Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec VPN Multiple Peer IPs

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Phil
      last edited by

      One side of the tunnel has a failover IP that is used when the primary connection goes down. I've successfully established an IPSec tunnel with a Cisco ASA device, by adding both IPs as peers on the ASA side. Is this possible on pfSense?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Not directly, no. But if the side with multiple IP addresses can setup a dyndns entry that will change based on the "active" IP for the tunnel it can switch that way.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • P
          Phil
          last edited by

          @jimp:

          Not directly, no. But if the side with multiple IP addresses can setup a dyndns entry that will change based on the "active" IP for the tunnel it can switch that way.

          Do you know what the implications with regards to caching of this lookup are? Is it looked up on every connection attempt or does the TTL of the record affect it?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It works similarly to how lookups are handled for aliases. It's checked every few minutes and if the DNS entry has changed, /etc/rc.newipsecdns is run. I believe it's also checked when the tunnel settings are synchronized so that the IP address may be written into the ipsec configuration.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.