• Firewall Rules do not work with NAT unless default gateway is selected

    4
    0 Votes
    4 Posts
    572 Views
    S
    when I watch the states of one of the test servers, it looks like this: LAN tcp x.x.0.96:45922 -> x.x.0.50:80 (x.x.x.148:80) CLOSED:SYN_SENT 4 / 0 240 B / 0 B This shows up multiple times, but it still receives the same error. I am not seeing it go through the gateway anymore though (Instead of LAN it used to say the GW name)
  • Routing between multiple sites

    15
    0 Votes
    15 Posts
    1k Views
    DerelictD
    @amundae IPsec traffic selectors are not in the routing table because they are not routes. https://forum.netgate.com/topic/131420/routed-ipsec-using-if_ipsec-vti-interfaces
  • Sharing ethernet line with dedicated pipe for each company

    3
    0 Votes
    3 Posts
    447 Views
    johnpozJ
    Yeah why not just use 1 pfsense, put your different companies on different networks and then just limit bandwidth or better just rate limit them at the switch level.
  • Remote access one subnet to secondary subnet w/it's own gateway

    7
    0 Votes
    7 Posts
    982 Views
    johnpozJ
    yes when you put hosts on a transit you have to route on them as well.. because hosts do not belong on a transit network only routers do..
  • Dual-path routing to the internal network?

    13
    0 Votes
    13 Posts
    3k Views
    N
    Having pf on vm's gives another layer of redunduncy, but thats another story. Maintaining one system does have its benefits (upgrades, troubleshooting etc) And routing the packets in and out of virtual interfaces does consume unnecessary cycles. I can't tell if this has any measureable degradation whatsoever in any case. I do have second thoughts if that would work in the end, becauseit all boils down to a common routing table so traffic would never pass through the lans :(
  • Only Have IPV6 on Wan and IPV4 on Lan?

    1
    0 Votes
    1 Posts
    275 Views
    No one has replied
  • No PPPoE link in Loadbalance

    2
    0 Votes
    2 Posts
    457 Views
    No one has replied
  • vlan question

    12
    0 Votes
    12 Posts
    1k Views
    S
    It sounds like you do need the functionality of a managed switch. I recently went through this myself. I'm not a professional network engineer but I do understand networking reasonably well. I can help translate what the pros here are saying because I'm not one of these guys .. they know their stuff. What might help this discussion is to understand your needs a bit more clearly. How many VLANs do you anticipate? How many clients/ports do you need to support per VLAN? How are you running pfSense? Is it a Netgate appliance, home built, in a VM?
  • Multi Wan 4G Router DWM-312

    1
    0 Votes
    1 Posts
    293 Views
    No one has replied
  • Multi WAN with same gateway IP intereferes with balancing

    15
    0 Votes
    15 Posts
    6k Views
    N
    I can safely verify that in 2.4.3-RELEASE-p1 (current stable) works as it should One interface is left with the dynamicly selected monitor peer and the other pings a stable ip inside the provider (in my case the cluster ip of the main dns stack) If the provider changes her policy and blocks ping that would be an issue, but I think I can live with that. :)
  • Dual WAN failover due to DNS failure , possible?

    dns failover multi-wan
    1
    0 Votes
    1 Posts
    651 Views
    No one has replied
  • [SOLVED]Alternative to sticky connection option

    Moved
    2
    0 Votes
    2 Posts
    489 Views
    dotdashD
    Make an alias of sites that you don't want to load balance, then put a lan rule with the destination of the alias and point it to a failover group.
  • Minor bug with routing web interface

    Moved
    2
    0 Votes
    2 Posts
    349 Views
    R
    I wonder if this is a more prevalent bug that other people are noticing as well. I had something similar happen and I thought it was rather weird. At least the interface still shows and recognizes the gateway.
  • TFTP over two subnets

    7
    0 Votes
    7 Posts
    3k Views
    R
    After long time of searching i figured out, that one of the upper rules (which was for outgoing traffic) was responsible for the problem. after i set it to the bottom, everithing worked fine. Thanks for your fast response Kind regards Roger
  • Pfsense and Vodafone fibrex

    5
    0 Votes
    5 Posts
    1k Views
    B
    @beekay said in Pfsense and Vodafone fibrex: So I got my router to see the internet … eventually! Don't know if it is the right way, but My WAN connection is connected through VLAN - igb1.10 Now I need to sort out VPN. I can set up various VPN clients and will finish that up tonight. What I need is the router to recognize a connection to say Netflix from any device and then direct it's traffic through the US VPN client I picked. If I want to connect to another streaming site, I want the router to direct the traffic to an alternate VPN client I set up. Any other traffic which is not geo-locked, must be sent through a general VPN client in my home country. Please point me in the right direction as I do not know how to set this up. BUMP
  • OPT1 to lan to wan

    3
    0 Votes
    3 Posts
    340 Views
    D
    @derelict OMG you saw it so quickly, thank you for your reply ! "beginner mistake" I don't want to pollute this forum, so you can delete this topic if you want, my problem was not really a problem in fact...
  • Multi-Wan IPV6

    12
    0 Votes
    12 Posts
    2k Views
    C
    @derelict doh' I knew it would be something as dumb as that! Jeez. Thanks a lot to everyone for your help. it works now :) !!
  • Multi-WAN, Multi-LAN, no failover, cross communication issues over WAN

    5
    0 Votes
    5 Posts
    748 Views
    F
    Sorry for the late reply, thank you very much for helping! In the end, it ended up being NAT reflection on the port forward being set to default instead of enabled. For whatever reason I assumed that this was on by default, I'll RTFM next time! After enabling that, I can now connect to LAN2 properly through LAN1 using the external WAN2 IP!
  • Delay or manual failback?

    5
    0 Votes
    5 Posts
    912 Views
    Z
    @derelict Ahh.. OK. Thank you! That was exactly what I was looking for! /Raj
  • Connect certain IP-ranges across multiple PFsenses

    2
    0 Votes
    2 Posts
    371 Views
    DerelictD
    Yes, it's possible, but I would not do it like that. I would put each pfSense on its own transit network, such as 10.1.10.0/30 for the link to the top pfSense and 10.0.10.4/30 for the link to the lower pfSense. You can keep them on the same network like they are if you want to, say, enable an OSPF area containing all three routers so they all know where to send the traffic without relying on hairpinning, ICMP redirects and other nastiness. Or maintain static routing tables pointing everything where it needs to go.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.