Guides · VPN & Multi-WAN
Business VPN and Multi-WAN with pfSense: remote access, sites and failover
Two needs drive most business networks: encrypted connectivity for remote users and branch offices, and an Internet connection that does not die with a single line. pfSense Plus on Netgate covers both natively — VPN tunnels and Multi-WAN with failover — and FRAOS designs, pre-configures and supports them.
What VPN and Multi-WAN give you
- Encrypted access for remote staff and site-to-site links between offices.
- Controlled exposure: only the services you decide cross the firewall.
- A second line — for example fibre plus 4G/5G — takes over automatically when the primary fails.
- Policy routing: you decide which traffic uses which line.
WireGuard, IPsec or OpenVPN?
All three are included in pfSense Plus. The choice depends on the scenario, not on fashion:
| Protocol | Best for | Character | Watch out for |
|---|---|---|---|
| WireGuard | Modern site-to-site and remote access | Lean, quick to set up, modern cryptography | Narrower interoperability with third-party firewalls |
| IPsec | Site-to-site between different vendors | Industry standard, mature and interoperable | More parameters to get right; NAT traversal needs care |
| OpenVPN | Remote access with many clients | Flexible, mature clients on every platform | Higher per-connection overhead than the other two |
Typical scenarios
- Remote access for staff, with multi-factor authentication on the VPN — also a NIS2 expectation.
- Site-to-site VPN between headquarters and branches, or between offices and cloud.
- Hub-and-spoke topologies with several branches.
- Failover between two providers: primary fibre with a 4G/5G or second-fibre backup.
How Multi-WAN failover works — and what it does not do
pfSense Plus monitors every gateway and moves traffic to a healthy line when the primary fails; policy routing decides which traffic follows which gateway.
Failover is not instantaneous: the gateway monitor needs seconds to declare a line down, and long-lived connections (VoIP calls, large transfers) may have to be re-established. Plan maintenance windows for critical services, and combine Multi-WAN with a redundant firewall pair when the firewall itself must not be a single point of failure.
Which appliance?
VPN encryption and gateway handling are CPU work: the more simultaneous users and lines, the larger the appliance. Our sizing guide maps bandwidth, VPN users and services to each model, and the homepage selector gives a starting point in a few clicks.
We design VPN and Multi-WAN with you
Tell us the sites, remote users, available lines and which traffic must survive a failover: we propose the architecture, pre-configure the appliance and support you after go-live.
Frequently asked questions
WireGuard or IPsec to connect two offices?
If both endpoints run pfSense Plus or support WireGuard, it is the simplest to operate. When the other side is a third-party firewall or a vendor standard is required, IPsec remains the interoperable choice.
Is failover immediate?
No. The gateway monitor needs a few seconds to declare a line down, and established connections may be re-established over the new line. For zero-interruption requirements, combine Multi-WAN with a redundant firewall pair.
Can I use two different providers?
Yes — that is the point: fibre plus 4G/5G, or two separate fibre providers. Policy routing can also split traffic deliberately, for example nightly backups on the secondary line.
Do I need a licence for VPN or Multi-WAN?
No. VPN protocols and Multi-WAN are features of pfSense Plus included with the Netgate appliance; no additional licence is required.