@CapitanBlack Thank you! that's is what I needed.
I didn't realize I could assign the same IP on pf1 and pf2 wg interfaces.
Now I need to test the failover.
Pulling up an old thread again. I am wondering if we cant have a wireguard setup that is aware of which CARP member is active, so we can have two firewall serving the same clients with seamless failover when one goes down.
Check out my post in Wireguard area - I have S2S Wireguard setup working in HA mode.
I am so sorry to have wasted your time but I've solved this, and it was complete and absolute muppetry on my behalf.
I had, many months ago, attempted to set this same thing up using an IPsec tunnel. The non-working IPsec tunnel was still set up on one of the devices...
It was coming back today after rebooting host and start the pfsense in its VM.
At least i now fond a solution without reboot the host and the pfsense.
Solution was to go to Interfaces -> WGTun0 (tun_wg0) and disable the interface, safe that and the enable the interface gain.
So i gust the WGTun0-Interface will not every time comes up correctly after rebooting pfsense. Something went wrong.
@flat4
Not sure -- but it's really strange how the routing / connection persists after initiating on my cellular network then "transistioning" to the guest wifi
I have the same issue. I'm running pfsense CE 2.7.2 and after restart I have to enable the wireguard gateway, then start the wireguard service.
I was thinking to do a script and add it to a cron job, but I couldn't find the right command that can enable the wireguard gateway. Any help is much appreciated. thanks.