Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site to Site VPN Priority

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bstamper
      last edited by

      I have a situation where I have a site to site VPN from my main site to two remote sites.  The two remote sites just got connectivity to each other (wireless point to point) as they are close together with line of site.  Lucky for me both remote sites still have their own internet connection and have it with different ISP's.    I want to open the scope of the Remote end of the VPN tunnel to include the subnets for both remote sites on both vpn tunnels.  This would allow me to continue to access one site thru the other if one sites ISP were to fail.  Is there a way in PFSense to prioritize which tunnel i want to use? How does it handle the overlap in remote subnet?  I belive in "cisco" the following handles this preference:
      crypto map External_map 1 match address Remotesite1
      crypto map External_map 2 match address Remotesite2

      In the above example if remotesite1 and remotesite2 contained the same subnets or a set of overlapping subnets the connection to External_map 1 would be preferred?  I don't see any "priority" in the PFSense ipsec setup page so I'm not sure how this would work or if its possible?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That won't work with normal routing. It doesn't handle that situation.

        However you might be able to make it work if you run a routing protocol like OSPF on each node.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.