The solution is ;
You need to make and allow the rules for interface OPT1 to LAN interface, set your destination (all MPLS network)
Create a gateway for OPT1 and do a static route for each MPLS network.
Hi Karl, I'm also from the Philippines and been using pfsense for several years now.
I'm not sure with your first question but for the second question, you can definitely use IDM or torrent downloading to achieve the combined speed of both connections for downloading one file. You are right that they use multiple connections so they will use both WAN links when you're downloading as long as you setup the firewall correctly.
Ow… Ok, just understood. Specifying timeout and saving isn't enough.
So, FYI, if needed : need to uncheck "use sticky connections", save, recheck "use sticky connections" and specify timeout, then save.
Works nicely now 8)
Glad you were able to get it to work at least once (don't you hate it when that happens) :P
My only suggestion is to try and start with simple scenarios (take things apart to simplify if necessary) and then add complexity till it breaks ;)
Good luuck and let us know how it works out.
@adambmedent:
Thinking about this more. How do you guys connect a single ISP handoff to 2 pfsense machines configured in HA. Currently all of my ISP's hand off a single ethernet connection.
I am hoping my ISP's can siply enable another port on their ONT/switch which I can run to the secondary pfsense box.
I was thinking implementing a switch after our ONT would be a single point of failure. After some thought I realized BGP would detect the link as down and fail us over to the other circuits. So a switch after our ONT shouldn't be a big deal.
Now I just need to decide if I want to do a carp based hardware HA or virtual HA. Carp seems to have its advantages, but its a completely new concept for me.
I was thinking if routing would do the trick, if there something can be done to reroute the traffic from the HQ default gateway to the AD gateway vice versa.
thanks