Ph0enix 0 Posted ... I configured a few instances on my OpnSense router that connect to AirVPN. Afterwards I configured them as gateways. As part of the process one is advised to specify a monitor IP that the system pings to determine if the corresponding gateway is up and what the latency is. For the first one I use the IPs of AirVPN DNS server. Are there any other IP addresses that could be used as monitor IPs? Currently I picked some random IP addresses from the corresponding countries. I suppose that's not the best solution, it's not nice for IP owners to be constantly pinged and then there is no guarantee that the IPs stay up or not gonna block me. I'd like to avoid using something like 8.8.8.8 or 1.1.1.1, etc as I need these DNS servers to be routable from other subnets without locking them to just one. But if there are some other IPs on the Internet are there to be used as monitor IPs please share what they are. Quote Share this post Link to post
Staff 10384 Posted ... 3 hours ago, Ph0enix said: Afterwards I configured them as gateways. As part of the process one is advised to specify a monitor IP that the system pings to determine if the corresponding gateway is up and what the latency is. For the first one I use the IPs of AirVPN DNS server. Hello! With WireGuard it's a very good choice as the DNS server IP address (10.128.0.1) is also the VPN gateway address, on every and each server since the WireGuard network is one. With OpenVPN, you have different subnet on every server though and you can't rely on a fixed address. 10.4.0.1 is available on every server for DNS queries but does not respond to ping. You could consider to extract the gateway from the tun interface settings at each connection and ping that gateway. Kind regards Quote Share this post Link to post
go558a83nk 380 Posted ... Are you sure you don't have an option somewhere in the gateway settings to prevent opnsense making static routes for monitor IP? I have that in pfsense. I usually trace the route through the VPN interface to anything (e.g. 9.9.9.9) and then use the first or second hop as the monitor address for that gateway. In past experience I've had times where gateway monitoring said everything was fine but reaching the internet wasn't happening. That's why I've taken to pinging something on the other side of the VPN gateway. Quote Share this post Link to post