<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CARP Backup can&#x27;t access remote resource over site-to-site OpenVPN]]></title><description><![CDATA[<p dir="auto">We have two sites each using a pair of pfSense firewalls configured for HA. They are connected via a site-to-site OpenVPN setup. I'm aware of the issue and solution described at <a href="https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-vpn-secondary.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-vpn-secondary.html</a>, and the solution has been implemented on both ends. Our issue is the reverse; the backup firewall is not able to access a resource on the remote network (presumably for the same reason described in the page above), and I'm having a hard time figuring out a good way to overcome it.</p>
<p dir="auto">So far I've only thought of adding a NAT rule that listens on a CARP VIP on the LAN interface. In experimenting with this, I found that the backup firewall was able to access the resource through the NAT rule, but the master firewall was not able to access the resource this way. This was the case for all three kinds of NAT reflection types. I feel like the solution is another Outbound NAT rule or a static route, but I'm not sure what rule I could make that wouldn't mess up the routing for whatever firewall has the CARP master role...</p>
<p dir="auto">The master one is able to access the resource directly, so I <em>could</em> setup separate configs for each, but this is part of a config in pfBlockerNG, so I would really like to use a config that works for both firewalls so I don't have to manually copy configs between the two.</p>
]]></description><link>https://forum.netgate.com/topic/175388/carp-backup-can-t-access-remote-resource-over-site-to-site-openvpn</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 03:35:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/175388.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 20 Oct 2022 05:15:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CARP Backup can&#x27;t access remote resource over site-to-site OpenVPN on Fri, 21 Oct 2022 20:33:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> Or put the pfblocker file on an inside network that both nodes have ready access to. Sync it to a reachable server or something.</p>
]]></description><link>https://forum.netgate.com/post/1067281</link><guid isPermaLink="true">https://forum.netgate.com/post/1067281</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Fri, 21 Oct 2022 20:33:14 GMT</pubDate></item><item><title><![CDATA[Reply to CARP Backup can&#x27;t access remote resource over site-to-site OpenVPN on Thu, 20 Oct 2022 21:11:16 GMT]]></title><description><![CDATA[<p dir="auto">@caleb-hornbeck<br />
To route that over the VPN is not be trivial, I guess. It might be easier to route it over the WAN and access the server by a public IP.</p>
]]></description><link>https://forum.netgate.com/post/1067149</link><guid isPermaLink="true">https://forum.netgate.com/post/1067149</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 20 Oct 2022 21:11:16 GMT</pubDate></item><item><title><![CDATA[Reply to CARP Backup can&#x27;t access remote resource over site-to-site OpenVPN on Thu, 20 Oct 2022 20:36:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a><br />
The pfBlockerNG package pulls a list of IPs that's generated by a server in the remote site.</p>
]]></description><link>https://forum.netgate.com/post/1067142</link><guid isPermaLink="true">https://forum.netgate.com/post/1067142</guid><dc:creator><![CDATA[caleb.hornbeck]]></dc:creator><pubDate>Thu, 20 Oct 2022 20:36:20 GMT</pubDate></item><item><title><![CDATA[Reply to CARP Backup can&#x27;t access remote resource over site-to-site OpenVPN on Thu, 20 Oct 2022 18:35:23 GMT]]></title><description><![CDATA[<p dir="auto">@caleb-hornbeck<br />
Why does the backup need to access anything on the remote site?</p>
]]></description><link>https://forum.netgate.com/post/1067132</link><guid isPermaLink="true">https://forum.netgate.com/post/1067132</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 20 Oct 2022 18:35:23 GMT</pubDate></item></channel></rss>