Redundant LAN with Wifi and VPN routing question



  • Hi,

    I have a setup where the branch office and the HQ is within line of sight, so we have a point to point Wireless Bridge between the HQ and branch.  For redundancy, we have setup a IPSec Site to Site which work.  Now the question is how do I setup dynamic routing where the wifi bridge should be the default and would failover to the VPN when the wifi signal do drop.  Another question,  Is to possible to setup active/active routing on the two links plus failover?  Is there any better way to do this?

    Thank you.

    HQ LAN –-- HQ FW ------- BR Pfsense ----- BR LAN
                            |                  |
                        Wifi hq ------- Wifi br

    Pfsense (Branch)
    WAN 172.188.1.1

    LAN - 10.1.3.1/24

    OPT1 - 172.16.2.10/24 (connect to wifi br)

    IPsec VPN site to site  remote IP 172.190.100.1  - remote LAN 10.1.1.1/24

    wifi hq - 172.16.2.1

    HQ IP - 10.1.1.1/24