• 0 Votes
    1 Posts
    127 Views
    No one has replied
  • mesh openvpn network doesn't route openvpn clients to remote networks

    3
    0 Votes
    3 Posts
    234 Views
    T

    Well, i figured it out.

    I was doing the logical thing by adding the remote network to each side (Site B) and to the OpenVPN service (hosted on Site A). And that wasn't working.

    So I started messing around with the openvpn firewall. Turns out that you need an additional explicit route on the mobile client server config.

    Source: openvpn mobile client subnet (192.168.1.0/24 in this example)
    Destination: any

    Now the traffic routes. I'm sure that is documented somewhere but i couldn't come up with the right search phrase. I only figured it out with lucky guesses.

    Now those lucky bastards on OpenVPN Client can see the network resources on Site B. (And much more since this is a mesh setup.)

  • Multi WAN: editing FW rules necessary?

    2
    0 Votes
    2 Posts
    160 Views
    X

    Based on my understanding (which might be wrong), set your Gateway Group as the default Gateway then you shouldn't need to modify the firewall rules.

    In my case, I need to modify the firewall rules to block all but high priority devices from using the backup (Tier 2) WAN. But, if thats not a concern of yours then I think you should be fine.

  • 0 Votes
    1 Posts
    101 Views
    No one has replied
  • Routing Troubles with Dual WAN

    2
    0 Votes
    2 Posts
    115 Views
    S

    Found the problem.

    I swapped out SIM cards and everything worked fine. Therefore, I tracked it down to having an issue with the cellular provider.

  • Can't ping/access internal network from LAN or WAN interface.

    2
    0 Votes
    2 Posts
    264 Views
    KOMK

    @romal-amarkhail said in Can't ping/access internal network from LAN or WAN interface.:

    Any idea what might be wrong here?

    Do you know for a fact that the unit responds to pings? And if your LAN is 192.168.2.0, why is the wifi on 192.168.1.0? Are you using a /16 mask? Is your wifi in AP mode?

  • Monitor is FALSE detecting one of my WANs as DOWN and another WAN as UP

    39
    0 Votes
    39 Posts
    3k Views
    G

    It's more interesting, i switch Trigger Level to High Latency, and some time later pfSense himself switch it to Packet Loss! I didn't understand, why it happens.

    And for sure it's dpinger bugs related, case i have checked "Disable Gateway Monitoring Action" and then made reconnect on router 2 (3 gateway) and in "Gateway status" i get on 3 gateway "Danger, Packetloss: 100%" on 3 gateway, i have check - traffic still goes through 3 gateway (router 2) without any problems, but dpinger thinks that it's dead for sure forever, till i make "save and apply" in any gateway settings.

    I didn't now how to make monitoring work in pfSense. :(

  • pfSense with multi-WAN on same subnet

    7
    0 Votes
    7 Posts
    1k Views
    J

    I guess this issue is then solved.
    Thanks for the help.

  • How many NIC's PFSENSE can handle ?

    4
    0 Votes
    4 Posts
    341 Views
    jimpJ

    VLANs, VPNs, anything virtual.

  • Optimal VPN solution for Dual wan?

    2
    0 Votes
    2 Posts
    422 Views
    S

    GRE Tunnel Bonding Protocol [https://tools.ietf.org/html/rfc8157](link url) - "Single flow may use the combined bandwidth of the two connections.
    Can this be implemented in pfSense?

    It seems Layer2 bonding is one solution. " since load balancing in bonding takes places in Ethernet frames, even a single TCP/IP connection will enjoy an increased band thanks to the presence of multiple links."
    [https://zeroshell.org/load-balancing-failover/#vpn-bonding](link url)
    Can this be implemented in pfSense?

  • No Internet on second lan

    13
    0 Votes
    13 Posts
    2k Views
    D

    I believe I am now sorted.

    I have left don't pull roots unchecked and in firewall/rules/secondlan advanced options/gateway I chose WAN_PPPoE.

    I now have internet connection via VPN on igb1 and igb2 and connection not through VPN on igb4 just as I wanted.

    Many thanks for the help

  • Dpinger sendto error: 65 on one of identically configured WANs

    2
    0 Votes
    2 Posts
    1k Views
    KOMK

    @dimskraft said in Dpinger sendto error: 65 on one of identically configured WANs:

    sendto error: 65

    Maybe this is relevant?

    https://forum.netgate.com/topic/98656/gateway-send-to-error-65

  • Traffic graphs not matching throughput + poor performance

    1
    0 Votes
    1 Posts
    89 Views
    No one has replied
  • PFSense doesn't switch back to primary connection in multi-WAN setup

    12
    1 Votes
    12 Posts
    1k Views
    R

    @hebein glad to help you! I think log analyzing will help to reach 100%)

  • pfSense loses internet when dpinger fails (help with gateway config)

    6
    0 Votes
    6 Posts
    1k Views
    KOMK

    Put the other members of the gateway group on a lower tier. If you have them all on tier 1 then it won't switch when the down member comes back.

  • Routing| Wan and Lan

    6
    0 Votes
    6 Posts
    649 Views
    KOMK

    Well, the only rule that has seen any traffic at all is the Default allow LAN to any rule, so nothing is being blocked. That's why I suggested you try looking at it from the Synology side.

  • Routing dynamic URL to correct internal IP address.

    2
    0 Votes
    2 Posts
    168 Views
    johnpozJ

    Sure with the HA proxy you can do that. I do it now for a couple different fqdn.

    But that is going to work with http protocols, not going to be able to work with say smtp.

  • Route default over AWS Transit Gateway VPN over an AWS Direct Connect

    1
    0 Votes
    1 Posts
    445 Views
    No one has replied
  • Outbound Routing over specific IP

    2
    0 Votes
    2 Posts
    228 Views
    V

    Add each WAN IPs you want to use to the WAN interface. Firewall >Virtual IPs. Use type "IP Alias".

    Go to Firewall >NAT >Outbound. Switch into the manual mode. pfSense should take over the automically generated rules for each of your subnets into the manual mode. Edit each one, go down to the translation address and select the outbound IP from the drop-town you want to assign the respective source network.

  • Unexpected route chosen when using a Group Route

    1
    0 Votes
    1 Posts
    148 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.