Netgate SG-1000 microFirewall

Author Topic: Re-establish site-to-site IPsec on failover (CARP)  (Read 147 times)

0 Members and 1 Guest are viewing this topic.

Offline a-h

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
Re-establish site-to-site IPsec on failover (CARP)
« on: December 08, 2017, 04:26:46 am »
Hello all,

I'd appreciate any help or suggestions that people may have.

Firstly, my setup includes 2 PfSense boxes (2.4.1) with both CARP and IPsec setup and working correctly.  Connections are initiated from the remote end (router) to the CARP address and re-establish themselves within ~1 second upon disconnecting the tunnel from my end.

The problem I'm having is during testing of a firewall failover, if I enter persistent maintenance mode (or simply change advskew), everything fails over to the backup as expected but the IPsec tunnel remains on the primary (now backup) firewall. In the ipsec.log file, I can see the following when this happens as well;

"old path is not available anymore, try to find another"
"looking for a route to 123.123.123.123"

If I disconnect the IPsec session via the browser or CLI on the former primary firewall, it is re-established again on the same firewall (instead of the backup that now has the CARP address) which I can also see in ipsec.log.

Has anybody else had experience with this and have any suggestions on how to prevent this from happening?

Thanks
« Last Edit: December 08, 2017, 04:36:37 am by a-h »