Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC over CARP addresses using Gateway Group as Interface

    HA/CARP/VIPs
    2
    4
    255
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DiegoEspinozaP
      last edited by

      Dear Community,

      I've been trying to setup the following environment:

      4 pfSense systems in two sites with:

      pfS1D1 + pfS1D2: Dual WAN, CARP
      pfS2D1 + pfS2D2: Single WAN, CARP (Next months i will be having dual WAN)

      I've seen that you can configure Gateway Groups with Failover (Primary + Backup) in order to have HA at ISP level, and I also know how to configure HA over CARP, i have my master and backup nodes properly setup.

      What i've trying to configure is IPSEC as a first time Dual WAN service, and not knowing if i can use CARP addresses.

      Has somebody done this before?
      Using CARP addresses for Gateway Groups (Failover) over IPSEC?
      I need to propagate the same Local Networks over Primary and Secondary WAN IP Service

      Any ideas or suggestions are greatly appreciated
      Warm Regards

      D 1 Reply Last reply Reply Quote 0
      • D
        DiegoEspinozaP @DiegoEspinozaP
        last edited by

        Edit,

        I just found that in Gateway Groups you can select the CARP Addresses per Gateway.

        M 1 Reply Last reply Reply Quote 0
        • M
          mcury @DiegoEspinozaP
          last edited by

          @DiegoEspinozaP said in IPSEC over CARP addresses using Gateway Group as Interface:

          Edit,

          I just found that in Gateway Groups you can select the CARP Addresses per Gateway.

          I have a similar setup in a customer..
          I created two gateway groups.

          One using the interface address, to use in my firewall rules.
          And the other, using the VIP addresses, to use in IPsec.

          Found it to be more reliable during failover and IPsec works in both nodes.

          dead on arrival, nowhere to be found.

          D 1 Reply Last reply Reply Quote 0
          • D
            DiegoEspinozaP @mcury
            last edited by

            @mcury
            Thanks a lot, i am working with Gateway Groups and VIP addresses to check that everything is working as intented

            Warm Regards

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.