• Stupid multi WAN-question

    4
    0 Votes
    4 Posts
    1k Views
    H
    you can, but unless both ends are "aware' this is how it should be;  it'll result in a broken communication
  • FTP connection with multi-wan and Squid

    8
    0 Votes
    8 Posts
    1k Views
    M
    you mean i should add a Rule under LAN with following settings Protocol    Source      Port    Destination    Port    Gateway Ipv4          LAN net      any    any              21      WAN1 but is not working
  • 0 Votes
    8 Posts
    3k Views
    M
    @rba: I first recognised the ftp client problem at an event installation. As soon as I have a configuration with two WAN connections again I will try the FTP Client Proxy package. luckman212: Thanks for the hint. and ?
  • Policy Based Routing - Internal Firewall

    2
    0 Votes
    2 Posts
    491 Views
    H
    draw a schematic of your network so all of us understand what it is you want to do. trying to explain a network layout with words is hopeless ;)
  • DMZ with Public IP

    1
    0 Votes
    1 Posts
    757 Views
    No one has replied
  • Static routes and multiwan

    5
    0 Votes
    5 Posts
    1k Views
    P
    There are no downsides I guess, it's just pfsense behaviour that puts policy routing above static routing, which is the opposite on what happens in fortinet units for example. It's just a matter of what you're used to :) Thank you, have a nice day!
  • Advertising Default Route RIP

    2
    0 Votes
    2 Posts
    994 Views
    N
    I'm starting to believe that the routed daemon in pfSense has some stripped functionality. Even if I use these examples root@localhost: routed -g ~ routed -F 0/0,1 Adding fake_default=1 to /etc/gateways No default route is sent out. If I try to do something like adding this to /etc/gateways net 0.0.0.0 gateway 172.22.0.14 metric 1 active I get a bad net message saying I can't have that as the default route which is confusing as I can find a few people that have used something like that as an example or in lab scenarios. Seriously how hard can it be to get a default route to go out correctly? This is easily implemented most all other mainstream firewalls such as Juniper or Cisco firewalls. For example Cisco has the 'default-originate' option in it's RIP settings as well on most IOS UI's - same goes for Juniper.
  • Dual link and multi IPs

    1
    0 Votes
    1 Posts
    365 Views
    No one has replied
  • Multi-WAN using Cisco Sw VLAN for Single Pfsense NIC

    1
    0 Votes
    1 Posts
    476 Views
    No one has replied
  • Unconnected PPPoE does not always failover.

    1
    0 Votes
    1 Posts
    517 Views
    No one has replied
  • 0 Votes
    1 Posts
    544 Views
    No one has replied
  • Multi-WAN problems with proxy

    7
    0 Votes
    7 Posts
    1k Views
    D
    @Karakaraza: I want to ask the same to you. No, nothing changed in past 3 days. It still does not work…  ::)
  • Multi-WAN + CARP, moved VPN tunnels to new WAN, strange routing issue

    2
    0 Votes
    2 Posts
    476 Views
    D
    The answer was indeed outbound NAT rules needed.
  • [SOLVED] Multi-WAN with specific gateway for some ip

    2
    0 Votes
    2 Posts
    713 Views
    S
    Solved. The rule wasn't the first one in the firewall, so it wasn't effective.
  • Routing Multicast to a GRE tunnel using IGMP Proxy

    8
    0 Votes
    8 Posts
    3k Views
    D
    Perhaps ask someone who's using it on the other thread…
  • Static route with interface

    6
    0 Votes
    6 Posts
    2k Views
    K
    Hi Thanks, i did'nt know about packet capture inside Pfsense. Great tool. 16:11:59.654405 00:0c:29:4f:xx:xx > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: (tos 0x10, ttl 128, id 0, offset 0, flags [none], proto UDP (17), length 328)     185.45.xx.xx.68 > 255.255.255.255.67: [udp sum ok] BOOTP/DHCP, Request from 00:0c:29:4f:bf:8a, length 300, xid 0x713f4345, Flags [none] (0x0000)   Client-Ethernet-Address 00:0c:29:4f:xx:xx   Vendor-rfc1048 Extensions     Magic Cookie 0x63825363     DHCP-Message Option 53, length 1: Request     Requested-IP Option 50, length 4: 185.45.xx.xx     Client-ID Option 61, length 7: ether 00:0c:29:4f:xx:xx     Hostname Option 12, length 7: "pfsense"     Parameter-Request Option 55, length 9:       Subnet-Mask, BR, Time-Zone, Classless-Static-Route       Default-Gateway, Domain-Name, Domain-Name-Server, Hostname       Option 119 16:11:59.770129 e0:97:96:a2:xx:xx > 00:0c:29:4f:xx:xx, ethertype IPv4 (0x0800), length 342: (tos 0x0, ttl 63, id 50246, offset 0, flags [DF], proto UDP (17), length 328)     172.16.100.xx.67 > 185.45.xx.xx.68: [udp sum ok] BOOTP/DHCP, Reply, length 300, hops 1, xid 0x713f4345, Flags [none] (0x0000)   Your-IP 185.45.xx.xx   Gateway-IP 172.16.102.xx   Client-Ethernet-Address 00:0c:29:4f:xx:xx   Vendor-rfc1048 Extensions     Magic Cookie 0x63825363     DHCP-Message Option 53, length 1: ACK     Server-ID Option 54, length 4: 172.16.100.xx     Lease-Time Option 51, length 4: 150000     Subnet-Mask Option 1, length 4: 255.255.255.255     Default-Gateway Option 3, length 4: 185.4.79.254     Domain-Name-Server Option 6, length 8: 178.250.xx.xx,178.250.xx.xx I am going to get some full wireshark log at up and down time and try to find some clue..
  • Multiple locations and MultiWAN Failover

    7
    0 Votes
    7 Posts
    1k Views
    T
    You may have a double-NAT situation.  I don't have as much time as I'd like to dedicate answering your question, but IMHO I would look at how you can create a route to the failed router traffic across that link and then directly out the WAN2 link w/o NATing.
  • 0 Votes
    5 Posts
    975 Views
    R
    still no luck sir. ill give a scenario . when we log in to our mail server(via web) the IP our mail server reads is the Wan1 then after a sec we got rejected because the returning ip is our Wan2.  Thats why i wanted only port 80(http) only on one Wan1 back and forth
  • One WAN Interface Multiple IP Subnets

    2
    0 Votes
    2 Posts
    618 Views
    T
    https://doc.pfsense.org/index.php/What_are_Virtual_IP_Addresses pfSense gets assigned one address on its WAN port.  From there you assign VirtualIPs using the additional IP addresses your ISP gave you.  Set them up as IP Aliases and they should be on a /32 subnet. Oh, wait, you have two different gateways.  Not sure this is going to work.  I added another physical NIC to achieve this, plus I wanted physical separation of the WANs.
  • Split ports from LAN to multiWAN

    2
    0 Votes
    2 Posts
    503 Views
    T
    Yes, it is possible. I think what you want to do is set up policy-based routing.  This will allow you to direct traffic to an interface based on a set of rules (policies), such as IP address, port, or protocol. Additionally, pfSense has advance capabilities such as QoS (Quality of Service) that can prioritize one kind of traffic over another.  So you could eventually use both WAN ports as either a load balanced pair or a failover pair, and ensure that your VOIP traffic has the highest protocol priority, and that would ensure the quality of those connections. It can do a lot, and you'll eventually see the value of some of these other features as you implement them.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.