Wireguard multiple VPN server endpoints - round robin?

Started by ajohn, October 10, 2020, 10:08:05 AM

Previous topic - Next topic
Hi, I've successfully setup my OPNsense firewall as a wireguard client. My VPN provider provides many servers, so I have configured multiple under "endpoints". OPNsense allows me to enable multiple, but it will always send traffic to the first enabled in the list.

Is there any way to periodically switch automatically between VPN servers?

Sorry to resurrect an old post but i'w been trying to figure this out as well, the fact that you can select a bunch of endpoints gives the impression of some kind of faiƶover right? But how would it know when to change?

The only way I can think of to make this work is set up multiple connections, all with their own single endpoint,disable automatic routing and add a gateway to each connection and loadbalance the gateways in a gateway group... But this seems way more advanced for the functionality it provides :-D

EDIT: come to think of it, this would limit the amount of servers you can use to the amount of allowed clients, I guess it's better then nothing though but what is the actually point of enabling more then 1 endpoint anyway? Is there some unexplained functionality?

Quote from: Kieeps on November 28, 2020, 10:51:15 AM
Sorry to resurrect an old post but i'w been trying to figure this out as well, the fact that you can select a bunch of endpoints gives the impression of some kind of faiƶover right? But how would it know when to change?

The only way I can think of to make this work is set up multiple connections, all with their own single endpoint,disable automatic routing and add a gateway to each connection and loadbalance the gateways in a gateway group... But this seems way more advanced for the functionality it provides :-D

EDIT: come to think of it, this would limit the amount of servers you can use to the amount of allowed clients, I guess it's better then nothing though but what is the actually point of enabling more then 1 endpoint anyway? Is there some unexplained functionality?

No, it more or less failover Controlled by WireGuard itself