Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Failover from local i/f to OpenVPN tunnel (2.0-RC3)

    Scheduled Pinned Locked Moved Routing and Multi WAN
    5 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Groer
      last edited by

      Hi,

      Sorry if this was already covered somewhere, I didn't find it by searching web and forums.

      I've got 2 pfSense 2.0-RC3 VMs connecting 2 networks on different sites:

      nwA: 10.1.10.0/24
      nwB: 10.1.100.0/24

      pfA: LAN (10.1.10.1), WAN1, WAN2, OPT1 (10.1.100.2)
      pfB: LAN (10.1.100.1), WAN

      A fibre link connects nwB directly to pfA-OPT1, so if pfA can ping pfB-LAN (10.1.100.1) on OPT1, traffic between nwA and nwB should go thru OPT1 (this already works, of course).

      But if pfA cannot ping 10.1.100.1 on OPT1 (i.e. the fibre link between sites is down), traffic between nwA and nwB should go thru an OpenVPN site-to-site tunnel between pfA-WAN2 (a backup Internet connection) and pfB-WAN.

      Can this be achieved with pfSense, and if so, how?

      Thanks a lot,

      Frank

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Yes this can be done.
        Create a failover pool under "System" –> "Routing" --> "Groups" and use this failover pool in the allow-firewall on your LAN interface.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • G
          Groer
          last edited by

          Thanks for the quick response!

          Yeah, I tried that, and it works fine for "normal" gateways. But which gateway should I use for OpenVPN in the new gateway group?

          The OpenVPN tunnel uses 10.1.98.0/24 as transfer network, but I cannot create a gateway for 10.1.98.1. No matter which i/f I choose (there are only LAN, WAN1, WAN2, OPT1 to choose from, no OpenVPN), I always get: "The gateway address 10.1.98.1 does not lie within the chosen interface's subnet." That's true, of course.

          Thank you,

          Frank

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            You can assign the OpenVPN interface as another OPTx.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • G
              Groer
              last edited by

              Ah, that's nice!

              I've done it like this now, and the configuration part of it seems to work just fine … I'll try an automatic failover this weekend.

              Thanks a lot!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.