Could you please confirm which firmware version is currently running on your RUTX50? The issue you’re describing with failover not working properly alongside an active IPsec tunnel was addressed and fixed in the 7.13.2 firmware release.
If you’re already on 7.13.2 or newer, could you let me know whether the original issue still persists or if it behaves differently now?
Actually I had 7.14.2 version, but today I did update to 7.14.3. Unfortunately RUTX50 behavior is exactly the same as I describe at first.
If you are Teltonika enginier you will be welcome to connect remotely to my network if you wish (I spoke polish, russian, english).
Could you please check whether the Flush connections option is enabled on your Failover interfaces, as well as the Flush conntrack option in IPsec advanced settings?
Failover interfaces (/network/failover/mwan) both have “Flush connections on” - all 4 options are on.
My IPSec (/services/vpn/ipsec#id=VLAN3 → Advanced Settings: Flush conntrack) was OFF, but I have changed it to ON.
Unfortunetelly it didnt helped, I did test 2 times with device restart just in case. Do you have any other ideas ?
At this point, it’s still a bit unclear how exactly you’re testing the failover alongside IPsec, particularly why the public WAN IP is being pinged during the test. Could you please provide a full topology of your setup, including the key IP addresses involved?
Also, could you try testing by pinging a device within the IPsec LAN (right side) from a computer connected to the appropriate VLAN on the RUTX50 side? Then, check if the pings continue when the wired WAN connection fails over to the mobile WAN.
I am using 2 VLANS as local LAN networks, only 2nd VLAN is beeing connected via IPSec and fully routed to the tunnel (with 0.0.0.0 mask). 1st VLAN is regural LAN network without vpn, just behing NAT on WAN interface.
Now I imagine. when I unplug optical wire from modem (modem is bridged with LAN cable to WAN interface), it shoud trigger failover mechanism, and change default WAN interface to Mobile1 (which is of course tested and working fine). And it is - Mobile interface status is changed from Standby to Online, but … routing is not working.
I am doing tests (pingi from screens) from 1st VLAN which is not using ipsec and - I am trying to reach public IP of course.
I believe to understand, troubleshoot, and assist you effectively, we’ll need to continue this process privately. You should find a support request form in the inbox of the email address you used for your forum registration. Kindly fill out the form, and please reference Ticket ID: 13772 when submitting it. Once the form is completed, we’ll contact you directly via email to investigate the issue in detail and help work towards a solution.