Feature Request: Automatic Failover for Overlapping CIDRs (High Availability) #2383
3azmeo
started this conversation in
Feature Requests
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
I am requesting the implementation of automatic routing failover when multiple sites (Newt agents) advertise the same Private Resource (CIDR or Host). Currently, if the active site goes down, traffic does not switch to the available backup sites.
Motivation
I am migrating from Twingate to Pangolin for a self-hosted Zero Trust setup and need redundancy (High Availability).
Currently, the documentation states that Pangolin "arbitrarily chooses a single site" when resolving overlapping networks. In my testing, if I have two gateways (Site A and Site B) advertising the same subnet (e.g., 10.0.0.0/24), the client binds to one. If that specific gateway goes offline (container stop or network failure), the connection times out and does not switch to the healthy gateway.
This creates a single point of failure, making it impossible to run a resilient network compared to other solutions like Twingate Connectors or Tailscale Subnet Routers.
Proposed Solution
The client (or controller) should be "health-aware" regarding overlapping routes:
Alternatives Considered
Additional Context
I verified this behavior by deploying Newt on two separate physical hosts advertising the same CIDR.
Beta Was this translation helpful? Give feedback.
All reactions