• Multiple VLANs as WAN using PPPoE Connection to ISP

    1
    0 Votes
    1 Posts
    309 Views
    No one has replied
  • Failover notifications

    3
    0 Votes
    3 Posts
    992 Views
    luckman212L
    First, it's time to upgrade your pfSense! 2.2.6 is pretty old, and one of the best things to come in 2.3+ was that apinger (gateway monitoring daemon) was replaced by dpinger – which is infinitely more reliable. Anyone who's been using pfSense for more than a couple of years will remember with much angst the nightmare of wrestling with apinger. Once you've done that, I highly suggest you read https://doc.pfsense.org/index.php/Multi-WAN#Optional_Tweaks and experiment with the latency & loss thresholds. The messages about IPSEC/OpenVPN/Dyndns are not important and do not indicate any problem. They are just basically debug messages from code paths that, in your case, are not being hit. Good luck. If you need more specific help feel free to come back and ask.
  • Dual GW, picking GW based on Destination

    2
    0 Votes
    2 Posts
    407 Views
    luckman212L
    Not quite enough info there to help you… can you post a screenshot of the rules on your LAN interface? Rules are processed in order from top to bottom, so make sure you put any policy-based routing rules ABOVE your last "default" rule otherwise it will never get hit... Generally, make sure you leave "source port" blank - 99% of the time source ports are random and you should only be concerned w/ Dest. port. Did you change anything on the Firewall > NAT > Outbound page? (you should leave that on 'Automatic' until you understand it fully)
  • Two Pfsense each with Seprate Internet routing each other

    39
    0 Votes
    39 Posts
    4k Views
    johnpozJ
    "can you explain from where the gateway 192.168.9.253 and 192.168.2.253 comes from" As I told you already - those were my wan_dhcp gateways in the downstream pf1 and 2 I setup.. That is just my internet in my setup to mimic yours.  Here is a drawing.. "Both firewall communicate each other but can not access Internet." Who can not access internet, can your 2 networks talk to each other? 192.168.0 and 192.168.10?  Did you mess with outbound nat?  When you create your downstream route it should automatic create your outbound nat for you. Your going to have to post your setup if you want me to spot what your doing wrong.  How is it showing online when shows NO interface or connection just "NONE"  How does your wan have a 0.0ms response time?? [image: setupsimyoursetup.png] [image: setupsimyoursetup.png_thumb]
  • A second configured WAN doesn't work properly through PfSense

    1
    0 Votes
    1 Posts
    269 Views
    No one has replied
  • Dynamic routing

    2
    0 Votes
    2 Posts
    1k Views
    H
    Policy routing Will do that. (specifying a gateway on a fwrule)
  • Failover not working for ICMP and UDP

    1
    0 Votes
    1 Posts
    390 Views
    No one has replied
  • Gateway Offline

    3
    0 Votes
    3 Posts
    1k Views
    GilG
    Sorry for the belated reply. The answer is not specific and definitive. It appears that FreeBSD is more stringent on the rules it will accept for routing than is NanoBSD. Look at the way your routes and gateways function.
  • LAGG setup and "down" detection

    2
    0 Votes
    2 Posts
    535 Views
    H
    Well static lags generally only detect link up/down AFAIK. Then you have more modern stuff like LACP. its a bit more intelligent: https://www.thomas-krenn.com/en/wiki/Link_Aggregation_and_LACP_basics When multiple switches are involved you probably want STP (or brandspecific alternative) https://en.m.wikipedia.org/wiki/Spanning_Tree_Protocol
  • 2 WANS with dedicated routing - VLANs or not?

    4
    0 Votes
    4 Posts
    474 Views
    DerelictD
    pfSense Multi-WAN does not care if they are VLANs or physical interfaces. It works the same way.
  • Interrupt race conditions on network interface cards

    2
    0 Votes
    2 Posts
    391 Views
    G
    :-[ Unfortunately I had another one today, 8 out of the 12 processors where going berserk on the interrupts, while there was only 20Mb/s and between 2000 and 5000 pps.
  • 0 Votes
    2 Posts
    433 Views
    W
    Hi, Generally speaking, your pfSense box is placed in between your work (1.x) and other (2.x) networks which appears to be acting as a firewall/router. If you want to continue with a configuration like this, you'll need to do some NAT/Port forwarding AND firewall rules to allow the 1.x network to be able to talk to the specific 2.x network hosts in terms of what ports (i.e.: 443, 80, 22, etc) and protocols (icmp, tcp, udp, etc). You'd then access the pfSense box's WAN address on the 1.x network and define which port you want to access, which translates over to the proper host on the 2.x via NAT/port forward with some configuration on the pfSense box. As a side note, you may be able to disable NAT on the WAN interface (1.x) of the pfSense box and then you'd only need to do firewalling. I have never done this before but seems simple in concept. A cleaner configuration would be to have the pfsense box with multiple network adapters (minimum of 3 in your configuration) which segregates these networks using pfSense, (but using a single box for LAN1, LAN2, WAN, etc),  LAN1 could be the 1.x and LAN2 could be the 2.x. Then you would only need fire walling rules and not also inbound NAT rules/port forwarding. There's some other settings to be applied with outbound NAT i believe but the auto-generated outbound NAT should suffice out of the box in this scenario. Hope this helps give you some direction on how you want to approach the problem without writing a book. @WillieBeamen: Hi. I need some help, and I think the answer is simple, but I'm not very experienced with routing and networking, so I need some noob-friendly help, or pointers to some threads that might help. I use an internet anonymizing service (PIA (Private Internet Access) if that helps).  I have 8 PCs (towers and some laptops) in my home, some for work, some for leisure, some just for Netflix, streaming.  I am trying to set up a system so that 1-3 devices stay fully anon (behind the PIA servers) when surfing the internet, but can still share folders / files between the other PCs in my home network (which are not utilizing any anonymizing services at all). Following the guides provided by PIA I was able to successfully install pfsense to a single tower PC (1 Realtek NIC (embedded) + 1 4-port HP gigabit NIC (PIC-e slot))  and configure OpvenVP services for PIA access.  Amazingly, I got it up and running, but now I have a problem. Here's my situation at the moment. My 'work' PCs are all plugged straight into my home router and are using 192.168.1.xxx These do not (nor will ever) use or need to access PIA's services. My pfsense Box (which is configured with PIA/OpenVPN (anonymizing traffic)  is configured to use the 192.168.1.xxx gateway, but the LAN address is 192.168.2.xxx so here's my problem. Any PC on 192.168.1.x can't see / share files with any PC on the 192.168.2.x domain. Is there a way to get devices on 192.168.1.x  to see the devices on 192.168.2.x ? Or am I going about this all wrong? apologies in advance, I'm a noob at this, I'm honestly surprised that I was able to even get my pfsense box setup and working with PIA. Everything would be great, except I can no longer share files between the two domains. Any (noob friendly) help would be very greatly appreciated. edited to add: on the box running OpenVPN: pfsense:  running 2.3.4-Release-p1 (amd64) WAN:  is being assigned a gateway from 192.168.1.xxx LAN:  192.168.2.xxx
  • Routing Upload and Download through two seperate WAN connections

    4
    0 Votes
    4 Posts
    762 Views
    johnpozJ
    He changed his post from his original question..  Yes what he asked now is easy peasy..
  • Can lagg be done between geographically separated pfsense machines?

    20
    0 Votes
    20 Posts
    2k Views
    U
    Like the Chinese say: those who say it cannot be done should not interrupt the one already doing it.
  • Per host multi wan load balancing (https)

    1
    0 Votes
    1 Posts
    290 Views
    No one has replied
  • Custom settings for RIP (routed). Save /etc/gateways permanently

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • Simultaneous pppoe not working with VLAN

    4
    0 Votes
    4 Posts
    1k Views
    R
    Bump, I am having the same problem, one PPPoE via VLAN works, adding two or more using VLAN fails.
  • Negate rule and policy routing

    3
    0 Votes
    3 Posts
    1k Views
    N
    Thanks for your reply, Lan rules image has been attached, [image: Lan-RULE.jpg_thumb] [image: Lan-RULE.jpg]
  • Fetch from pfsense shell with different gateway

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    Same fetch, but our pf ruleset has some tricks with route-to that make it work.
  • Changing the Gateway for one Machine not working anymore.

    5
    0 Votes
    5 Posts
    560 Views
    N
    I have the same issue. i think there is a bug in "policy base routing". when you add a rule to "any" destination to change the gateway, it will not work. if you set a specific destination for that rule, it will works. you can add your rule with "!1.2.4.5" destination to change your client GW till pfsense team fix it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.