Applicable Products
QVPN Service
Details
If you are using QVPN Service on a QNAP device with High Availability (HA) enabled, consider the following to ensure a stable and functional VPN environment:
VPN server limitations in HA mode
- Unsupported VPN protocols: PPTP and L2TP/IPSec (PSK) are not available as VPN server options in HA mode. Use QBelt, OpenVPN, or WireGuard instead. QBelt, QNAP's proprietary VPN protocol, is recommended for better integration with QNAP systems.
 - Client-side adjustments: Before enabling HA, manually configure all VPN clients to use a supported protocol to prevent connection issues. 
 
Connection requirements for HA
- Use cluster IP (CIP): Always use the cluster IP instead of the node IP (NIP) when connecting to the VPN. The CIP remains consistent regardless of which NAS is active, ensuring uninterrupted access even during an HA failover or switchover.
 - DNS and routing considerations: If your VPN clients rely on a specific DNS configuration, ensure that DNS resolution points to the CIP to prevent connectivity disruptions.
 
Handling OpenVPN client reconnection
If you are using OpenVPN Connect on your device to connect to QVPN Service on the QNAP device, the connection will not automatically restore after an HA failover or switchover. If a failover or switchover occurs, you must manually reconnect to regain VPN access.
OpenVPN connections are stateful, meaning they maintain an active session with the server. However, HA failover or switchover does not transfer session states between nodes, requiring a manual reconnection.
For further assistance with VPN configuration in an HA environment, contact QNAP Customer Service.
                             
                                                            
                                    适用产品
QVPN VPN服务器
详细信息
如果您在启用了高可用性(HA)的QNAP设备上使用QVPN VPN服务器,请考虑以下事项以确保稳定和功能正常的VPN环境:
HA模式下的VPN服务器限制
- 不支持的VPN协议:在HA模式下,PPTP和L2TP/IPSec(PSK)不可用作VPN服务器选项。请改用QBelt、OpenVPN或WireGuard。推荐使用QBelt,QNAP的专有VPN协议,以便更好地与QNAP系统集成。
 - 客户端调整:在启用HA之前,手动配置所有VPN客户端以使用支持的协议,以防止连接问题。
 
HA的连接要求
- 使用群集 IP(CIP):连接VPN时始终使用群集 IP而不是节点IP(NIP)。无论哪个NAS处于活动状态,CIP始终保持一致,即使在HA 故障转移或切换期间也能确保不间断访问。
 - DNS和路由考虑:如果您的VPN客户端依赖于特定的DNS配置,请确保DNS解析指向CIP以防止连接中断。
 
处理OpenVPN客户端重新连接
如果您使用OpenVPN Connect在您的设备上连接到QNAP设备上的QVPN VPN服务器,在HA 故障转移或切换后,连接不会自动恢复。如果发生故障转移或切换,您必须手动重新连接以恢复VPN访问。
OpenVPN连接是有状态的,意味着它们与服务器保持活动会话。然而,HA 故障转移或切换不会在节点之间传输会话状态,因此需要手动重新连接。
如需在HA环境中进行VPN配置的进一步帮助,请联系QNAP客户服务。