• MPLS ipSec Failover Confusion

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    K

    I tried policy based routing which worked on failure but never switched back :/

  • Routing multiple gateways

    Locked
    10
    0 Votes
    10 Posts
    5k Views
    O

    Thanks GF. You are correct vyatta needed to be told about the routes, so not the fault of pfsense at all. Very happy this is now working and traffic is flowing nicely.

    Thanks again!

    :)

  • Outbound Load Balancing and inbound port forwarding

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    marcellocM

    It will be 'statefull' for tcp and udp, keep sessions will work on both at pfsense.

    See via tcpdump at console how your VPN connections are 'flowing'.
    Open two consoles,one for each wan.

    Also test sessions To other services like dns or http for example.

  • Hello everyone static route 0.0.0.0 in snapshot 1.2.3

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    jimpJ

    Make it in the GUI. If you are on 1.2.3, just put the target IP in the 'gateway' field on the WAN interface page.

    If you are on 2.0, make the gateway entry under System > Routing, select it as default, and make sure it's also chosen from the gateway drop-down on your WAN interface page.

    You're really overcomplicating what is actually a very simple setting.

  • Load Balance 1.2.3 need help

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    K

    the 8.8.4.4 and 8.8.8.8 will work maybe you should put a static route which interfaces will be used to go in 8.8.4.4 and 8.8.8.8  :)

  • Help with port forwarding on PFSense VMWare.

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Load balance

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    S

    Anybody got any feelings on this?

  • Refresh Load-Balanced WAN Gateway

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    K

    it wouldnt help on setting them on different tiers?

  • 2 Wan combine to 1 Lan

    Locked
    18
    0 Votes
    18 Posts
    14k Views
    K

    Hey, i made a simple guide for everyone to follow on how to setup multiwan (2x wan 1x LAN).
    The guide assumes that you have already configured pfsense with both wans.
    it's so simple and beautiful.
    Step 1-3 sets up the load balancing.
    step 4 is about giving specific computers, or ports (services) direct access to only one of the WAN's - in other words, it won't be load balanced.
    This helps with certain webpages like facebook or very secure webpages.
    hope it helps

  • 0 Votes
    8 Posts
    3k Views
    P

    thanks also GruensFroeschli! you guys are great! i'll be learning more from all of you guys, just started the box a month ago.. :)

  • How to Check my Load Balancing is Working or Not?

    Locked
    10
    0 Votes
    10 Posts
    9k Views
    M

    You could post that problem here or open new topic

  • Is it possible to do outgoing load balancing?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M

    If you look your forum nick and under that is white box with search button next to it.
    please consider using that. Policybased routing is the term what you're searching at.

    And yes it can be done. just remember firewall rules work on ingress and top-to-down.

  • 0 Votes
    1 Posts
    973 Views
    No one has replied
  • Load balance nit-picks (post-success questions)

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    I have noted a high ping ms there - this is due a bit load. It can be as low as 20-30 and still 'fail' with 'correct' config'.

    Each GW is fed into a switch then to the pfSense box - no more than 3 feet total distance from each other, tested with different switch and routers - will sit at this figure under load.

    Pinging 74.125.230.100 (google svr) via a pc routed through the pfSense box will result in a 18ms ping.
    Pinging the same IP via pfSense diags results also in an 18ms ping
    Rather oddly - pinging a GW via the digs results in a 0.5ms ping - so why in the 70's range with the LB tool?

    More 'oddly':
    As I type this, I tried half/half. First 5 having unique external IPs to ping. The first being the pfSense gateway, 200, is now responding with a 20ms ping. The following 3 are 100% loss. The fifth 100% loss but 217ms ping.
    Last four 'live' as still pointing to themselves.

    Changing the pfSense GW to another IP makes the first in the list go offline - with 19ms ping.

    Some randomness, with some changing state with no correlation to ping ms.

  • 0 Votes
    5 Posts
    2k Views
    R

    @Metu69salemi:

    okay..

    What you want to allow that is something what you need to decide. But now i assume that you want to allow anything

    You may want create network alias to help out this rule(Firewall: Alias) goto your lan rule tab(Firewall:Rules:Lan) and create rule
    Action: Pass
    Interface: Lan
    Protocol: any
    Source: any
    Destination: Your newly created alias
    Destination port range: any
    Description: Write descriptive name

    all the advanced features isn't needed currently, if you don't need any scheduling, or different gateway etc

    Nope, nothing advanced, I just basically want the firewall to be absolutely transparent for everything on the LAN/WLAN side and to only really be active between the WAN and the LAN/WLAN.

    Does that make any sense?

    I'm running PFSense 2.0 now, if that makes any difference.

    So what exactly does a Firewall Alias do and why would I want to use it in this case? I'm just trying to understand the concepts that I'm using so I will be able to do this on my own next time.

    -RS

  • Route 2 Lans

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    D

    Hi, this is a simplied diagram. Bridge 172.16.0.3 are far far away from pfsense (its a PtP link with 172.16.0.2)

    net.PNG
    net.PNG_thumb

  • HTTPS TIMING OUT

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    pttP

    Or, if, you have problems with "sticky connections", can create a Failover GW group and use "policy routing" to direct all "problematic" traffic to that group, i think this approach is better than have all "problematic" traffic routed to one GW.

  • Static Routing / Bridging

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • How to use pfSense w/ Layer 3 switch running 5 VLAN / Subnets.

    Locked
    2
    0 Votes
    2 Posts
    6k Views
    A

    VLAN 101:  Switches, Firewalls Huh
    Network:  10.10.1.0 /24
    Switch IP: 10.10.1.1

    1. assume ur pfsense has wan ip x.x.x.b/zz and wan gateway is x.x.x.a/24 and lan ip is 10.10.1.10
    2. connect lan into access port belongs to VLAN101 make sure it is not trunk port
    3. create another gateway having ip 10.10.1.1 named LANGW
    4. create static route of 10.10.2.0 /24 using gateway LANGW I.E FOR ALL OF YOUR VLAN
    5. open firewall nat click Manual Outbound NAT rule generation and SAVE
    6. after generating automatic rule add similar rule for all vlan networks

    hope u will get internet from lan
    let me know

  • Gateway Weights?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    M

    Looks like it.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.