@viragomann said in HA, gateway groups and firewall's default route.:
Is it this, why you were looking for localhost?
Not OpenVPN, but the outbound connections from the firewall itself.
In the documentation, localhost should be 'NATted' to interface IP address, which is OK, this part is clear to me.
What wasn't clear to me is if I should have created a new gateway group, using Interface address, to use as the default route of the firewall.
However, since it doesn't translate anything and everything is working, including IPsec, I'll leave as it is right now, everything using the same gateway group, that has the CARP IP there.
Note that without those CARP IPs in the gateway group, IPsec tunnels won't go up.