• Problem changing gateway through rules

    12
    1
    0 Votes
    12 Posts
    1k Views
    DerelictD
    @dukynuky said in Problem changing gateway through rules: pass in log quick on $OpenVPN reply-to ( ovpnc1 10.10.10.1 ) inet from any to any tracker 1560717223 keep state label "USER_RULE" now it is working.. seems pfsense isnt creating the reply to rules.. :( That will not survive filter rule rewrites. The traffic coming into the lower pfsense MUST NOT MATCH rules on the OpenVPN tab or the state will not get reply-to. The traffic must match the rules on the Assigned interface tab. If it matches a rule on the OpenVPN tab, those are processed first so the assigned interface rules will never be reached, and therefore no reply-to. All of this works. It just has to be configured correctly. I would just remove all rules from the OpenVPN tab and put the necessary rules on the appropriate assigned interface tab and never worry about it again. Some topologies support this method, some don't.
  • Multiple public IP multiple routers...

    10
    0 Votes
    10 Posts
    2k Views
    johnpozJ
    @Derelict said in Multiple public IP multiple routers...: If all of this is jibber-jabber to you My money is on this statement ;)
  • 0 Votes
    6 Posts
    349 Views
    nzkiwi68N
    I still got this issue, now I can replicate it easily at 2 completely sites, all 2.4.4_p3 and both using; FRR and OSPF list itemHA pair list itemIPSEC VTI tunnels bound to a CARP IP address list itemFRR set to fllow the lan CARP address (so FRR off on the backup firewall) Here's a continuous ping across the VPN from site A to site B. Reply from 10.10.40.1: bytes=32 time=4ms TTL=253 Reply from 10.10.40.1: bytes=32 time=7ms TTL=253 Request timed out. Request timed out. Request timed out. Request timed out. Reply from 10.10.40.1: bytes=32 time=4ms TTL=253 Reply from 10.10.40.1: bytes=32 time=3ms TTL=253 Reply from 10.10.40.1: bytes=32 time=4ms TTL=253 Reply from 10.10.40.1: bytes=32 time=3ms TTL=253 First timeed out, that's the primary firewall being rebooted, 4 pings lost and the backup completely takes over. Very acceptable. Excellent. Now the slow bit... The primary comes up, CARP takes over and takes ages for things to settle and go online. Reply from 10.10.40.1: bytes=32 time=3ms TTL=253 Reply from 10.10.40.1: bytes=32 time=17ms TTL=253 Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Request timed out. Reply from 10.10.40.1: bytes=32 time=3ms TTL=253 Reply from 10.10.40.1: bytes=32 time=4ms TTL=253 After digging, I think the cause is the VPN, IPSEC, it's just not getting released from the backup firewall in a timely manner, it seems to hold on and on and on and keeps running IPSEC VPN tunnels. I can speed up the fail back by logging onto the backup firewall and in IPSEC status stopping the IPSEC tunnels. I wonder if the issue is because my IPSEC tunnels are using a CARP IP address?
  • Two WAN - same gateway

    4
    0 Votes
    4 Posts
    690 Views
    DerelictD
    Ask the provider if they have an alternate subnet they can assign to the other subscription.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    1 Views
    No one has replied
  • Block traffic/No routing between LANs on pfSense

    15
    0 Votes
    15 Posts
    6k Views
    E
    Many thanks for your help, it works fine. You help me a lots.
  • Dual Wan LB Slower Upload

    1
    0 Votes
    1 Posts
    116 Views
    No one has replied
  • Dual Wan+LB Plex

    2
    0 Votes
    2 Posts
    337 Views
    T
    @techanalyst NM solved
  • Multiwan failover between two sites via P2P Leased line.

    2
    1
    0 Votes
    2 Posts
    521 Views
    N
    @Nick-Sharp said in Multiwan failover between two sites via P2P Leased line.: Static routes 192.168.2.0/24 GW_OPT1 – 10.10.100.2 Interface WSP2PHH This should read... 192.168.1.0/24 GW_OPT1 - 10.10.100.1 Interface HHP2PWS
  • PPPoE Connected to lan

    1
    0 Votes
    1 Posts
    146 Views
    No one has replied
  • Specifying a gateway in a firewall rule breaks routing

    3
    1
    0 Votes
    3 Posts
    503 Views
    M
    Thanks for your response. You know, sometimes you need to be told something three times before it sinks in. Every time I've seen this recommendation, I've read the settings as "Pull Routes" not as "Don't Pull Routes". I thought having the box unchecked was accomplishing this. After more careful examination I see that I had it backward. I checked this box and voila! It's now working as expected. Thank you! Help me understand the DNS leak concern and how to avoid it?
  • 0 Votes
    17 Posts
    2k Views
    johnpozJ
    Well then you changing the cache default time makes no sense how it could fix anything.. Have your isp explain what that setting "fixes" If the mac doesn't change then your cache could be for 10 years ;) Seems like your isp wants to see arps more often than every 20 minutes for whatever reason?
  • Multiple LAN subnet with single gateway

    1
    0 Votes
    1 Posts
    144 Views
    No one has replied
  • Access to Web Gui over ISP WAN Gateway - Rules,NAT?

    6
    0 Votes
    6 Posts
    1k Views
    JeGrJ
    @guido_neumann said in Access to Web Gui over ISP WAN Gateway - Rules,NAT?: Destination WAN Orbis1 and now i can ping and HTTPS. Destination would be "WAN_ORBIS1 Addr" or "This Firewall". Source should be any because of - you get it - the internet. Or even better, if you access that from a static IP (company etc.) then only allow this or another trusted IP. Much better than just allowing all.
  • Setup of SG-3100 after hitting the reset button

    5
    0 Votes
    5 Posts
    854 Views
    P
    Thank you, Chris. I was able to download and install the image. All is good!
  • 0 Votes
    5 Posts
    587 Views
    S
    @viragomann Thanks, I may just try that.
  • Using PfSense to serve CGNAT or Dual Stack Lite

    7
    0 Votes
    7 Posts
    2k Views
    0daymaster0
    My immediate goal in regards to addressing is to make it long enough so that I can purchase a class C IPv4 netblock on the open market. Nothing would make me happier than the death of IPv4 but until then I am forced to support it.
  • WAN IP is on different subnet than default Gateway

    13
    0 Votes
    13 Posts
    7k Views
    E
    Hi to all, I'm facing to the same problem, WAN connexion is droped after 10min, and up after 10 other... I try to add route or modify "Use non-local gateway" in WAN gateway advanced, but it doesn't fix the problem. [image: 1563130173992-f8db588f-7b67-4e9e-b040-f2425f22c50b-image.png] How can i fix WAN connexion ? Best Regards.
  • 0 Votes
    1 Posts
    153 Views
    No one has replied
  • unbound dns resolver loses custom config

    6
    0 Votes
    6 Posts
    770 Views
    johnpozJ
    There is a package called filer, it would allow you to store the contents of a file in the xml, so the file will be created for you after say an update to pfsense.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.