Project

General

Profile

Actions

Feature #16061

closed

Automatic Site-to-Site VPN

Added by Andrew Collings about 2 months ago. Updated about 2 months ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
VPN (Multiple Types)
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default

Description

Would it be feasible to implement a solution similar to Ubiquiti's Site Magic? We have 12 locations with Netgate appliances that have 2 WAN connections per as well as HA firewalls in 2 locations. Manually building site to site VPNs has been challenging and exacerbated by bugs in Wireguard and the interaction of Wireguard and FRR. It seems like Ubiquiti is just using Wireguard and FRR (OSPF) with their own orchestration software to make it work so it should be doable in theory (though I'm not implying it'd be easy). I could even settle for a proper Tailscale implementation that allows me to disable NAT. I have a strong preference toward open source software and I want to stick with pfSense but we're actively evaluating switching to UniFi because I'm the only one who understands all the idiosyncrasies of our VPN setup which is a business continuity problem.

Actions

Also available in: Atom PDF