I have a multihomed office, a remote office and a bunch of remote workers. Between the main office and remote office I have 2 IPsec VTI tunnels and using BGP for failover routing. Works as expected. For the remote user I use another ipsec instance (connection) on the main link and EAP authentication. What happens is that one user a time works normally. As soon as a 2nd user logs in, the outgoing / return packets don´t go thru the tunnel. They show up unencrypted on the WAN interface. The connection pool is a /24 network. Running OpnSense 26.1.11_10.
Any clues ?
Without knowing more it kinda sounds like this we recently found.
It happens on mixed vti and policy based setups and is hard to replicate
https://github.com/opnsense/src/commit/e666a996d5325b10cafe21b67a97c4538deae139
the github link mentions Opnsense 26.7 stable. I´m on 26.1 ...
perhaps upgrading to the latest version ?