Gateway Group, Routed VTI IPSEC tunnels and failover
-
Hello,
I have two VPN tunnels, from the same network (AWS), to provide redundancy. The IPSEC connection (Routed VTI) on the pfSense side is functional for both tunnels.
But for redundancy, I'd like to do automatic failover. I've defined a Gateway Group, bringing together the two IPSEC interfaces. I've specified this Gateway in my firewall rules. However, as soon as I remove the static route (defined for a single IPSEC interface, as I can't define two on the same network), the VPN network is no longer routed.
Is it possible to do automatic failover with Gateway Group and Routed VTI IPSEC tunnels ?
-
@lc63
The answer seems to be no. I have switched to Policy-based mode for tunnels, which allows failover automatically.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.