• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WireGuard HA Sync

WireGuard
3
3
1.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    MMapplebeck
    last edited by MMapplebeck Feb 22, 2021, 4:02 PM Feb 22, 2021, 3:59 PM

    Is there a reason that WireGuard is not synchronized to HA peers? I am switching over to WireGuard due to the issues with IPSec in 21.02, and would like to sync them between my HA units. For now, I am just going to backup the WireGuard section from the primary unit, and restore that specific section on the backup device, and manually add the wgX interfaces, then rules should replicate properly.

    Is there some caveat that I missed in the documentation that may cause problems? I have all WG peers set to dynamic so that the HA unit does not initiate. I also have the filter rules on the HA units to only accept connectiong to WireGuard ports on CARP VIPs.

    Thanks,

    • Marc
    J 1 Reply Last reply Feb 23, 2021, 11:11 AM Reply Quote 0
    • J
      JeGr LAYER 8 Moderator @MMapplebeck
      last edited by Feb 23, 2021, 11:11 AM

      @mmapplebeck As Wireguard does not "listen" on an interface or a specific IP it's a bit tricky/hard to make it compliant to CARP, as besides forcing it to accept incoming connections only via the CARP IP you don't have a way to force outgoing connections (WG is server/clientless after all and can be both) via the CARP IP and will end up of a peer being connected to the host itself rather than the CARP IP. So a failover will likely result in a broken connection that has to be reestablished.

      As far as my understanding of the current situation is, it is recommended to just create two separate tunnels to the remote peer and use a mechanism like OSPF to switch the active node instead of trying to force "CARP'ish" failover behavior onto wireguard that doesn't really understand it.

      Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

      If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

      1 Reply Last reply Reply Quote 0
      • V
        viktor_g Netgate
        last edited by Feb 23, 2021, 1:28 PM

        see https://redmine.pfsense.org/issues/11302

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.