> To also catch the case if the primary is the backup to the following:
> Say you want to access the backup using management VLAN IP, on the primary add both management IPs to an alias. I call it FW1_FW2.
>
> Then add an outbound NAT rule to the management VLAN interface, use FW1_FW2 for the destination, translation = interface address (default), save.
This is helpful for me too, but:
Restrict the source address to "Wireguard (Group) net".
Without that restriction I had the issue that a zabbix proxy was no longer reachable on the secondary opnsense. The zabbix proxy rejected connections from the zabbix server because they appeared to come from the primary opnsense.
> Say you want to access the backup using management VLAN IP, on the primary add both management IPs to an alias. I call it FW1_FW2.
>
> Then add an outbound NAT rule to the management VLAN interface, use FW1_FW2 for the destination, translation = interface address (default), save.
This is helpful for me too, but:
Restrict the source address to "Wireguard (Group) net".
Without that restriction I had the issue that a zabbix proxy was no longer reachable on the secondary opnsense. The zabbix proxy rejected connections from the zabbix server because they appeared to come from the primary opnsense.
"