Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ipsec over multi wan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    7 Posts 2 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      necross
      last edited by

      Hey guys,
      I was looking for some info on the forums but was unable to find an answer.

      I have a multi wan setup + IPSEC tunnel through one of them.
      I have also configured GW groups for outgoing load balancing (load sharing). Everything works like a charm ;)

      Since our upload speeds are pretty shameful, I was wondering if its possible to use the gateways for said IPSEC tunnel. (some sort of load sharing).

      Is that possible?

      Thanks!

      n.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        No, you can't load balance IPsec in that way.

        You can pull that off with OpenVPN (one tunnel always up on each WAN, interfaces assigned, using a gateway group of VPN gateways, etc)

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • N
          necross
          last edited by

          Hi @Jimp.
          Thanks for your reply.

          Would you be able to explain the difference?
          If I understand you correctly, one tunnel always up using a gateway group would essentially be a Failover rather than a load balance. will it not?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It depends on the gateway group and how you set it up.

            IPsec and OpenVPN can only use a failover group (one gateway per tier) on their actual VPN settings, but what I mentioned is different.

            In the load balancing setup with OpenVPN, OpenVPN would be always active on both WANs โ€“ two clients/two servers, one on each WAN, always connected. When you assign the OpenVPN interfaces, the firewall creates automatic dynamic gateways for the OpenVPN connection itself. Those would be added to a new gateway group that can be set to load balance. So you don't tell OpenVPN to load balance directly.

            You have to be careful with the assignment and placement of the rules, but you can policy route connections into the tunnel and reply-to will send the responses back the correct path. It's still only connection-based load balancing though so a single connection can't max out both VPNs, but with multiple connections/clients it can utilize both.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • N
              necross
              last edited by

              Fair point.
              I am trying to find a solution for an offsite backup while utilizing multiple WANs.
              Any thoughts?

              Thanks!

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                A high speed dedicated fiber circuit? :-)

                Unless you can get MLPPP DSL there won't be a way to bond multiple WANs or VPNs on pfSense into a single larger pipe that will accelerate one connection.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • N
                  necross
                  last edited by

                  Thank youย  ;)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.