• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPsec multi-wan failover

Scheduled Pinned Locked Moved IPsec
40 Posts 21 Posters 38.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kapara
    last edited by Feb 13, 2013, 4:34 PM

    Are there any tutorials for this process?  I have not been able to find one…

    Skype ID:  Marinhd

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Feb 13, 2013, 4:47 PM

      Not yet. That's really all there is to it though.

      Setup DynDNS, set to use a failover gateway group.
      Setup IPsec to use the same failover gateway group.
      Set the other end to use the dyndns host as the peer address.

      Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • K
        kapara
        last edited by Feb 13, 2013, 6:58 PM

        but DynDns uses a name and the gateways require IP addresses so I am not following you.

        Skype ID:  Marinhd

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Feb 13, 2013, 7:12 PM

          IPsec peers can be hostnames.

          The identifier is left as "My IP Address" and "Peer IP Address". The remote gateway for IPsec is the dyndns hostname.

          Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • D
            dhatz
            last edited by Feb 13, 2013, 10:11 PM

            jim, what were the changes in 2.1 that facilitated this new IPsec multi-wan failover feature ?

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Feb 13, 2013, 10:13 PM

              I'd have to dig through the code, I don't recall, it's been several months. databeestje originally did the work.

              Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • F
                flojose
                last edited by Apr 25, 2013, 3:37 PM

                Hi.

                I have setup this with 2 pfsense 2 dedicated static IP WAN.

                Results are not what I expect:
                Wen WAN1 goes down on Local PFsense:
                Dyn update failovergroup.
                Firewall rules using  failover group as wan acts correctly.
                IPSec tunnel does not UP. Logs show that is trying to use WAN1 IP adress to stablish tunel. Remote pfsense does not permit connections from that peer.

                Remote PFSense:
                IPSec tunnel goes down after timeout, as Dyn hostname has been updated, IPSec tries to stablish tunnel to new IP Address, Remote PFsense does not respond.
                IPSec logs shows a unknown peer trying to stablish a connection to local ipsec port.

                Solution:
                I have to restart racoon service on Local PFSense for racoon start using WAN2 IP.

                Same results if WAN1 goes down on Remote PFSense.

                Is there a way to add than when routing changes due multiwan failover, a service(s) can be restarted?

                1 Reply Last reply Reply Quote 0
                • J
                  jimp Rebel Alliance Developer Netgate
                  last edited by Apr 25, 2013, 4:47 PM

                  Try the patch from this ticket:
                  http://redmine.pfsense.org/issues/2896

                  Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • F
                    flojose
                    last edited by Apr 26, 2013, 1:43 AM

                    Thank you so much.

                    I will try it.

                    1 Reply Last reply Reply Quote 0
                    • N
                      nnogales
                      last edited by Aug 1, 2013, 11:28 AM

                      I have the same issue but I don't know how to apply the path

                      1 Reply Last reply Reply Quote 0
                      • B
                        Briantist
                        last edited by Nov 18, 2013, 4:07 PM

                        Did anyone ever do do this successfully?

                        Also, has anyone successfully done multi-wan failover with a sonicwall?

                        I also do not know how to apply the patch mentioned except to manually make the changes which doesn't seem like the best idea.

                        1 Reply Last reply Reply Quote 0
                        • J
                          jimp Rebel Alliance Developer Netgate
                          last edited by Nov 18, 2013, 4:21 PM

                          The patch is no longer needed. There is a checkbox to activate the behavior on 2.1 (System > Advanced, Misc tab, under IP Security)

                          Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 0
                          • B
                            Briantist
                            last edited by Nov 18, 2013, 4:26 PM

                            Ah, got it. So I guess there's no way to use mutiple gateways for the remote side except to use Dynamic DNS?

                            1 Reply Last reply Reply Quote 0
                            • A
                              acriollo
                              last edited by Dec 29, 2013, 8:21 AM

                              Flojose, what was the behavior after you appplied the patch code?

                              Results as expected ?

                              1 Reply Last reply Reply Quote 0
                              • S
                                sollostech
                                last edited by Feb 6, 2014, 10:03 PM

                                Can this be done if one side of the VPN is not a pfSense? I am going to a Fortigate on Fiber in Atlanta with a pfSense in Michigan with Cable and DSL connections.

                                Thanks!

                                1 Reply Last reply Reply Quote 0
                                • luckman212L
                                  luckman212 LAYER 8
                                  last edited by May 28, 2014, 11:42 PM

                                  @sollostech:

                                  Can this be done if one side of the VPN is not a pfSense? I am going to a Fortigate on Fiber in Atlanta with a pfSense in Michigan with Cable and DSL connections.

                                  Did you ever get an answer on this? I have a similar scenario and before I bang my head against the wall just wanted to know if you got it working.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    sollostech
                                    last edited by May 29, 2014, 2:00 PM

                                    No unfortunately.

                                    1 Reply Last reply Reply Quote 0
                                    • N
                                      neo_X
                                      last edited by Jun 18, 2014, 6:38 PM

                                      Hello guys,

                                      I have the pfSense firewall 2.1.3 and need configure ipsec failover with sonicwall. I know that sonicwall have the option for add the second peer in the configuration ipsec vpn, very easy.

                                      Do you configure failover ipsec vpn?

                                      1 Reply Last reply Reply Quote 0
                                      • N
                                        niccarp89
                                        last edited by Sep 1, 2014, 5:44 AM

                                        Hi to all, anyone has test it again this with new versions of psense or have experience?

                                        Also knows some dns service as dyndns but free?, i have one side of the ipsec tunel with three internet providers with CARP so having this feature will be amazing.

                                        How i can create the group routing pointing to the group?, i have statics ips on both sides free to use.

                                        Thanks

                                        1 Reply Last reply Reply Quote 0
                                        • N
                                          neo_X
                                          last edited by Sep 1, 2014, 10:47 AM

                                          @niccarp89:

                                          Hi to all, anyone has test it again this with new versions of psense or have experience?

                                          Also knows some dns service as dyndns but free?, i have one side of the ipsec tunel with three internet providers with CARP so having this feature will be amazing.

                                          How i can create the group routing pointing to the group?, i have statics ips on both sides free to use.

                                          Thanks

                                          Hi,

                                          I can help you with the tests, ok.    Do you have dyndns service like a noip.com ?

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            [[user:consent.lead]]
                                            [[user:consent.not_received]]