Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Re-establish site-to-site IPsec on failover (CARP)

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 531 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      Hello all,

      I'd appreciate any help or suggestions that people may have.

      Firstly, my setup includes 2 PfSense boxes (2.4.1) with both CARP and IPsec setup and working correctly.  Connections are initiated from the remote end (router) to the CARP address and re-establish themselves within ~1 second upon disconnecting the tunnel from my end.

      The problem I'm having is during testing of a firewall failover, if I enter persistent maintenance mode (or simply change advskew), everything fails over to the backup as expected but the IPsec tunnel remains on the primary (now backup) firewall. In the ipsec.log file, I can see the following when this happens as well;

      "old path is not available anymore, try to find another"
      "looking for a route to 123.123.123.123"

      If I disconnect the IPsec session via the browser or CLI on the former primary firewall, it is re-established again on the same firewall (instead of the backup that now has the CARP address) which I can also see in ipsec.log.

      Has anybody else had experience with this and have any suggestions on how to prevent this from happening?

      Thanks

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.