HA with Fallback Internet connection

Started by Mombro, July 04, 2024, 08:26:03 PM

Previous topic - Next topic
July 04, 2024, 08:26:03 PM Last Edit: July 05, 2024, 01:59:14 AM by Mombro
Hi everyone,

this topic has become a bit too much for me and I have found the limits of my understanding here.

The short version is that I have two OPNsense firewalls with CARP, which I "accidentally" found out is working properly ;-) I also have two internet routers, one with fiber internet, one with LTE/4G as backup internet.

The backup internet connection worked properly until I configured the HA system. Now, I cannot ping the backup LTE router from my internal network or from the OPNsense. This draws the conclusion that something is wrong with the NATing, seeing also that I had to perform changes there during the HA setup and that there needs to be NAT happening because the LTE router is in a different network.

For easier understanding, I tried to visualize this - see the attached screenshot.

I thought that maybe I just needed to add the LTE WAN in outbound NAT like the Fiber WAN, but that did not help - screenshot attached.

Now I'm lost where to look or what to do ... I'm unconscious of changes that would be necessary in regards to firewall rules, so although I have not attached a screenshot, you can expect that I haven't changed anything there.

I used this guide to setup my high availability system: https://www.thomas-krenn.com/en/wiki/OPNsense_HA_Cluster_configuration

I really hope someone out there can help me. During my miserable attempts, I killed the main firewall's config (thereby finding out that the aväilability part works).

Thanks a lot in advance. Your help is highly appreciated!