Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Nify

#1
Quote from: Native2184 on September 25, 2024, 02:51:37 PM
Also posted on this a good while ago but never received a reply to this. Also tried a pool of VPN client connections but everthing would be routed out through the default internet gateway. Tried different tier settings (equal tiers and different tiers) to no avail.

Had given up on this and just set a gateway and no gateway groups for VPN clients. But if there's a solution or workaround for this, I'm happy to hear it.

Yes, I'm having the same experience and I've found similar posts on this going back for over a year at this point. This apparently is not a priority for anyone--which I don't understand, because it seems like such a simple thing and also a really basic piece of functionality that you'd expect to find in a firewall software.
#2
Thanks for your reply.

So with this feature not working, what would be the best way to configure failover/load balancing with several OpenVPN clients? IE, for a certain set of IPs, I'd like to route to a pool of VPN connections with failover and/or load balancing, but I am configuring the VPN connections using gateways with dynamic IPs.

I'm able to route any given IP to a specific VPN connection this way, but currently can find no way of routing to a pool of potential VPN connections that use dynamic gateways.

This seems like a very basic piece of functionality that is now missing.

Thanks again
#3
Hello all,

It seems that for many versions now (going back even to 23.x versions), Opnsense has the peculiar behavior of ignoring rules which attempt to route to gateway groups that use dynamic gateways. This also appears to be affecting the current version.

An issue was opened on Github, but appears to have been abandoned:

https://github.com/opnsense/core/issues/6486

Any plans for this to be fixed, or are there any workarounds?

Thanks.