Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP BACKUP OPENVPN SITE2SITE

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 2 Posters 695 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vettalex
      last edited by

      Hi everyone, I have a VPN between 2 Site2Site pfsense that works perfectly:

      SITE A (SERVER) public_ip A
      SITE B (CLIENT) public_ip B

      Now, a 4G backup line is configured on the SITE B router, with a public IP "different" from the main one.
      How can I set the pfsense so that if the main line of SITE B falls and the backup line goes up, also changing the public ip address, the VPN connection is automatically re-established?

      Thanks a lot to everyone in advance

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @vettalex
        last edited by

        @vettalex
        Did you already configure a gateway failover group and set it as default?

        If that is already done, in the client settings simply change the interface to any.

        V 1 Reply Last reply Reply Quote 0
        • V
          vettalex @viragomann
          last edited by

          @viragomann no, let me explain:
          The router has a housing inside for a 4g backup sim that comes into operation only when the main line drops.
          The pfsense WAN always points only to the router's LAN ip, I don't know if I was clear ...

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @vettalex
            last edited by

            @vettalex
            So there is a router in front of pfSense which is used as default gateway and pfSense establishes the VPN? So the router has to switch the upstream gateway to the 4g if the main line fails and nothing should be to do on pfSense at all.

            V 2 Replies Last reply Reply Quote 0
            • V
              vettalex @viragomann
              last edited by

              @viragomann that's right, just that the main line and the backup line have 2 different public IPs

              1 Reply Last reply Reply Quote 0
              • V
                vettalex @viragomann
                last edited by

                @viragomann the problem is just that, how can I tell pfsense that in the pfsense server / client configuration the public ip changes if the main line drops?

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @vettalex
                  last edited by

                  @vettalex
                  If it's an SSL/TLS setup check "Dynamic IP" in the server settings.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.