IPsec tunnel, but intermittent drops can be especially frustrating. We specialize in diagnosing and resolving connectivity issues for network appliances, ensuring robust and stable connections for our clients. With a deep understanding of Opnsense and experience with enterprise firewalls, I can quickly pinpoint the cause of your tunnel's instability. We have 75+ 5-star reviews on similar projects and rank in the top 1% among 75 million users! Could you share any recent changes you made prior to the drops, or are there specific times when the issues occur? Regards, Hamza
$15 USD in 7 days
0.0
0.0

We provide experienced IT Field Engineers for onsite support worldwide. Our services include Smart Hands, Remote Hands, Desktop Support, Network Support, Server Installation, IMAC, Break/Fix, and L1/L2 IT Support. We offer fast response and 24/7 coverage.
$40 USD in 7 days
0.0
0.0

Hello, I have strong experience in network administration and troubleshooting, specifically with Opnsense and IPsec tunnel configurations. I understand how frustrating intermittent connection drops can be, and I am confident in my ability to identify the root cause—whether it is a Phase 1/Phase 2 mismatch, NAT-T issue, or lifetime configuration error. My approach includes a thorough review of your logs, verification of security parameters, and performing packet captures to ensure a rock-solid, stable connection. I am ready to work with you via a remote session to resolve this efficiently.
$20 USD in 7 days
0.0
0.0

Hello, I can troubleshoot the intermittent IPsec tunnel drops by reviewing the OPNsense configuration, IKE/IPsec logs, security associations, routing, firewall and NAT rules, and packet captures from both normal and failed sessions. I will compare Phase 1 and Phase 2 proposals, encryption settings, PFS, lifetimes, DPD, rekey behavior, NAT-T, MTU, and peer-side parameters to isolate the actual cause. I’ll begin with a configuration backup and read-only review before applying any approved changes. After remediation, I will test the tunnel under sustained traffic and provide a concise report covering the root cause, changes made, and verification results. Please confirm the remote firewall model, whether the peer-side configuration/logs are available, and the monitoring period required to consider the tunnel stable.
$20 USD in 7 days
0.1
0.1

Hey there, looking forward to hearing from you Your post highlights a frustrating issue with intermittent tunnel drops despite following best practices. The lack of clear error codes in the logs indicates a deeper, underlying problem that needs expert attention. I have successfully diagnosed and resolved similar IPsec tunnel issues, ensuring stability across various firewall configurations. I will pinpoint the root cause of the dropouts, implement corrective changes, and confirm sustained connectivity. Your mention of Opnsense and the potential tweaks suggests a close examination of the Phase 1 and Phase 2 settings is necessary. While my profile is new, my extensive background in network troubleshooting speaks for itself with a focus on reliable outcomes. Let’s discuss the specific settings you’ve adjusted to tailor my approach effectively. Chat Soon, Warm Regards Mthoko
$10 USD in 7 days
0.0
0.0

Hello, I have experience troubleshooting IPsec VPNs, OPNsense, and enterprise firewalls. I can review your Phase 1/2 settings, NAT-T, crypto policies, logs, and packet captures to identify the root cause, implement the required fixes, and verify the tunnel remains stable. I agree to work on this project and can start immediately.
$25 USD in 7 days
0.0
0.0

Heidelberg, Germany
Payment method verified
Member since Mar 10, 2022
€8-30 EUR
$15-25 USD / hour
₹400-750 INR / hour
$15-25 USD / hour
€8-30 EUR
$10-30 USD
$15-25 USD / hour
₹12500-37500 INR
$25-50 USD / hour
$10-30 USD
₹12500-25000 INR
$10-30 USD
$2000-6000 HKD
$15-25 USD / hour
min €36 EUR / hour
$30-250 USD
$15-25 USD / hour
₹12500-37500 INR
$15-25 USD / hour
₹1500-12500 INR
$250-750 USD