Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't reach backup firewall when connected by VPN

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    5 Posts 2 Posters 651 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      ca_maer
      last edited by

      Hello,

      I've followed the doc to setup the HA and everything works as expected. I only have an issue where if connected by VPN to the main firewall (192.168.1.253) I can't ping nor reach the webui of the backup firewall (192.168.1.254).

      The VPN uses a different subnet (192.168.2.0/24) but I can reach other servers in the same subnet as the firewalls fine.

      When connected locally into the LAN, I can reach the second firewall correctly.

      Is there something special I need to do ?

      Thanks !

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        https://docs.netgate.com/pfsense/en/latest/highavailability/troubleshooting-vpn-connectivity-to-a-high-availability-secondary-node.html

        1 Reply Last reply Reply Quote 1
        • C Offline
          ca_maer
          last edited by

          Thanks for the link ! I was able to make it work for the road warriors but settings the same for the Site-To-Site openvpn tunnel is not working.

          My tunnel is 10.1.99.0/30 so I added the following outbound rule:
          Source: 10.1.99.0/30
          Destination: Alias with both firewalls LAN IPs
          NAT Address: LAN addresse

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            For the site to site vpn, you must use the remote LAN in the source box instead of the tunnel network.

            1 Reply Last reply Reply Quote 1
            • C Offline
              ca_maer
              last edited by

              Well that was it ! Thanks a lot for the help !

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.