• HA, gateway groups and firewall's default route.

    11
    0 Votes
    11 Posts
    656 Views
    M

    @viragomann said in HA, gateway groups and firewall's default route.:

    Is it this, why you were looking for localhost?

    Not OpenVPN, but the outbound connections from the firewall itself.
    In the documentation, localhost should be 'NATted' to interface IP address, which is OK, this part is clear to me.

    What wasn't clear to me is if I should have created a new gateway group, using Interface address, to use as the default route of the firewall.

    However, since it doesn't translate anything and everything is working, including IPsec, I'll leave as it is right now, everything using the same gateway group, that has the CARP IP there.

    Note that without those CARP IPs in the gateway group, IPsec tunnels won't go up.

  • WireGuard Zugriff auf Fritz!Box

    6
    0 Votes
    6 Posts
    307 Views
    N

    Gut, denn das sollte einfach so funktionieren, wenn die IP der Fritz im Netz liegt was durch den VPN Tunnel geroutet wird.
    Also Route in die Fritz mit Ziel pfSense für das gleiche netzt und auf geht es.

  • Not Getting IP Address from Cable Modem

    12
    0 Votes
    12 Posts
    1k Views
    M

    @Dobby_ Yes, this is how we are setup. There is not a static IP address, but the cable modem assigns an address to the WAN port on the pfsense router through DHCP. This has been stable for several years before it suddenly stopped working and showed an IP address of 0.0.0.0. Since MAC spoofing solves it, I think the cable modem or ISP is somehow locking the old MAC address and excluding it.

  • Multiple local networks with multiple vpn connections

    1
    0 Votes
    1 Posts
    97 Views
    No one has replied
  • 0 Votes
    1 Posts
    116 Views
    No one has replied
  • 2 gateways showing identical IP ?

    6
    0 Votes
    6 Posts
    264 Views
    M

    @madbrain I rebooted one more time, and the problem went away - Verizon gateway no longer showed. Very strange. It's an intermittent problem.

    I decided to remove the USB Realtek 8156B NIC, and replace it with a PCI-E Intel I-225V (B3) that I bought at Central Computers earlier today. This necessitated shutting down the machine to insert the PCI-E card.

    During the next boot, this is what the interface assignment screen looked like (MAC adresses omitted) :

    58150e9e-53b2-46dd-81e9-09f2c62e0d3d-image.png

    As you can see, both the Comcast and Verizon interfaces are assigned to the same ix0 network port. Previously, Verizon was assigned to the ue0 network port for the RTL8156B. That port no longer exists since the USB NIC was unplugged. It is a bit disconcerting to see two interfaces on the same NIC, to say the list. Not sure what the right behavior should be, though. Maybe have the interface be unbound (no network port) ?

    So far, I am not seeing the same issue with all 4 Ethernet ports using Intel NICs (motherboard 1 Gbe, X550-T2 2 x 10 GBe, I225-V (B3) 2.5 Gbe), but it's only been a few minutes.

  • using 2nd public IP subnet

    3
    0 Votes
    3 Posts
    169 Views
    G

    @viragomann perfect - thank you for the response

  • LAN traffic to Staging page?

    1
    1 Votes
    1 Posts
    88 Views
    No one has replied
  • Direct web browser access to device on OPT2?

    1
    0 Votes
    1 Posts
    98 Views
    No one has replied
  • Routing to another subnet through new gateway inside the server's network

    2
    0 Votes
    2 Posts
    145 Views
    V

    @ssppcc
    You just need to add a static route for the docker subnet.

    So in System > Routing > Gateway add a new gateway within the server network with the IP 10.0.200.8.
    Then go to the Static routes tab and and a new static route for 10.31.0.0/16 and state the gateway you've created before.

  • Force gateway group NOT to fail back

    5
    0 Votes
    5 Posts
    283 Views
    D

    @Gblenn I teach daily, days and nights so my occurrences are likely more visible. Typically, it fails over to Tier 2 and often is unnoticable. (I find out later looking at logs.)
    However, on this latest instance, the Tier 1 was flapping and zoom reported my connection was unstable. Students reported poor audio and video. It was only resolved by changing the backup to Tier 1 and restarting zoom. Later that night my main connection stabilized. so naturally I'm thinking it is trying to switch back as soon as Tier 1 is available. I will test to verify.

  • PfSense HAProxy certificate export import

    57
    0 Votes
    57 Posts
    6k Views
    V

    @viragomann

    I’ll work on that and some spare time

    Another quick question from another Bundoo machine and two other windows machines I’m not able to get a SSL connection to the Qnap machine even though I imported the CA certificate into the browsers this goes for chrome and Firefox getting a machine reboot cleared cookies and data from browsers. Any suggestions on this one?

    Thank you,

  • Pfsense port forwarding across Wireguard VPN - Asymmetric routing issue

    3
    0 Votes
    3 Posts
    1k Views
    Tom5051T

    @viragomann

    I figured it out in the end.
    The guide I followed to setup the site to site wireguard tunnel specified not setting the upstream gateways on the tunnels and using static routes to avoid double nat.
    It also stops reply-to working correctly.

  • How to force a client to only have access to WAN1?

    4
    0 Votes
    4 Posts
    233 Views
    M

    @SteveITS Indeed that was the issue! You're a legend mate, I've been struggling with this for almost a week now, whats even worse is that I scoured the docs and still somehow managed to miss the bit you highlighted for me 🤦‍♂️

  • Route subnet through VPN Client - Outbound NAT

    10
    0 Votes
    10 Posts
    728 Views
    U

    @viragomann
    Super - and thanks for the patience ✌ anf final explanations

  • Allow IPs on another subnet straight to the WAN gateway

    34
    0 Votes
    34 Posts
    3k Views
    T

    @Troniclab sorry, correction: both subnets are /24 ;-)

  • Assigning new gateway for vlan client does not work

    3
    0 Votes
    3 Posts
    235 Views
    A

    @SteveITS
    no they are internal networks.
    i want to redirect all traffic from one client to use another route.

    this used to work in previous days.

  • Assigning new gateway for vlan client does not work

    1
    0 Votes
    1 Posts
    114 Views
    No one has replied
  • Pass rules for WAN2

    8
    0 Votes
    8 Posts
    307 Views
    V

    @madbrain
    Firewall > NAT > port forwarding

    You have to add these rule manually.

  • Frequent packet loss / latency on WAN connection.

    1
    0 Votes
    1 Posts
    88 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.