Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN with HA/CARP not connecting on VIP

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 795 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      Kajetan321
      last edited by Kajetan321

      Hello. I have successfully got HA with CARP working. I tested by pulling the plug on the main firewall and sure enough the connection to the Internet on a client computer was maintained through the second firewall. When I enter "what is my IP address" into Google I get the VIP external address.

      I have also been able to get Open VPN to work when using the non VIP address for the server's interface. However as soon as I switch the interface to the VIP one, the OpenVPN client hangs right
      after the UDPv4 link remote: [AF-INET] {external CARP VIP address}.

      I'm trying to follow what's mentioned here:
      https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-vpn-secondary.html

      To create the HA/CARP setup I followed this tutorial:

      https://www.youtube.com/watch?v=-1Og5ogkyZY

      Any ideas as to what might be wrong? I'm new to pfSense.

      Cheers,
      Kajetan.

      K 2 Replies Last reply Reply Quote 0
      • K
        Kajetan321 @Kajetan321
        last edited by

        I tried following this guide:

        https://vorkbaard.nl/openvpn-in-a-pfsense-carp-cluster/

        and entered the "local {External CARP VIP}" into the custom options field. As far as I can tell, nothing changed.

        1 Reply Last reply Reply Quote 0
        • K
          Kajetan321 @Kajetan321
          last edited by

          When looking at System Logs > Firewall it seems OpenVPN packets are being blocked. I don't know how to change that. Is the rule created by the OpenVPN wizard not enough?

          d55be343-b84e-425a-a219-ba459f3281c2-image.png

          2d8810e3-9463-45b4-8fa3-8d968824ae30-image.png

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @Kajetan321
            last edited by

            @Kajetan321 said in OpenVPN with HA/CARP not connecting on VIP:

            s the rule created by the OpenVPN wizard not enough?

            No, "WAN address" doesn't seem to be the VIP. So you will have to edit the rule and change the destination to the desired VIP.

            K 1 Reply Last reply Reply Quote 1
            • K
              Kajetan321 @viragomann
              last edited by

              @viragomann Thank you, that did the trick. In the rule I changed:

              Destination
              Destination: WAN address

              to

              Destination
              Destination: Single host or alias 99.XXX.XXX.XXX

              1 Reply Last reply Reply Quote 0
              • R reberhar referenced this topic on
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.