• BGP Route sharing between IPSec tunnels

    3
    0 Votes
    3 Posts
    599 Views
    A

    Yeah, that's already done. It works great with the Cisco CSR 1000v devices but I can't seem to figure out how to make it work properly within pfSense.

  • BGP: kernel arpresolve

    2
    0 Votes
    2 Posts
    672 Views
    R

    Were you ever able to figure out the cause of this?

    I'm experiencing the same issue.

  • Firewall Rules w/ Advanced Options: Gateway slows traffic

    1
    0 Votes
    1 Posts
    292 Views
    No one has replied
  • Unknown static route

    6
    0 Votes
    6 Posts
    726 Views
    DerelictD

    Yeah there must be something somewhere that doesn't clear that in certain cases. I have only seen the end result - never the actual event - and then only a couple of times.

    Glad it worked.

  • Website Access through IPSEC VPN

    6
    0 Votes
    6 Posts
    480 Views
    P

    The answer was indeed a missing NAT entry on the main offices Firewall.

    Tanks.

  • WAN ISP insists on DHCP for static IPs

    10
    0 Votes
    10 Posts
    1k Views
    V

    I got an idea from a reddit user:

    have a device on the network spoof the mac of your WAN interface and do a DHCP request on a schedule

    This sounds like it could work.  Could I use something like a packet squirrel that would run a script, every day it could spoof the required MACs, do a dhcp req, then go dormant until the next day?

    Since I have a switch on the WAN side to split the WAN to the two firewalls, I could just plug it into that switch.  It would pull all three necessary IPs once per day.

  • PfSense as a DHCP relay routing to the same subnet / network conflicts

    2
    0 Votes
    2 Posts
    503 Views
    johnpozJ

    Is this x.x.186 network public - why are you obfuscating it?

    Please draw your network.. Saying you have network A and network B doesn't tell us how you have it connected together.  Any router connected to another router should have a transit network, or more likely then not your going to have asymmetrical routing unless doing host routing on each device in what is the transit network.

  • Multi WAN Multi VLAN set up Internet working but ping not responding

    3
    0 Votes
    3 Posts
    565 Views
    S
    I have created Multi-Wan Gateway in pfsense

    Wan-1+Wan-2+Wan-3+Wan-4 = Multi-Wan default Gateway

    Then Vlans are created and assigned to the LAN interface

    -> Rules are created in each vlans as protocol ->  to destination ->any

    same vlans are created in an L3 switch and Trunk is configured to provide access to all the vlans All the vlans are routed to the pfsense firewall

    * The IP name server is the x.x.x.x(pfsense ip address) and the secondary dns is

    Now internet is working in all the vlans, I am able to access the pfsense firewall via browser from all the vlans. But there is no ICMP reply for the ping. No ping to firewall or any other sites. I am unable to download any package via wget. please help me out with this problem.

  • Unable to make routing(gateway) between interfaces.

    1
    0 Votes
    1 Posts
    258 Views
    No one has replied
  • 0 Votes
    1 Posts
    329 Views
    No one has replied
  • How to failover _quickly_?

    1
    0 Votes
    1 Posts
    332 Views
    No one has replied
  • 2 WAN, 1 LAN - IPTV

    2
    0 Votes
    2 Posts
    547 Views
    R

    Yes best would be separate vlan's.

    I think you also need to setup static routes on the pfsense box to route IPTV traffic to the separte interface. And default gateway to the internet interface.

  • Second LAN connection has no internet access

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD

    At least use hybrid if you need something special. Only place manual really makes sense is HA. And even then it's easier to leave it on auto until all the interfaces are defined then switch to manual.

  • 0 Votes
    1 Posts
    317 Views
    No one has replied
  • Two gateways, how to route?

    4
    0 Votes
    4 Posts
    835 Views
    P

    Like I said, it's just hypothetical, trying to understand some things.

    I usually build networks with only 1 router, and let the physical devices like switches, ap's and such be in a backbone network (vlan1) while the devices and clients are on other vlans. But what if I want to offload a modest router that is being used for some high throughput backups for example, by adding a second router just for that purpose.

    I guess transfer network would be a solution, yes. Will consider that in my scenario. Thanks!

  • Zabbix proxy to route via a specific gateway

    4
    0 Votes
    4 Posts
    426 Views
    R

    Ok found my solution,

    Go at the bottom and click on the advance options

    There add the following

    SourceIP=X.X.X.X

    AND THEN SAVE

    The X.X.X.X should be the ip address of the gateway via which you want the traffic to go out of

    Hope this helps someone.

    Rajbps

  • 0 Votes
    2 Posts
    351 Views
    DerelictD

    You might ask them to put that list on their webserver it a plain-text format. That way you could just periodically update a URL type alias from their site.

    Absent that, yes, you will probably need to keep the alias updated yourself.

  • MultiNetting the LAN interface?

    2
    0 Votes
    2 Posts
    596 Views
    DerelictD

    That sounds completely convoluted but you don't control NAT sourced from a specific network on rules on that network. You control them with Outbound NAT.

    The easiest way is to probably enable Hybrid mode then make a NO NAT rule for the public source addresses on that WAN address.

    There is no such thing as 'classic Multinet.' Putting tewo layer 3 networks on one layer 2 is something that should only be used to do something like transition to new addressing. It should not be used as a permanent solution to anything.

  • Policy routing troubles

    1
    0 Votes
    1 Posts
    405 Views
    No one has replied
  • 0 Votes
    11 Posts
    14k Views
    S

    ok i found the AS numbers for xfinity live tv

    AS7922

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.