Project

General

Profile

Actions

Bug #16611

open

WireGuard MultiWAN Not Failing Back to Tier 1

Added by steven warner about 1 month ago. Updated 1 day ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Gateways
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default
Affected Plus Version:
25.11
Affected Architecture:
amd64

Description

When using a GW group for WAN failover, WireGuard will fail to Tier2 when the Tier1 GW is down. However, when Tier1 is restore, WireGuard does not revert back to Tier1.

re-opening issue 11630. This issue still occurs in 25.11.

Actions #1

Updated by Kris Phillips about 1 month ago

Hello Steven,

Do you have state killing on lower priority gateways selected under System --> Advanced --> Misc?

Actions #2

Updated by steven warner about 1 month ago

Hi Kris - Yes that setting is set as you asked. The Wireguard tunnel stays firmly gripped on the lower tier gateway when the higher priority tier restores, while other traffic correctly migrates.

Actions #3

Updated by Chris Palmer 28 days ago

I also see this behavior at my location here.

Actions #4

Updated by steven warner 17 days ago

I can add linbks to other reports from reddit etc... I believe this really happens. Big problem when your backup WAN is on a metered link...

Actions #5

Updated by Azamat Khakimyanov 1 day ago

Tested on 25.11.1-RELEASE

I was able to reproduce this issue and as a workaround I added Floating Firewall rule:

Interfaces: Any
Direction: Out
Protocol: UDP
Destination: <WireGuard Server IP>
Destination Port: <WireGuard Port> (for example, 51820)
Gateway: <Failover Gateway group>

and in System->Advanced-> Miscellaneous I chose 'State Killing on Gateway Recovery: Kill all states for lower-priority gateways'.

After I added these settings, whenever WAN1 went down, WireGuard started using WAN2. When WAN1 came back up, WireGuard successfully switched back to WAN1.

Actions

Also available in: Atom PDF