Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    is it possible to implement redundant IPSec tunnels over 2 different WAN connections?

    Scheduled Pinned Locked Moved IPsec
    3 Posts 3 Posters 615 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • opticalcO
      opticalc
      last edited by

      I would put 2 WANs on PFSense, this would connect to an Azure VPNGW that is redundant (it has 2 different IPs).

      I guess I would create tunnels, such that the "primary" WAN connection has more specific network routes than the "secondary"?

      1 Reply Last reply Reply Quote 0
      • T
        thesurf
        last edited by

        Hi,

        If you wait for 2.4.4 you get routed vpn. With this and the far package you could do this.

        Also you can setup now gre tunnel with ipsec in transport mode. Then use for with ospf on both sides. Then you can but a cost for each tunnel and ospf will use the other tunnel ist the primary goes down.

        Hope that helped you.

        Hint last monthly hangout did a talk about the routed vpn and frr and ospf.

        1 Reply Last reply Reply Quote 0
        • R
          Righter
          last edited by

          Hi

          I've done such a setup with two PFSenses. each has a seperate WAN Provider.
          The other site is a single HA Vmware NSX Edge Firewall.

          I made a scripts which checks the WAN Connection. If the internet fails, the script will switches to the backup PFSense and start there the VPN Tunnel.

          There is nothing much you can do else.
          I'm also waiting for VTI Tunnel Support on 2.4.4

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.