Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - brunorafa

#1
**Title:** OPNsense HA + BGP with our own ASN and /24 — what architecture is recommended?

Hi everyone,

I would like to get some advice on the recommended architecture for using **BGP with OPNsense HA**, with two physical firewalls, our own IPv4 /24 prefix, and **IPsec VPNs that need to work redundantly across both firewalls**.

Our environment has:

- 2 physical OPNsense firewalls;
- HA configured with **CARP + pfsync + configuration synchronization**;
- A **Master/Slave** architecture, where the Master handles normal operations and the Slave takes over in case of failure;
- **Both firewalls need to be able to take over and operate the IPsec VPNs** during a failover;
- Our **own ASN**;
- Our own **IPv4 /24 prefix**, which will be advertised to our ISP;
- Both firewalls have independent physical connections to the same ISP.

So, we have two independent physical links:

```text
ISP 10.52.70.1  <---->  OPNsense 01 10.52.70.2

ISP 10.52.70.5  <---->  OPNsense 02 10.52.70.6
```

For BGP, we have flexibility with our ISP and can use **either a single BGP session or two independent BGP sessions**, one for each firewall.

### Option 1 — Two BGP sessions

```text
                         ISP
                    /           \
                 BGP               BGP
                  |                 |
           10.52.70.1           10.52.70.5
                  |                 |
           10.52.70.2           10.52.70.6
          OPNsense 01           OPNsense 02
              MASTER              SLAVE
                  \               /
                   ---- HA/CARP ---
```

This is the setup we are currently using.

Each physical firewall has its own BGP session with the ISP, using our ASN and advertising the same /24 prefix.

The HA failover itself works: when we put the Master firewall into **maintenance mode**, traffic successfully moves to the Slave firewall.

However, we are seeing a behavior that makes us question the BGP architecture: **even after traffic has moved to the Slave, some flows appear to return through the Master firewall**, resulting in asymmetric routing.

At the same time, we need the Slave to take over not only the normal traffic handled by the Master, but also the **IPsec VPNs**, keeping connectivity during the failover.

This is what led us to question whether using **two independent BGP sessions**, one on each firewall, is actually the recommended approach for an OPNsense HA pair, or whether we should use a single BGP session associated with the active/Master firewall.

### Option 2 — Single BGP session

The other possibility would be to use a single BGP session associated with the Master firewall, with the Slave taking over the BGP session during a failover.

Our main question is **which of these two approaches is considered the more appropriate/recommended architecture for OPNsense in a HA setup with two physical firewalls, our own ASN, our own /24 prefix advertised via BGP, and IPsec VPNs that need to operate redundantly**.

We would especially like to understand how the OPNsense/FRR project recommends structuring this type of setup.

Thank you!