phil.davis
late reply but i upgraded to 2.1.3 and the gateway for PPPoE WAN still says Pending even though i can ping from DSL connection using the ping app.
any ideas ?
Thanks for the tip, sounds a bit complicated.
We are actually looking for a way to let a non tech user do the switch over, perhaps via command file or some kind of app.
We are windows programmers, we can create something as long as we are able to trigger the right functions via the http or some other interface.
Lex
@cheonne:
@shms:
@cheonne:
hi shms,
1. create an alias for these ports 550 and 17759, and name it skype as an example
2. create a lan rule:
protocol: specify what protocol that ports uses
source: single host (just type the ip of that PC - assuming that you add ip_mac binding in DHCP)
destination port: to & from: others then specify the alias name in the red box
gateway: wan2
hmm doesnt seem to work, http://i.imgur.com/vR1Pk3d.png ?
put that rule below "anti-lockout rule"…2nd to all rules
didnt work either :/ however i can make that computer use wan2 with specified port *, but then it uses that wan for everyting :/
Have you created a gateway group? System, Routing, Groups, add both gateways to the group. Go to firewall rules, LAN, edit the default rule, and under advanced, choose gateway, and set it to the gateway group.
@BBcan17:
@waldopulanco:
thanks you so much! how about in gateway for wan2? If I want to select my wan2 gateway in firewall rules: lan? because wan1 is for browsing, streaming and downloading, and wan2 is for online games..
You don't need to set a WAN2 Gateway as it is using the same gateway as WAN1.
You need to configure the OUTBOUND NAT for the IP address of the LAN computer that you use for gaming, and add the PORTS to the NAT Rule so that when pfSense sees the Lan address going out a certain port, it will use the WAN2 address.
You might need to add Port Forwards (Inbound) depending on the Game application.
You don't need to edit the Firewall Rules for that.
Thanks! I will try it!!
I'm also struggling with OSPF. A proper "HowTo Guite" on Quagga would be nice to read.
I have experience with OSPF on cisco but seem not to be able to get it proper configured on pfSense.
If you have info or links, please share them.
I try to connect my Cisco Homelab to have internet access.
The lab can ping every host in my local network and on other site-2-site-vpn network witch also runs ospf.
My ISP IP is present in the routing table but I think a ping request can not "leave" the pfsense-box.
So I think there is no NAT going on between the pfsense-box and the ospf-network.
If anyone has suggestions.. please let me know. Thanks!
https://forum.pfsense.org/index.php?topic=72393.msg395001#msg395001
From:
System –> General Setup
In addition, optionally select the gateway for each DNS server. When using multiple WAN connections there should be at least one unique DNS server per gateway.
I finally figured this out. So for anyone else that might be looking to accomplish the same thing, here is what I had to.
Open the web interface and click on Firewall > NAT.
Click on the Outbound tab.
Tick off the option for Manual Outbound NAT rule generation (AON-Advanced Outbound NAT). Click Save.
Find in the list Auto created rule for OPT1 to WAN. Click the plus (+) on the right. It will say: "add a new NAT based on this one"
You should now have a new rule that says OPT1 instead of WAN. Edit that rule and set it to use Protocol of Any. Source should be changed to the type Network. Destination should be set to any.
Save and apply all changes
Next click on Firewall > Rules > OPT1
Here you just need to enable the rule to allow traffic.
Hope this helps someone. Goodluck.
On the WAN rules, I edited the rule as suggested
IPv4 TCP/UDP * * OPT1 net * * none
Still nothing. It's as if pfsense doesn't know where to send the packets. When I did a traceroute, that failed too. Have a lot to learn about this wonderful firewall, but feel as if OPT should have an ip address so that it can route to machines physically attached to it.
When I get this figured out, I will write a full "How To" on getting this working.
@Jason:
If you use policy routing (manually specifying the gateway on a firewall rule) then your pfSense box will not show in a traceroute.
That 10.125.x.x IP is the first hop off your network.
I'm not changing the default GW on any of my rules. This even happens when I try to traceroute from on pc connected to interface A to interface B. A and B are on the same pfsense machine.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.