← EuroFirewalls

Guides · VPN & Multi-WAN

Business VPN and Multi-WAN with pfSense: remote access, sites and failover

Two needs drive most business networks: encrypted connectivity for remote users and branch offices, and an Internet connection that does not die with a single line. pfSense Plus on Netgate covers both natively — VPN tunnels and Multi-WAN with failover — and FRAOS designs, pre-configures and supports them.

Request a VPN and Multi-WAN assessmentBrowse Netgate appliances

What VPN and Multi-WAN give you

WireGuard, IPsec or OpenVPN?

All three are included in pfSense Plus. The choice depends on the scenario, not on fashion:

ProtocolBest forCharacterWatch out for
WireGuardModern site-to-site and remote accessLean, quick to set up, modern cryptographyNarrower interoperability with third-party firewalls
IPsecSite-to-site between different vendorsIndustry standard, mature and interoperableMore parameters to get right; NAT traversal needs care
OpenVPNRemote access with many clientsFlexible, mature clients on every platformHigher per-connection overhead than the other two

Typical scenarios

How Multi-WAN failover works — and what it does not do

pfSense Plus monitors every gateway and moves traffic to a healthy line when the primary fails; policy routing decides which traffic follows which gateway.

Failover is not instantaneous: the gateway monitor needs seconds to declare a line down, and long-lived connections (VoIP calls, large transfers) may have to be re-established. Plan maintenance windows for critical services, and combine Multi-WAN with a redundant firewall pair when the firewall itself must not be a single point of failure.

Which appliance?

VPN encryption and gateway handling are CPU work: the more simultaneous users and lines, the larger the appliance. Our sizing guide maps bandwidth, VPN users and services to each model, and the homepage selector gives a starting point in a few clicks.

We design VPN and Multi-WAN with you

Tell us the sites, remote users, available lines and which traffic must survive a failover: we propose the architecture, pre-configure the appliance and support you after go-live.

Frequently asked questions

WireGuard or IPsec to connect two offices?

If both endpoints run pfSense Plus or support WireGuard, it is the simplest to operate. When the other side is a third-party firewall or a vendor standard is required, IPsec remains the interoperable choice.

Is failover immediate?

No. The gateway monitor needs a few seconds to declare a line down, and established connections may be re-established over the new line. For zero-interruption requirements, combine Multi-WAN with a redundant firewall pair.

Can I use two different providers?

Yes — that is the point: fibre plus 4G/5G, or two separate fibre providers. Policy routing can also split traffic deliberately, for example nightly backups on the secondary line.

Do I need a licence for VPN or Multi-WAN?

No. VPN protocols and Multi-WAN are features of pfSense Plus included with the Netgate appliance; no additional licence is required.

Sources

Last verified: 2026-08-29. Orientation guide: actual behaviour depends on configuration, providers and traffic. Have FRAOS review the design before implementation.