Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access to GUI - VPN

    Scheduled Pinned Locked Moved webGUI
    11 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MrGamecaseM
      MrGamecase
      last edited by MrGamecase

      Hi All,

      Experienceing a Weird issue here .....

      I have set up 2 PFSense vBoxes setup in CARP Failover.... Working beautifuly [ Thaks to the help from all on this forum]..... I have set up Wireguard on both PFSense vMachine and i can remote into my network perfectly friom either..... The issue is - I can access the first vPFSense GUI without any issues, when i go theo the second VPfsense GUI nothing i dont get any ui.

      If i switch over the Wireguard connections the issue is reversed i can access the second but not the first

      Both oxes are on the same LAN Subnet.........vPFSenseA - 10.20.10.253 vPFSenseB - 10.20.10.252. if i am within the network no VPN i can access both boxes withoiut any issues.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @MrGamecase
        last edited by

        @MrGamecase
        The solution is described in the docs:
        Troubleshooting VPN Connectivity to a High Availability Secondary Node

        MrGamecaseM 1 Reply Last reply Reply Quote 1
        • MrGamecaseM
          MrGamecase @viragomann
          last edited by

          @viragomann

          Indeed it it, I missed that in there guidance.... Thank you 👍

          1 Reply Last reply Reply Quote 0
          • MrGamecaseM
            MrGamecase
            last edited by

            For example, add a manual outbound NAT rule on the LAN interface, - DONE

            source being the VPN subnet, destination being an alias that contains both the primary and secondary node LAN IPs., DONE

            Translation would be Interface Address (NOT the CARP VIP!)., I'm confused with this bit

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @MrGamecase
              last edited by

              @MrGamecase
              Why?
              The goal is that response pavkets from the backup node come back to the master. So interface address is fine. However, CARP VIP should work ad well, since it is always owned by the master.

              MrGamecaseM 1 Reply Last reply Reply Quote 0
              • MrGamecaseM
                MrGamecase @viragomann
                last edited by

                @viragomann said in Access to GUI - VPN:

                @MrGamecase
                Why?
                The goal is that response pavkets from the backup node come back to the master. So interface address is fine. However, CARP VIP should work ad well, since it is always owned by the master.

                Im having a complete DUMB moment, Im forgeting im unsing VLAN 10 as management access to the systems. I saw LAN and set it up on the LAN interface wich was why i got confised as to why it wasnt working.

                Changing the interfaces to my VLAN 10 interfaces everything now finctions as expected..

                Once again Thank you for you help in resolving anoth issue i. had with CARP

                1 Reply Last reply Reply Quote 0
                • MrGamecaseM
                  MrGamecase
                  last edited by

                  @viragomann

                  On a complete random note.... i use mesh cenrtal as a systems management / remote access software [ self hosted behind firewall ]. how would i get this to work if primary vPFSense server failed.

                  the dnns name runs through cloudflare pointingb to the primary

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @MrGamecase
                    last edited by

                    @MrGamecase said in Access to GUI - VPN:

                    the dnns name runs through cloudflare pointingb to the primary

                    Point the host name to the WAN CARP VIP.

                    MrGamecaseM 1 Reply Last reply Reply Quote 0
                    • MrGamecaseM
                      MrGamecase @viragomann
                      last edited by MrGamecase

                      @viragomann said in Access to GUI - VPN:

                      @MrGamecase said in Access to GUI - VPN:

                      the dnns name runs through cloudflare pointingb to the primary

                      Point the host name to the WAN CARP VIP.
                      Screenshot 2024-03-11 at 12.15.04 am.png

                      Just to confirm where the red box was pointing to one of the wan on the vPFSense. i change this ti CARP VIP.

                      also adjusting the wan rule for trhe ports - changing destination to the wan CARP VIP?

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @MrGamecase
                        last edited by

                        @MrGamecase
                        Of course. All access should use the CARP VIP. Likewise all internal devices have to use the respective CARP as default gateway to go to the internet or other network segments.

                        MrGamecaseM 1 Reply Last reply Reply Quote 1
                        • MrGamecaseM
                          MrGamecase @viragomann
                          last edited by

                          @viragomann said in Access to GUI - VPN:

                          @MrGamecase
                          Of course. All access should use the CARP VIP. Likewise all internal devices have to use the respective CARP as default gateway to go to the internet or other network segments.

                          I got ya, Slowly understanding CARP😁

                          Thankyou for your help this evenig VERY much apreciated

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.