Ipsec vpn site to site with sonicwall



  • Good evening,

    I have successfully configured the site to site vpn from various pfsense vm's to sonicwall's.  However, one of my clients has a sonicwall with 2 ISP.  How can I enable to that on the pfsense side to connect with both public IP's on the sonicwall incase one of the ISP goes down on the client side.

    client side = sonicwall w/ 2 public IP's w/ fail over
    data center side = pfsense vm

    Thank you for your help!


  • Rebel Alliance Developer Netgate

    At the moment there is no way to enter that directly. If the sonicwall side supports Dynamic DNS along with WAN failover you can enter the hostname on pfSense as the peer address. For that to work, the sonicwall side would have to update its address in DNS when the WAN switches, and then pfSense will see the DNS result change and update the IPsec tunnel to follow.


Log in to reply