• Resolved: Unidirection inter subnet routing problem

    8
    0 Votes
    8 Posts
    818 Views
    V
    As a workaround you may set up an SNAT rule for the AP. Maybe that's what also the USG did. I've seen this also on a Fortigate.
  • 0 Votes
    1 Posts
    564 Views
    No one has replied
  • Routing all traffic via VPN?

    2
    0 Votes
    2 Posts
    471 Views
    V
    Yes, you need a route on the client, but not static. The OpenVPN server can push the route to the client after the connection is established, when connection is closed the route is deleted again. To set this up go to the server settings and check "Redirect gateway". Ensure that there is an outbound NAT rule for the vpn tunnel subnet in place on pfSense with NAT address = WAN address.
  • Load balancing not working correctly upon reboot

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • 0 Votes
    3 Posts
    475 Views
    G
    Awesome! Thank you for your help! Now I just have to find out the IP Adresses for Steam and I'm fine :)
  • SG-2220 - VLANs on the WAN side?

    2
    0 Votes
    2 Posts
    434 Views
    DerelictD
    Yes. You can have VLANs on WAN going to an outside switch to two or more different providers. pfSense: vlan 100 vlan 101 Switch: tagged port vlans 100 and 101 to pfsense, untagged 100 to ISP 1 modem, untagged 101 port to ISP 2 modem. It will be functionally equivalent to having two different WAN interfaces. You will have to understand that powering off and on one of the modems won't trigger a DHCP renewal event on pfSense because the port will not go down from its perspective. You might have to release renew manually, etc, if that ever arises.
  • Rip over vpn

    1
    0 Votes
    1 Posts
    438 Views
    No one has replied
  • Need additional gateway failure detection

    3
    0 Votes
    3 Posts
    412 Views
    G
    Ping works fine claims it's up but it is qos limited normally 14mbps now 0.5 Mbps
  • Setting up another router behind pfSense

    6
    0 Votes
    6 Posts
    1k Views
    johnpozJ
    That would depend on the isp sure.. I know you can get a lowend vps for your vpn connection for like $15 a year..
  • Load Balance Outgoing Traffic

    3
    0 Votes
    3 Posts
    746 Views
    M
    That'll probably break your users' firewalls. If they send packets to xxx.xxx.xxx.xx1 and get a response from xxx.xxx.xxx.xx2, firewalls will block the response packet. Sounds like you need a CDN service or similar. I don't think pfSense can help you here.
  • Colo Active / Passive or Bridged mode question

    1
    0 Votes
    1 Posts
    333 Views
    No one has replied
  • External domain Mapping to Pfsense wan ip

    3
    0 Votes
    3 Posts
    465 Views
    R
    Dear all . .. Its works for me . It was my mistake to give proper name to my router as same as a.example.com . Thank you all 44 Mems read this post
  • Routing Public IP's With pfSense

    4
    0 Votes
    4 Posts
    698 Views
    johnpozJ
    Pfsense shines as your edge router/firewall - if it couldn't route public or was something you shouldn't do pfsense would be pretty freaking useless ;)
  • PFsense using 3650 for routing

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • 0 Votes
    1 Posts
    981 Views
    No one has replied
  • Juniper ex3300 layer 3 with pfsense

    12
    0 Votes
    12 Posts
    2k Views
    johnpozJ
    pfsense out of the box does not use forwarding.. So you changed to using the forwarder?  Or have unbound in forward mode - where are you forwarding? Can pfsense lookup stuff?  ie use the diag, dns lookup. Can clients query pfsense dns for say pfsense fqdn?  If using unbound and your coming from downstream networks you will most likely have to adjust the ACLs to allow for the downstream networks.  If using the unbound auto rules it prob only added your local lan network to the ACL..
  • Multi VPN and incoming traffic

    5
    0 Votes
    5 Posts
    584 Views
    D
    Thank you very much, it's work !  :)
  • Subnet routing

    2
    0 Votes
    2 Posts
    646 Views
    johnpozJ
    So are you natting because you state those are public IP.. If you want to hit the rfc1918 on that other box you would need to have a tunnel vs just a forward from the public. So what vpn did you bring up.  What tunnel network did you use?  Where is your routing table?
  • What a mess with DNS and multi WAN

    2
    0 Votes
    2 Posts
    723 Views
    johnpozJ
    I would think that unbound able to use outgoing your wans should all you should need.
  • Unable to get traffic to route down OPT1 / OPT2 - gateway won't ping

    1
    0 Votes
    1 Posts
    339 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.