IPSEC VTI Redundant Tunnel

Started by matzeeg3, Today at 11:43:38 AM

Previous topic - Next topic
Hey everyone, i am face a little problem and maybe i don“t know if i did something wrong or if i missunderstand something.
so here is what i like to do:
1 like to setup 2 VTI Tunnels to my Fortigate, the Fortigate has two different WANs and on the Fortigate Side everything worked as expected.

Now i am on the side of the opnsense i setup 2 Connections see attached "connctions_1.png" than i have 2 VTIs defined see "vti.png".

In the Gateway Section i setup the Gateways and an gateway group "gw.png" and "gwgroup.png".

At last step i create a policy with the gateway group in it.

so now if one vpn goes down i am not able to get any traffic from the opnsense to the fortigate.
i see traffic from fortigate is coming in but the opnsense try to send all traffic to the "down" gateway