Flint 2 4.9 VPN Failover doesn't work

Hi, please help. When Priority 1 VPN (WG PIA) goes down, Priority 2 VPN (OVPN) doesn’t back-up. Connection lost, doesn’t even use default WAN (no vpn) connection.
Kill Switch is disabled and Allow Non-VPN Traffic is enabled.

Hi,

In firmware 4.9, VPN failover works between multiple profiles selected within the same VPN tunnel. The profiles are attempted in the order shown in the selected profile list, from top to bottom.

Different VPN tunnels operate independently. The priority configured between tunnels determines the order in which traffic rules are matched.
Therefore, a WireGuard tunnel cannot currently fail over automatically to a separate OpenVPN tunnel through the web interface.

However, if the WireGuard tunnel is disconnected while its Kill Switch is disabled and Allow Non-VPN Traffic is enabled, the traffic should fall back to the local WAN connection.
Could you please provide screenshots of the VPN Dashboard, the WireGuard tunnel options, and the All Other Traffic settings when the issue occurs?

Thank you for your understanding and cooperation.

Hi, Ok I understand. So I should create another PIA WG server aside from current, since it'll only back-up on same segment. Also will there be update to back-up VPN on other segments? Since I use 2 different VPN provider, I experience before that Express shut my account due to suspected hacker used my account, so VPN stops and there's no option on backing it up on same provider since it's an account halt. I was able to use the VPN again after changing my email like the support told me so. In this case, backing-up to another segment means a lot. Attached files are included as per your request. Thanks very much

Hi,

Thank you for providing the screenshots and for explaining your use case in detail.

Yes, you may add another PIA WireGuard profile to the same PIA WireGuard tunnel. If the active profile fails, the router will try the selected profiles in the order shown in the profile list.

At present, automatic failover between separate tunnels, we have recorded your request for cross-tunnel, cross-protocol, and cross-provider VPN failover for further evaluation.

Based on the screenshots, the Kill Switch is disabled and Allow Non-VPN Traffic is enabled. With these settings, traffic should be allowed to fall back to the regular WAN connection if all selected profiles in the PIA WireGuard tunnel become unavailable.

If the issue where traffic does not fall back to WAN occurs again, could you please export the system log while the issue is still present and send it to us via private message, so we can further check the VPN failover and routing behavior?


Thank you for your understanding and cooperation.

It doesn’t failover on WAN, even the Kill Switch is disabled and Allow Non-VPN Traffic is enabled :frowning: Ok, I’ll send personal message to you. Thanks

Does anyone if it’s possible to get failover between tunnels like in previous 4.8.x firmware?

On Tunnel 1 i have 2 Wireguard vpns and on Tunnel 2 i have 2 OpenVPN vpns, i want when wireguard not working to failover to the OpenVPN tunnels.

Hi,

In firmware 4.9, the failover behavior has changed. Failover is currently supported between multiple profiles within the same tunnel, but separate tunnel groups operate independently and do not fail over from one VPN tunnel to another.

Therefore, a WireGuard-to-OpenVPN failover between Tunnel 1 and Tunnel 2 cannot currently be configured through the v4.9 VPN Dashboard. If the WireGuard tunnel fails and its Kill Switch is disabled, traffic can fall back to the All Other Traffic settings, such as the local WAN, but it will not automatically use the OpenVPN tunnel.

Thank you for your understanding.

Thank you for the information.

But what i would like to know if there is any plan to have that functionality work again on 4.9.x firmware?

Is quite bad that traffic can’t failover from Wireguard to OpenVPN tunnel.

1 Like