• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can't get to backup Firewall from IPSEC

Scheduled Pinned Locked Moved HA/CARP/VIPs
5 Posts 3 Posters 1.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U
    upthehill
    last edited by Apr 15, 2013, 6:31 PM

    Hi,

    I have an issue that is causing problems. I really don't fully understand the problem but will have a try. I'm very new to PFSense.

    I have two pairs of pfsense firewalls. One pair in NY and one pair in Boston.

    I've attached a diagram.

    If I connect through the NY side, a tunnel is formed and allows me to connect to the LAN on the otherside. What it does not allow ,me to do is connect to the backup firewall.

    If I then clean the SAD, I'm then able to connect.

    What am I doing wrong?

    Thanks
    xyz.png
    xyz.png_thumb

    1 Reply Last reply Reply Quote 0
    • S
      SeventhSon
      last edited by May 6, 2013, 4:11 PM

      I would say the backup firewall is pushing the traffic through the wrong gateway/tunnel? But then clearing the SAD shouldn't make a difference?

      Actually, it might matter… What version of pfSense are you running, because on the new version (2.0.2 and up i think), it actually brings down the tunnel on the backup machine, so this might be what you need.

      1 Reply Last reply Reply Quote 0
      • J
        jimp Rebel Alliance Developer Netgate
        last edited by May 6, 2013, 6:20 PM

        http://forum.pfsense.org/index.php/topic,61775.msg333763.html#msg333763

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by May 6, 2013, 6:27 PM

          http://doc.pfsense.org/index.php/CARP_Secondary_Unreachable_Over_VPN
          (You didn't miss in the FAQ, I just added it)

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • S
            SeventhSon
            last edited by May 7, 2013, 4:09 PM

            Thanks jimp, seems so simple when it's written down so well  ;)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received