Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple VPNs via Gateway Groups?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 894 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SwedenGirl234
      last edited by

      I'm looking to toggle quickly between different VPN companies.

      Someone told me I could do this through gateway groups? But I'm having trouble actually implementing it. Can you please describe how to do this?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Gateway groups can be setup to switch traffic between them automatically but not to toggle them manually.

        Your username is only going to attract the worst kind of spam to every thread you respond in. Please change it.

        Steve

        S 1 Reply Last reply Reply Quote 0
        • S
          SwedenGirl234 @stephenw10
          last edited by SwedenGirl234

          @stephenw10 When you say automatically, what conditions could trigger a switch in interface or VPN?

          I have changed my username,, thank you

          V stephenw10S 2 Replies Last reply Reply Quote 1
          • V
            viragomann @SwedenGirl234
            last edited by

            @swedengirl234 said in Multiple VPNs via Gateway Groups?:

            When you say automatically, what conditions could trigger a switch in interface or VPN?

            The gateway monitoring. You have to assign an interface to each VPN, hence you get a gateway for it.

            pfSense automatically activates monitoring for the gateways by pinging it (the virtual Server IP). But often the server is not responding and so the gateway is determined as offline. If this is the case edit the gateway settings and set a custom monitoring IP. It could be any public IP which is responding to pings. pfSense automatically routes this IP over the respective VPN.
            Ensure that the gateway status is online for the gateway group to failover properly.

            In the gateway group you can set the failover trigger to gw offline. Then if the tier 1 is offline pfSense will switch to tier 2.

            S 1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator @SwedenGirl234
              last edited by

              @swedengirl234 said in Multiple VPNs via Gateway Groups?:

              I have changed my username

              Thanks. 👍

              1 Reply Last reply Reply Quote 0
              • S
                SwedenGirl234 @viragomann
                last edited by

                @viragomann So you are saying that gateway groups can ONLY be used to switch VPNs in an automatic situation should one VPN IP not respond, and can NOT be used to manually toggle between the different interfaces?

                Because right now I'm toggling interfaces manually for different VPNs and it's a huge hassle

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @SwedenGirl234
                  last edited by

                  @swedengirl234
                  Yes, gateway groups are meant to failover automatically in case one member is offline or has high latency.
                  But there might also be ways to toggle the gateway manually, when using a gateway group for routing. For instance you could disable a member gateway by ticking the respective action button in System > Routing > Gateways.

                  Because right now I'm toggling interfaces manually for different VPNs and it's a huge hassle

                  I'm wondering what's the reason for this. How do you do that?

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SwedenGirl234 @viragomann
                    last edited by

                    @viragomann yes I prefer certain VPNs for work or personal.

                    I do it via having different interfaces so all the firewall rules switch at once. However, it's annoying to switch DNS settings as well

                    I am/was struggling to get it to work via Gateway Groups. Do you know where I can find more on this because the official Netgate documentation only elaborated on setting up the proper gateway, not changing

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.