• [SOLVED]Alternative to sticky connection option

    Moved
    2
    0 Votes
    2 Posts
    482 Views
    dotdashD
    Make an alias of sites that you don't want to load balance, then put a lan rule with the destination of the alias and point it to a failover group.
  • Minor bug with routing web interface

    Moved
    2
    0 Votes
    2 Posts
    345 Views
    R
    I wonder if this is a more prevalent bug that other people are noticing as well. I had something similar happen and I thought it was rather weird. At least the interface still shows and recognizes the gateway.
  • TFTP over two subnets

    7
    0 Votes
    7 Posts
    3k Views
    R
    After long time of searching i figured out, that one of the upper rules (which was for outgoing traffic) was responsible for the problem. after i set it to the bottom, everithing worked fine. Thanks for your fast response Kind regards Roger
  • Pfsense and Vodafone fibrex

    5
    0 Votes
    5 Posts
    1k Views
    B
    @beekay said in Pfsense and Vodafone fibrex: So I got my router to see the internet … eventually! Don't know if it is the right way, but My WAN connection is connected through VLAN - igb1.10 Now I need to sort out VPN. I can set up various VPN clients and will finish that up tonight. What I need is the router to recognize a connection to say Netflix from any device and then direct it's traffic through the US VPN client I picked. If I want to connect to another streaming site, I want the router to direct the traffic to an alternate VPN client I set up. Any other traffic which is not geo-locked, must be sent through a general VPN client in my home country. Please point me in the right direction as I do not know how to set this up. BUMP
  • OPT1 to lan to wan

    3
    0 Votes
    3 Posts
    338 Views
    D
    @derelict OMG you saw it so quickly, thank you for your reply ! "beginner mistake" I don't want to pollute this forum, so you can delete this topic if you want, my problem was not really a problem in fact...
  • Multi-Wan IPV6

    12
    0 Votes
    12 Posts
    2k Views
    C
    @derelict doh' I knew it would be something as dumb as that! Jeez. Thanks a lot to everyone for your help. it works now :) !!
  • Multi-WAN, Multi-LAN, no failover, cross communication issues over WAN

    5
    0 Votes
    5 Posts
    731 Views
    F
    Sorry for the late reply, thank you very much for helping! In the end, it ended up being NAT reflection on the port forward being set to default instead of enabled. For whatever reason I assumed that this was on by default, I'll RTFM next time! After enabling that, I can now connect to LAN2 properly through LAN1 using the external WAN2 IP!
  • Delay or manual failback?

    5
    0 Votes
    5 Posts
    880 Views
    Z
    @derelict Ahh.. OK. Thank you! That was exactly what I was looking for! /Raj
  • Connect certain IP-ranges across multiple PFsenses

    2
    0 Votes
    2 Posts
    360 Views
    DerelictD
    Yes, it's possible, but I would not do it like that. I would put each pfSense on its own transit network, such as 10.1.10.0/30 for the link to the top pfSense and 10.0.10.4/30 for the link to the lower pfSense. You can keep them on the same network like they are if you want to, say, enable an OSPF area containing all three routers so they all know where to send the traffic without relying on hairpinning, ICMP redirects and other nastiness. Or maintain static routing tables pointing everything where it needs to go.
  • Gateway failover and gateway's DNS

    3
    0 Votes
    3 Posts
    730 Views
    H
    @derelict Yeah that was a typo. After some digging, https://developers.google.com/speed/public-dns/faq : "Google Public DNS is a validating, security-aware resolver. All responses from DNSSEC signed zones are validated unless clients explicitly set the CD flag in DNS requests to disable the validation." OpenDNS does not indeed. So I moved to some of the verisign servers that do (according to https://wiki.ipfire.org/dns/public-servers). So far no issues.
  • Routing between multiple subnets

    6
    0 Votes
    6 Posts
    957 Views
    DerelictD
    Those are fine. The rules on LAN sourcing from ESXi and the rules on ESXi sourcing from LAN don't make any sense but shouldn't be blocking the traffic. Based on that though you should probably take a look at these: https://doc.pfsense.org/index.php/Firewall_Rule_Basics https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting
  • Multi WAN - Multiple Public Subnets

    9
    0 Votes
    9 Posts
    1k Views
    DerelictD
    Pretty obscure checkbox to have been checked. Glad you found it.
  • 0 Votes
    2 Posts
    560 Views
    johnpozJ
    I would return that switch if v2, they have firmware for v3 that is supposed to fix the vlan.  But v2 model you can not remove vlan1 from every port so its no better than a dumb switch. That is not a layer 3 switch, so you would do 2 vlans and pfsense would route between them. your vlans are tagged on the port connected to pfsense, and untagged to your PCs.
  • Route througth remote gateway inside of IPSec tonel

    4
    0 Votes
    4 Posts
    456 Views
    A
    @viragomann: Add a second phase 2 for that site to the IPSec configuration. On pfSense: Local Network: 192.168.120.1/24 Remote Network: The network you want to route over the vpn And also on the Mikrotik with inverted values. thanks for your reply. very unexpected sollution, but it works
  • Routing LAN Interfaces via IPsec Tunnel

    3
    0 Votes
    3 Posts
    403 Views
    A
    both sides pfsense?
  • Supported LTE bridge for WAN failover?

    2
    0 Votes
    2 Posts
    315 Views
    ?
    See my recent post 'Netgear LB2120 as WAN failover'. It explains how I got the LB2120 working as my failover WAN. The firmware update for the Netgear LB series corrects the bridge issue. You can upgrade it directly from the LB2120's web administration. On the LB2120 itself, you'll need to have it connect to the wireless APN. This means that it is always on but that's what you need for a failover. You can limit the amount of pinging that the pfSense does to limit bandwidth usage under the pfSense Gateway Advanced section. I doubt Netgear would recommend anything but their antenna (Netgear 6000450 MIMO). If you go to an online LTE / antenna store, they might be able to provide you details on maximum cable length. That being said, unless you're carrier has exceptionally bad reception, or you're in a building that has shielding qualities, the antenna should be fine. Just using the internal antenna's I've got two bars or 3 bars, located 15 feet from an exterior wall.
  • Routing a /26 to Multiple /32

    7
    0 Votes
    7 Posts
    815 Views
    johnpozJ
    As Derelict says pfsense has really nothing to do with this - it would all be at your switch setup.  Layer 3 switch with /30 would be way to go - but your /26 is not going to allow for that. Why would your users be setting static IPs on their routers that could conflict when your just going to hand them their IP via dhcp.. If you do not have a single switch that can handle all the ports, prob want to break your /26 into say 2 /27 and use 2 48 port switches for each half, etc.  or a 48 and 24… There are much better switches than the unifi ones with much better feature sets at same sort of price point.. But if your worried about isolation of the customers you would have to check to see if it does private vlans, etc.
  • Multi WAN Failover with 2x PPPoE and same IP address

    4
    0 Votes
    4 Posts
    649 Views
    B
    Hi Nog, Tried all the above and no better I'm afraid! If anyone has any further suggestions please do let me know Thanks!
  • Vlan won’t cross

    3
    0 Votes
    3 Posts
    501 Views
    DerelictD
    Post Interfaces > Assignments Select ONE of the interfaces that isn't working and post its interface configuration and its Firewall > Rules Post Firewall > NAT, Outbound
  • VPN failover to WAN

    2
    0 Votes
    2 Posts
    446 Views
    M
    UPDATE: this is probably not going to be AirVPN as my 50/50 (without VPN) connection yields a 0.5/0.2 (with AirVPN)…
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.