Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access to GUI - VPN

    Scheduled Pinned Locked Moved webGUI
    11 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @MrGamecase
      last edited by

      @MrGamecase
      The solution is described in the docs:
      Troubleshooting VPN Connectivity to a High Availability Secondary Node

      MrGamecaseM 1 Reply Last reply Reply Quote 1
      • MrGamecaseM
        MrGamecase @viragomann
        last edited by

        @viragomann

        Indeed it it, I missed that in there guidance.... Thank you 👍

        1 Reply Last reply Reply Quote 0
        • MrGamecaseM
          MrGamecase
          last edited by

          For example, add a manual outbound NAT rule on the LAN interface, - DONE

          source being the VPN subnet, destination being an alias that contains both the primary and secondary node LAN IPs., DONE

          Translation would be Interface Address (NOT the CARP VIP!)., I'm confused with this bit

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @MrGamecase
            last edited by

            @MrGamecase
            Why?
            The goal is that response pavkets from the backup node come back to the master. So interface address is fine. However, CARP VIP should work ad well, since it is always owned by the master.

            MrGamecaseM 1 Reply Last reply Reply Quote 0
            • MrGamecaseM
              MrGamecase @viragomann
              last edited by

              @viragomann said in Access to GUI - VPN:

              @MrGamecase
              Why?
              The goal is that response pavkets from the backup node come back to the master. So interface address is fine. However, CARP VIP should work ad well, since it is always owned by the master.

              Im having a complete DUMB moment, Im forgeting im unsing VLAN 10 as management access to the systems. I saw LAN and set it up on the LAN interface wich was why i got confised as to why it wasnt working.

              Changing the interfaces to my VLAN 10 interfaces everything now finctions as expected..

              Once again Thank you for you help in resolving anoth issue i. had with CARP

              1 Reply Last reply Reply Quote 0
              • MrGamecaseM
                MrGamecase
                last edited by

                @viragomann

                On a complete random note.... i use mesh cenrtal as a systems management / remote access software [ self hosted behind firewall ]. how would i get this to work if primary vPFSense server failed.

                the dnns name runs through cloudflare pointingb to the primary

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @MrGamecase
                  last edited by

                  @MrGamecase said in Access to GUI - VPN:

                  the dnns name runs through cloudflare pointingb to the primary

                  Point the host name to the WAN CARP VIP.

                  MrGamecaseM 1 Reply Last reply Reply Quote 0
                  • MrGamecaseM
                    MrGamecase @viragomann
                    last edited by MrGamecase

                    @viragomann said in Access to GUI - VPN:

                    @MrGamecase said in Access to GUI - VPN:

                    the dnns name runs through cloudflare pointingb to the primary

                    Point the host name to the WAN CARP VIP.
                    Screenshot 2024-03-11 at 12.15.04 am.png

                    Just to confirm where the red box was pointing to one of the wan on the vPFSense. i change this ti CARP VIP.

                    also adjusting the wan rule for trhe ports - changing destination to the wan CARP VIP?

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @MrGamecase
                      last edited by

                      @MrGamecase
                      Of course. All access should use the CARP VIP. Likewise all internal devices have to use the respective CARP as default gateway to go to the internet or other network segments.

                      MrGamecaseM 1 Reply Last reply Reply Quote 1
                      • MrGamecaseM
                        MrGamecase @viragomann
                        last edited by

                        @viragomann said in Access to GUI - VPN:

                        @MrGamecase
                        Of course. All access should use the CARP VIP. Likewise all internal devices have to use the respective CARP as default gateway to go to the internet or other network segments.

                        I got ya, Slowly understanding CARP😁

                        Thankyou for your help this evenig VERY much apreciated

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.