<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC Failover - how to implement?]]></title><description><![CDATA[<p dir="auto">I'm planning to implement a failover IPSEC tunnel between two sites.</p>
<p dir="auto">Site A will have to independent static connections to the internet with to ISPs.<br />
Site B will have one static connection to the internet.</p>
<p dir="auto"><img src="https://forum.pfsense.org/index.php?action=dlattach;topic=115156.0;attach=84326;image" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">Main problem is, if one of the two connections from site A fail, the IPSEC tunnel should switch to ISP B.</p>
<p dir="auto">How to implement this?<br />
Would openVPN be a better option?<br />
<img src="/public/_imported_attachments_/1/site2site.png" alt="site2site.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/site2site.png_thumb" alt="site2site.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/102782/ipsec-failover-how-to-implement</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Jul 2026 11:05:55 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/102782.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 14 Jul 2016 08:01:19 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC Failover - how to implement? on Mon, 25 Jul 2016 20:48:34 GMT]]></title><description><![CDATA[<p dir="auto">I accomplish what you request, using WAN groups and dyndns..</p>
<p dir="auto">I attach my configurations, hope this helps you</p>
<p dir="auto">![Screen Shot 2016-07-25 at 5.43.41 PM.png](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.43.41 PM.png)<br />
![Screen Shot 2016-07-25 at 5.43.41 PM.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.43.41 PM.png_thumb)<br />
![Screen Shot 2016-07-25 at 5.43.50 PM.png](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.43.50 PM.png)<br />
![Screen Shot 2016-07-25 at 5.43.50 PM.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.43.50 PM.png_thumb)<br />
![Screen Shot 2016-07-25 at 5.46.08 PM.png](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.46.08 PM.png)<br />
![Screen Shot 2016-07-25 at 5.46.08 PM.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.46.08 PM.png_thumb)<br />
![Screen Shot 2016-07-25 at 5.47.26 PM.png](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.47.26 PM.png)<br />
![Screen Shot 2016-07-25 at 5.47.26 PM.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2016-07-25 at 5.47.26 PM.png_thumb)</p>
]]></description><link>https://forum.netgate.com/post/639752</link><guid isPermaLink="true">https://forum.netgate.com/post/639752</guid><dc:creator><![CDATA[acc4ever]]></dc:creator><pubDate>Mon, 25 Jul 2016 20:48:34 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC Failover - how to implement? on Wed, 20 Jul 2016 15:43:41 GMT]]></title><description><![CDATA[<p dir="auto">OpenVPN is a better option for this situation. You could use a dyndns target which would switch between the ISP's at site A.<br />
There is no way to have two targets for the same connection like you can do in some commercial firewalls.</p>
]]></description><link>https://forum.netgate.com/post/638734</link><guid isPermaLink="true">https://forum.netgate.com/post/638734</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Wed, 20 Jul 2016 15:43:41 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC Failover - how to implement? on Wed, 20 Jul 2016 13:57:28 GMT]]></title><description><![CDATA[<p dir="auto">I believe this can only be done with the help of the ISP, but I am not 100%.</p>
<p dir="auto">I'd be interested to know if anyone provides some other idea.</p>
]]></description><link>https://forum.netgate.com/post/638715</link><guid isPermaLink="true">https://forum.netgate.com/post/638715</guid><dc:creator><![CDATA[mannyjacobs73]]></dc:creator><pubDate>Wed, 20 Jul 2016 13:57:28 GMT</pubDate></item></channel></rss>