• WireGuard on pfSense behind ISP router. Why do I need a static route?

    34
    0 Votes
    34 Posts
    5k Views
    D
    @dangersheep @viragomann We discussed the need (or not!) for a static route/gateway. Isn't that related to the bug report here: https://redmine.pfsense.org/issues/14200 ?
  • Private subnets routing to somewhere unknown?

    13
    0 Votes
    13 Posts
    1k Views
    NogBadTheBadN
    Nevermind, just read the bit about connecting to home via OpenVPN. You mention using OpenVPN, if so have you selected "don't pull routes" if you don't it's likely your default route is via your OpenVPN connection rather than your WAN link. [image: 1696873391067-screenshot-2023-10-09-at-18.41.50.png]
  • RADIUS during failover

    1
    0 Votes
    1 Posts
    363 Views
    No one has replied
  • Failover doesn't work for IP phone. Something with DNS?

    2
    0 Votes
    2 Posts
    477 Views
    pfrickrollP
    Any thoughts? I know it's not the phone configuration or providers ISP because I had the same issue at my last job with other phones. However, the same set up worked just fine on Sonicwalls.
  • WAN to LAN routing with firewall

    4
    0 Votes
    4 Posts
    680 Views
    V
    @Antonii Yes, exactly.
  • Multi Gateways together with WireGuard and Multi Servers

    3
    0 Votes
    3 Posts
    705 Views
    Bob.DigB
    @Itay1787 I don't think you can do that with WG on pfSense. With OpenVPN you would be able to chain Clients though. Maybe use a VMs for your first client...
  • L3 Route not sending traffic along

    5
    0 Votes
    5 Posts
    788 Views
    J
    @viragomann Gateway is set to none, When sniffing packets, I see them come in but not come out of the firewall. They just terminate with Time to live exceeded This firewall is setup in HA and testing the route using the secondary firewall works fine. I suspect it's a routing bug somehow caused on the primary firewall. I guess a restart will be required for further troubleshooting. Thanks for your help.
  • Wireguard doesn't fail back to main tier 1 Link

    5
    1 Votes
    5 Posts
    900 Views
    pfrickrollP
    @jstride Is this Gateway group "WAN_VPN_GATEWAY" in your firewall rule the one from from your failover group you created in System/Routing/Gateway Groups? It should be. It looks like your failover group name is "WAN" from your first post.
  • pfsense+ AWS EC2 Asymmetric Routing Help

    2
    0 Votes
    2 Posts
    497 Views
    planedropP
    @pczinser Not personally super experienced with pfSense in AWS, but wanted to at least try and help or get this topic a bit of a bump haha. So, just to be clear, where are you seeing the default deny happen? In pfSense right? But on what interface in specific? I'd first be suspect of that and see if you can get the traffic to pass, but yes could be asymmetric for some reason. Again, not a huge AWS person, but is there a reason the VPN is built with AWS and not setup within pfSense at each location itself?
  • Multiple VLAN routing issue - works on F5 but cant emulate on PFS

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    @alexnyc On vlan3 set an outbound nat so that when 77.4.5 pings 10.10.10.4 it looks like it comes from pfsense 10.10.10.1 address. But why would you even want that to be used, why would 77.4.5 not just access 777.4.4? I would put a outbound nat on that vlan3 so any source comming from 71.77.4/24 going to 10.10.10/24 would look like it came from 10.10.10.1
  • 0 Votes
    4 Posts
    693 Views
    V
    @jankol said in Single public IP subnet on WAN scenario but pfSense router as default gateway for WAN clients: My main motivation for the alternative setup (compared to documentation) was the ability to control upstream communication from the server to the internet (so pfBlockerNG could block advertisements and possibly do port forwarding VIP => Server IP). I hoped that it is somehow possible You can do this anyway. All traffic to and from the server have to Pass pfSense, hence you can block and oass whatever you want. This is also true for pfBlocker rules.
  • 0 Votes
    1 Posts
    326 Views
    No one has replied
  • 0 Votes
    2 Posts
    316 Views
    J
    Admin: You can delete this post. I got things working by adding a basic pass rule. John
  • default gateway at a different subnet as the interface itself

    1
    0 Votes
    1 Posts
    224 Views
    No one has replied
  • Problem connecting the router to pfsense

    3
    0 Votes
    3 Posts
    368 Views
    A
    @viragomann thanks a lot!
  • 0 Votes
    5 Posts
    1k Views
    bingo600B
    @Bravo-0 said in How to have SVI's in a L3 switch route to the internet through a Pfsense router?: Just got more information from the firewall and interface monitoring dosn't pick up any incoming traffic form each device an a SVI. So it's not even hitting the device. I'm not sure how to interpret this ... Didn't you say you had some succesfull pings ?? Also the interface gi10 does have the no switchport command So it should operate as a L3 IF , not a switchport ?? I'm not experienced w. the 300 series .... If it's a "pure L3" IF , try to connect a PC to gi10 , and give it the pfSense ip. Then test if you can ping the switch: If yes (switch l3 config) ought to be ok , (challenge is on pfSense). If no ... (challenge is on switch) /Bingo
  • Load balancing on multiple WANs

    1
    0 Votes
    1 Posts
    337 Views
    No one has replied
  • Route a certain IP to a internal IP

    1
    0 Votes
    1 Posts
    223 Views
    No one has replied
  • 1 Votes
    1 Posts
    282 Views
    No one has replied
  • Public Static IP

    8
    0 Votes
    8 Posts
    835 Views
    johnpozJ
    @MarkCabrera so it gets a rfc1918 address, 192.168.x.x Then its in nat mode - you prob need to set it bridge or modem mode.. Again what is the make and model of the device?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.