• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC over CARP addresses using Gateway Group as Interface

Scheduled Pinned Locked Moved HA/CARP/VIPs
4 Posts 2 Posters 262 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    DiegoEspinozaP
    last edited by Oct 11, 2024, 2:42 PM

    Dear Community,

    I've been trying to setup the following environment:

    4 pfSense systems in two sites with:

    pfS1D1 + pfS1D2: Dual WAN, CARP
    pfS2D1 + pfS2D2: Single WAN, CARP (Next months i will be having dual WAN)

    I've seen that you can configure Gateway Groups with Failover (Primary + Backup) in order to have HA at ISP level, and I also know how to configure HA over CARP, i have my master and backup nodes properly setup.

    What i've trying to configure is IPSEC as a first time Dual WAN service, and not knowing if i can use CARP addresses.

    Has somebody done this before?
    Using CARP addresses for Gateway Groups (Failover) over IPSEC?
    I need to propagate the same Local Networks over Primary and Secondary WAN IP Service

    Any ideas or suggestions are greatly appreciated
    Warm Regards

    D 1 Reply Last reply Oct 11, 2024, 2:47 PM Reply Quote 0
    • D
      DiegoEspinozaP @DiegoEspinozaP
      last edited by Oct 11, 2024, 2:47 PM

      Edit,

      I just found that in Gateway Groups you can select the CARP Addresses per Gateway.

      M 1 Reply Last reply Oct 11, 2024, 2:56 PM Reply Quote 0
      • M
        mcury @DiegoEspinozaP
        last edited by Oct 11, 2024, 2:56 PM

        @DiegoEspinozaP said in IPSEC over CARP addresses using Gateway Group as Interface:

        Edit,

        I just found that in Gateway Groups you can select the CARP Addresses per Gateway.

        I have a similar setup in a customer..
        I created two gateway groups.

        One using the interface address, to use in my firewall rules.
        And the other, using the VIP addresses, to use in IPsec.

        Found it to be more reliable during failover and IPsec works in both nodes.

        dead on arrival, nowhere to be found.

        D 1 Reply Last reply Oct 11, 2024, 3:00 PM Reply Quote 0
        • D
          DiegoEspinozaP @mcury
          last edited by Oct 11, 2024, 3:00 PM

          @mcury
          Thanks a lot, i am working with Gateway Groups and VIP addresses to check that everything is working as intented

          Warm Regards

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received