• Static routes vs. OSPF - OSPF not routing to internet

    2
    0 Votes
    2 Posts
    811 Views
    5
    Wanted to provide an update to my own thread - after doing research it seems that OSPF will not create an automatic source/outbound NAT. So, it would seem that the "fix" would be to create automatic outbound NAT AND manual (hybrid mode), but this kind of defeats the whole point of OSPF. I could do a summary NAT, but then still, the benefit of OSPF would not be fully realized. Hrm.
  • Mark gateway as down and don‘t use it

    20
    0 Votes
    20 Posts
    3k Views
    DerelictD
    When that is the case it is customary to duplicate the steps to repeat the condition and report it, so the developers have something to work with regarding your specific set of circumstances. I understand it is a burden. Sometimes it is easier to just say, "it's a bug, fix it."
  • How to Access IoT device VLAN

    2
    1
    0 Votes
    2 Posts
    440 Views
    V
    You only need an outbound NAT rule for that. Firewall > NAT > Outbound If your outbound NAT is in automatic mode switch to hybrid first. Then add a rule: Interface: IoT Destination: 10.10.30.10 (the cam) Translation address: Interface address. Rules to allow access have to to be add to the interface where the connections come into pfSense, here it is the core.
  • unable to get to my multi static IP's from internal network.

    3
    0 Votes
    3 Posts
    573 Views
    DerelictD
    https://www.netgate.com/docs/pfsense/nat/accessing-port-forwards-from-local-networks.html
  • Connecting 2 sites

    11
    0 Votes
    11 Posts
    2k Views
    johnpozJ
    well yeah its simple copy there is no magic saying oh your copy me from lan net to opt net need to change the source.. Correct yourself. Change it to optX net or whatever you rename that opt net to be... I always change mine to something that makes sense to me. wlan net, dmz net, dtv net, etc.
  • gateway routing through 2 ipsec tunnel protocol based

    3
    0 Votes
    3 Posts
    552 Views
    L
    @jimp that's good news! I'm have researched looking for an solution and become here to post as last resort(because my english writing), fine both side are pfSense i'm happy to use it. While i will keep routing policy by hand a way statistically by adding hosts or networks according my needs. regards
  • Pass port traffic from home router > pfsense VM > gaming server

    8
    0 Votes
    8 Posts
    1k Views
    V
    Looks strange for me. That are only the states. Why don't you post packet captures, which are more informative.
  • Firewall Rules do not work with NAT unless default gateway is selected

    4
    0 Votes
    4 Posts
    649 Views
    S
    when I watch the states of one of the test servers, it looks like this: LAN tcp x.x.0.96:45922 -> x.x.0.50:80 (x.x.x.148:80) CLOSED:SYN_SENT 4 / 0 240 B / 0 B This shows up multiple times, but it still receives the same error. I am not seeing it go through the gateway anymore though (Instead of LAN it used to say the GW name)
  • Routing between multiple sites

    15
    0 Votes
    15 Posts
    2k Views
    DerelictD
    @amundae IPsec traffic selectors are not in the routing table because they are not routes. https://forum.netgate.com/topic/131420/routed-ipsec-using-if_ipsec-vti-interfaces
  • Sharing ethernet line with dedicated pipe for each company

    3
    1
    0 Votes
    3 Posts
    514 Views
    johnpozJ
    Yeah why not just use 1 pfsense, put your different companies on different networks and then just limit bandwidth or better just rate limit them at the switch level.
  • Remote access one subnet to secondary subnet w/it's own gateway

    7
    0 Votes
    7 Posts
    1k Views
    johnpozJ
    yes when you put hosts on a transit you have to route on them as well.. because hosts do not belong on a transit network only routers do..
  • Dual-path routing to the internal network?

    13
    0 Votes
    13 Posts
    3k Views
    N
    Having pf on vm's gives another layer of redunduncy, but thats another story. Maintaining one system does have its benefits (upgrades, troubleshooting etc) And routing the packets in and out of virtual interfaces does consume unnecessary cycles. I can't tell if this has any measureable degradation whatsoever in any case. I do have second thoughts if that would work in the end, becauseit all boils down to a common routing table so traffic would never pass through the lans :(
  • Only Have IPV6 on Wan and IPV4 on Lan?

    1
    0 Votes
    1 Posts
    285 Views
    No one has replied
  • No PPPoE link in Loadbalance

    2
    0 Votes
    2 Posts
    508 Views
    No one has replied
  • vlan question

    12
    0 Votes
    12 Posts
    2k Views
    S
    It sounds like you do need the functionality of a managed switch. I recently went through this myself. I'm not a professional network engineer but I do understand networking reasonably well. I can help translate what the pros here are saying because I'm not one of these guys .. they know their stuff. What might help this discussion is to understand your needs a bit more clearly. How many VLANs do you anticipate? How many clients/ports do you need to support per VLAN? How are you running pfSense? Is it a Netgate appliance, home built, in a VM?
  • Multi Wan 4G Router DWM-312

    1
    0 Votes
    1 Posts
    301 Views
    No one has replied
  • Multi WAN with same gateway IP intereferes with balancing

    15
    0 Votes
    15 Posts
    6k Views
    N
    I can safely verify that in 2.4.3-RELEASE-p1 (current stable) works as it should One interface is left with the dynamicly selected monitor peer and the other pings a stable ip inside the provider (in my case the cluster ip of the main dns stack) If the provider changes her policy and blocks ping that would be an issue, but I think I can live with that. :)
  • Dual WAN failover due to DNS failure , possible?

    dns failover multi-wan
    1
    0 Votes
    1 Posts
    679 Views
    No one has replied
  • [SOLVED]Alternative to sticky connection option

    Moved
    2
    0 Votes
    2 Posts
    522 Views
    dotdashD
    Make an alias of sites that you don't want to load balance, then put a lan rule with the destination of the alias and point it to a failover group.
  • Minor bug with routing web interface

    Moved
    2
    0 Votes
    2 Posts
    372 Views
    R
    I wonder if this is a more prevalent bug that other people are noticing as well. I had something similar happen and I thought it was rather weird. At least the interface still shows and recognizes the gateway.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.