I have working setup of opnsense in HA CARP mode. All works well with exception of gif based tunnel. Tunnel's local address is set to WAN CARP VIP (but not "depends on carp" like it's possible in WG).
And once failover takes place, tunnel is not reinstated in new master node. I can see there is active state with old master's wan ip address; but killing those states, gif interface down/up don't help. And after failback, main master node is able to re-use (not reinstate as never been lost there) tunnel.
Is there any way to configure failover correctly in /usr/local/etc/rc.syshook.d/carp/ script?
And once failover takes place, tunnel is not reinstated in new master node. I can see there is active state with old master's wan ip address; but killing those states, gif interface down/up don't help. And after failback, main master node is able to re-use (not reinstate as never been lost there) tunnel.
Is there any way to configure failover correctly in /usr/local/etc/rc.syshook.d/carp/ script?
"