Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual IPSEC tunnel - Failover

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 2 Posters 903 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      luan.provesi
      last edited by

      Hi everyone

      I have the scenario:

      PfSense with two WAN and at the other end (Cloud) two WAN as well.
      I have two IPSec tunnels, configured like this:
      10.x.x.x:WAN1 >> WAN1:172.1.x.x; 172.2.x.x, ...
      10.x.x.x:WAN2 >> WAN2:172.1.x.x; 172.2.x.x, ...
      Each subnet has its phase2

      Currently, if I leave both tunnels active, at some point packet losses occur, and I need to disable one of the tunnels.

      I would like to leave only one of the tunnels active and the second tunnel active in case the first one goes down.

      It's possible? I've seen in other scenarios use metric in static routes.
      Note: I cannot use only 1 tunnel + DDNS because the Cloud does not accept this type of configuration.

      Sorry about my English.
      Thank you!

      L 1 Reply Last reply Reply Quote 0
      • L
        luan.provesi @luan.provesi
        last edited by

        Any suggestion? T

        hank you!

        dotdashD 1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash @luan.provesi
          last edited by dotdash

          @luan-provesi
          This can be done. Look up ipsec vti on the docs site. It is however more complicated and there are some issues that come up. I've had mtu issues and problems with tunnels not re-establishing after a long ISP outage. A search of the forum should yield more information.

          Edit to add a link to Jim P's excellent video on the subject
          https://www.youtube.com/watch?v=AKMZ9rNQx7Y

          L 1 Reply Last reply Reply Quote 0
          • L
            luan.provesi @dotdash
            last edited by luan.provesi

            @dotdash Thank You!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.