<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Failover from WAN traffic (WAN1) to IPsec VPN (WAN2)]]></title><description><![CDATA[<p dir="auto">Hi all,<br />
Find attached my architecture for multi-WAN remote site using pfsense, the details are found below<br />
1. WAN1 uses normal routing from the remote site to the Data center via a WAN Service Provider.<br />
2. WAN2 use an internet modem to connect to the Data center using IPSec VPN.<br />
3.When WAN1 is in standalone mode (thus WAN2 shutdown), connectivity is seamless and works OK.<br />
4. When WAN2 is in standalone mode (thus WAN1 shutdown), IPsec works perfectively to the Data center with no issues.<br />
5. From the Gateway group WAN1 is the primary and WAN2 is the secondary (Failover mode)<br />
6. The issues is if I bring up both WAN1 and WAN2, instead of WAN2 waiting for WAN1 to fail before bringing up the IPSec VPN the VPN comes up automatically.<br />
7. When this happens, connectivity to the  data center becomes impossible.<br />
Question: How do I make WAN2 to be on standby till WAN1 fails to bring up the VPN</p>
<p dir="auto">Thanks guys looking forward to your response, but have a look at the diagram.<br />
![remote site arch.jpg](/public/<em>imported_attachments</em>/1/remote site arch.jpg)<br />
![remote site arch.jpg_thumb](/public/<em>imported_attachments</em>/1/remote site arch.jpg_thumb)</p>
]]></description><link>https://forum.netgate.com/topic/54904/failover-from-wan-traffic-wan1-to-ipsec-vpn-wan2</link><generator>RSS for Node</generator><lastBuildDate>Sat, 08 Aug 2026 22:56:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/54904.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 05 Apr 2013 11:47:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Failover from WAN traffic (WAN1) to IPsec VPN (WAN2) on Mon, 08 Apr 2013 16:43:39 GMT]]></title><description><![CDATA[<p dir="auto">Darnitol, you are the man!!! Works like magic, thanks a million.</p>
]]></description><link>https://forum.netgate.com/post/388589</link><guid isPermaLink="true">https://forum.netgate.com/post/388589</guid><dc:creator><![CDATA[oddy]]></dc:creator><pubDate>Mon, 08 Apr 2013 16:43:39 GMT</pubDate></item><item><title><![CDATA[Reply to Failover from WAN traffic (WAN1) to IPsec VPN (WAN2) on Mon, 08 Apr 2013 13:15:36 GMT]]></title><description><![CDATA[<p dir="auto">Thanks darnitol, will try it and get back to you. Many thanks for your input I appreciate it.</p>
]]></description><link>https://forum.netgate.com/post/388548</link><guid isPermaLink="true">https://forum.netgate.com/post/388548</guid><dc:creator><![CDATA[oddy]]></dc:creator><pubDate>Mon, 08 Apr 2013 13:15:36 GMT</pubDate></item><item><title><![CDATA[Reply to Failover from WAN traffic (WAN1) to IPsec VPN (WAN2) on Sat, 06 Apr 2013 01:53:07 GMT]]></title><description><![CDATA[<p dir="auto">Can you use OpenVPN instead of IPSec?</p>
<p dir="auto">The scenario:</p>
<p dir="auto">You have two locations with Internet connections and a dedicated point-to-point connection between the two and two pfSense systems performing all routing at both sites.  You desire the two sites remain connected should the dedicated connection fail.</p>
<p dir="auto">The solution:</p>
<p dir="auto">Create a pfSense configuration with failover from the point-to-point connection to a site-to-site VPN utilizing the existing Internet connections at each site.</p>
<p dir="auto">Steps:</p>
<p dir="auto">1.  Create an OpenVPN Server on the main pfSense and Client setup on the remote pfSense (I used pre-shared keys).  DO NOT set a route option in the Advanced box as most instructions for configuring OpenVPN will suggest nor should you have a static route to your remote network defined under System -&gt; Routes.  Also note that  IPSec can not be used in this scenario as it doesn't create a new adapter that we can work with in the firewall rules and gateways.</p>
<p dir="auto">2.  Check and see that the VPN turns on and connects via Status -&gt; OpenVPN before proceeding.  If it does not then troubleshoot your Internet connectivity and OpenVPN settings.</p>
<p dir="auto">2.  Go to Interfaces -&gt; Assign and add Interface OPT3 with Network port ovpns1 on both the server and the client pfSense systems.</p>
<p dir="auto">3.  On both your local and remote pfSense add a new Firewall Rule allowing all protocols from any source to to any destination under both OPT3 and OpenVPN.</p>
<p dir="auto">4.  On both your local and remote pfSense add OPT3 as a Gateway under System -&gt; Routing -&gt; Gateways leaving the Gateway and other options blank.</p>
<p dir="auto">5.  On both your local and remote pfSense create a new Group under System -&gt; Routing -&gt; Groups.  The group will define your dedicated connection as Tier 1 and OPT3 as Tier 2.  My trigger level is set to Member Down.</p>
<p dir="auto">6.  On both your local and remote pfSense create a new Firewall Rule under LAN which has all traffic from all sources bound for the remote network use the new Gateway Group (under Advanced) you created in Step 5.</p>
<p dir="auto">7.  Test - unplug the point-to-point connection, monitor things under Status -&gt; Gateways, wait a minute or so, and hopefully you will still be passing traffic albeit through the VPN.</p>
]]></description><link>https://forum.netgate.com/post/388250</link><guid isPermaLink="true">https://forum.netgate.com/post/388250</guid><dc:creator><![CDATA[darnitol]]></dc:creator><pubDate>Sat, 06 Apr 2013 01:53:07 GMT</pubDate></item></channel></rss>