<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN with HA&#x2F;CARP not connecting on VIP]]></title><description><![CDATA[<p dir="auto">Hello.  I have successfully got HA with CARP working.  I tested by pulling the plug on the main firewall and sure enough the connection to the Internet on a client computer was maintained through the second firewall.  When I enter "what is my IP address" into Google I get the VIP external address.</p>
<p dir="auto">I have also been able to get Open VPN to work when using the non VIP address for the server's interface.  However as soon as I switch the interface to the VIP one, the OpenVPN client hangs right<br />
after the UDPv4 link remote: [AF-INET] {external CARP VIP  address}.</p>
<p dir="auto">I'm trying to follow what's mentioned here:<br />
<a href="https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-vpn-secondary.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-vpn-secondary.html</a></p>
<p dir="auto">To create the HA/CARP setup I followed this tutorial:</p>
<p dir="auto"><a href="https://www.youtube.com/watch?v=-1Og5ogkyZYl" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.youtube.com/watch?v=-1Og5ogkyZY</a></p>
<p dir="auto">Any ideas as to what might be wrong?  I'm new to pfSense.</p>
<p dir="auto">Cheers,<br />
Kajetan.</p>
]]></description><link>https://forum.netgate.com/topic/182996/openvpn-with-ha-carp-not-connecting-on-vip</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 16:10:15 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/182996.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 22 Sep 2023 17:31:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN with HA&#x2F;CARP not connecting on VIP on Tue, 26 Sep 2023 14:17:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> Thank you, that did the trick.  In the rule I changed:</p>
<p dir="auto">Destination<br />
Destination: WAN address</p>
<p dir="auto">to</p>
<p dir="auto">Destination<br />
Destination: Single  host or alias 99.XXX.XXX.XXX</p>
]]></description><link>https://forum.netgate.com/post/1127297</link><guid isPermaLink="true">https://forum.netgate.com/post/1127297</guid><dc:creator><![CDATA[Kajetan321]]></dc:creator><pubDate>Tue, 26 Sep 2023 14:17:13 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN with HA&#x2F;CARP not connecting on VIP on Sun, 24 Sep 2023 14:41:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kajetan321">@<bdi>Kajetan321</bdi></a> said in <a href="/post/1126891">OpenVPN with HA/CARP not connecting on VIP</a>:</p>
<blockquote>
<p dir="auto">s the rule created by the OpenVPN wizard not enough?</p>
</blockquote>
<p dir="auto">No, "WAN address" doesn't seem to be the VIP. So you will have to edit the rule and change the destination to the desired VIP.</p>
]]></description><link>https://forum.netgate.com/post/1127007</link><guid isPermaLink="true">https://forum.netgate.com/post/1127007</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Sun, 24 Sep 2023 14:41:34 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN with HA&#x2F;CARP not connecting on VIP on Fri, 22 Sep 2023 20:36:02 GMT]]></title><description><![CDATA[<p dir="auto">When looking at System Logs &gt; Firewall it seems OpenVPN packets are being blocked.  I don't know how to change that.  Is the rule created by the OpenVPN wizard not enough?</p>
<p dir="auto"><img src="/assets/uploads/files/1695414922599-d55be343-b84e-425a-a219-ba459f3281c2-image.png" alt="d55be343-b84e-425a-a219-ba459f3281c2-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1695414459588-2d8810e3-9463-45b4-8fa3-8d968824ae30-image.png" alt="2d8810e3-9463-45b4-8fa3-8d968824ae30-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1126891</link><guid isPermaLink="true">https://forum.netgate.com/post/1126891</guid><dc:creator><![CDATA[Kajetan321]]></dc:creator><pubDate>Fri, 22 Sep 2023 20:36:02 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN with HA&#x2F;CARP not connecting on VIP on Fri, 22 Sep 2023 17:56:49 GMT]]></title><description><![CDATA[<p dir="auto">I tried following this guide:</p>
<p dir="auto"><a href="https://vorkbaard.nl/openvpn-in-a-pfsense-carp-cluster/" target="_blank" rel="noopener noreferrer nofollow ugc">https://vorkbaard.nl/openvpn-in-a-pfsense-carp-cluster/</a></p>
<p dir="auto">and entered the "local {External CARP VIP}" into the custom options field.  As far as I can tell, nothing changed.</p>
]]></description><link>https://forum.netgate.com/post/1126877</link><guid isPermaLink="true">https://forum.netgate.com/post/1126877</guid><dc:creator><![CDATA[Kajetan321]]></dc:creator><pubDate>Fri, 22 Sep 2023 17:56:49 GMT</pubDate></item></channel></rss>