• IPv6 Routing

    2
    0 Votes
    2 Posts
    173 Views
    johnpozJ

    Are you just pulling those IPs out of thin air?

    That first one is a peering network.. And the other one is securebit de company.

    If you don't have valid IPv6 to use - then use ULA.. .Or get a /48 from HE for free to use..

  • FRR BGP Routing & Subnetting

    1
    0 Votes
    1 Posts
    104 Views
    No one has replied
  • Selected devices through VPN

    3
    0 Votes
    3 Posts
    199 Views
    B

    @Rico Thanks

  • IPSEC vpn fails on Dual Wan Multi Lan after failover and restore

    1
    0 Votes
    1 Posts
    65 Views
    No one has replied
  • wireguard gateway - how to remove need for double NAT

    3
    0 Votes
    3 Posts
    2k Views
    S

    Hi there,
    Yes, I did resolve this in the end. The key for me was Static Routes on the Wireguard Gateway VM on my local network, I also set a static route on the Endpoint to send any traffic with my LAN IP addresses back over the wg interface.

    I didn't realise that if you set your wgx.conf to use AllowedIPs= 0.0.0.0/0 it forces ALL traffic over the wireguard interface, so returning traffic never gets back to the client that initiates the connection.

    Anyway, a picture is worth a thousand words, and see my updated diagram here. Apologies to the Network Engineers out there. I'm not a pro, so I guess my diagram is pretty amateur! It serves it's purpose for me as documentation though :)

    In the pic, you can see the routing table on the WG Gateway VM and the WG endpoint. The routes in Green are the ones I added manually, and it all works like a charm now. Also, note the MTU thing, that caused me no end of grief, so if you have issues with SSL handshakes failing and other random stuff....check your MTU.

    WireguardPublic3.jpg

  • 0 Votes
    13 Posts
    1k Views
    DaddyGoD

    @ihrewerbung said in How to Multi-WAN setup as Loadbalancing and route all traffic over VPN-Provider like mullvad?:

    Maybe a Floating rule would be another workaround?

    worth a try 😉

  • Interface Groups and Multi WAN

    6
    0 Votes
    6 Posts
    499 Views
    noplanN

    @viragomann

    group of internal networks no problem
    directing traffic to a different gateway than default
    brNP

  • Load Balancing multi-gigabit ISP connections?

    20
    0 Votes
    20 Posts
    2k Views
    E

    Hi All!

    Just to give an update to this, I moved my setup to a newer beefy server and I am now able to download upto 170Megabytes per seconds.

    I did not do anything special, I just migrated PFSense to our new beefy server as a virtual machine and now I'm very happy as ever.

    e983830f-0577-4b29-9620-020beb55b683-image.png

    Thank you all for responses!

    Consider this solved until 10Gbps is available in our location, that is to another milestone.

  • Linux Transparent Proxy as Gateway for domain based routing

    1
    0 Votes
    1 Posts
    148 Views
    No one has replied
  • pfSense using VPN gateway instead of WAN

    5
    0 Votes
    5 Posts
    1k Views
    I

    @Lanna Lanna thanks for the advice I tried that but it wasn't it.

    After digging around for almost a month here.

    I found the issue!
    VPN Server from Private Internet Access (PIA) created a route 0.0.0.0/1 when the interface is created.

    In OpenVPN client I had to select "Don't pull routes" and it no longer makes that route. pfSense 127.0.0.1 now properly goes through the default Gateway.

  • 0 Votes
    2 Posts
    295 Views
    JeGrJ

    @maartenv said in Can pfSense receive LACP over incoming dual WAN connections. Is that possible?:

    Or are there other solutions possible?

    Probably, depends on wether you have the possibility or want to put a device in another location and probably add some latency to the connection. But you could host another e.g. pfsense instance in another location or in the cloud, point your webserver DNS name to that and there use HAproxy to add both IPs of the external webserver IPs as loadbalancer/failover configuration so that would utilize the redundant internet connection. A bit like CDN services.

    That would also be another possibililty: put a CDN service (or sth alike) in front of the webservers, add your rendundant IPs to your webserver to them and have them utilize it.

    But this means that pfSense must also be able to receive LACP over the incoming WAN connections but I can not find a way to do this in the webgui. Is there a way to do this as in the Interfaces/LAGGs configuration screen the WAN interfaces are not shown.

    Should be pretty straighforward if a bit unusual: just add both physical interfaces that are pairs of the LACP bond to a LACP-type LAGG (interfaces/assignment -> Link aggregation / LAGG) and instead of configuring your WAN on the phys interface, use the newly created lagg0 interface.

  • Public IP's on DMZ interface over WAN-link or OpenVPN tunnel

    2
    0 Votes
    2 Posts
    179 Views
    M

    UPDATE: Solved

    Problem was solved, main issue was OpenVPN Main interface catch-all rule

    If anyone is interested in this thread let me know to provide a tutorial

    Thank you
    Regards
    Mike

  • Where can I enable "default gateway switching"

    3
    0 Votes
    3 Posts
    2k Views
    M

    Thank you very, very much.

    I did not know some of the Netgate documentation was outdated, so in order to prevent this kind of misinformation, I immediately downloaded the latest pfSense Documentation dated Sep 28, 2020 from here https://docs.netgate.com/pfsense/en/latest/index.html

  • Weird asymetric routing issue [solved]

    18
    0 Votes
    18 Posts
    1k Views
    M

    @viragomann Awesome, thanks again !

  • pfSense being client and being gateway for a DMZ subnet

    13
    0 Votes
    13 Posts
    2k Views
    M

    No problem, come back if you have further issues 😉

  • How to get historical data on load balancer performance, uptime etc

    1
    0 Votes
    1 Posts
    75 Views
    No one has replied
  • Failover from cable to cell modem with failback - example

    5
    1 Votes
    5 Posts
    650 Views
    P

    @Rico - As far as I can see PFsense built in features as presented handle failover reasonably well. But failback on an expensive and data capped service like CELL is not well supported. The script I am using is a necessary hack because of this.

  • OPT1 Interface Up, Gateway Down

    5
    0 Votes
    5 Posts
    498 Views
    R

    problem was on the provider side. I called back again and they were able to see the issue. Everything is functioning like we expect now.

  • Failover does not work

    22
    0 Votes
    22 Posts
    2k Views
    DaddyGoD

    @Raffi_ said in Failover does not work:

    Let's just call it the poor man's monitoring solution :)

    I understand

    I am lucky, -enough to work as a freelance "IT guy" for companies that entrust me with their supervision, of course then I also "run" my own things as these things are entrusted to me

    so at their expense, I also get private resources...
    I think this is called "symbiosis" in biology, hihihihi - I hope so

    in my reading this is the monitoring solution 😉

  • Dual Wan Dpinger Errors Every 10 Minutes

    3
    0 Votes
    3 Posts
    609 Views
    H

    probably something is triggering a restart of dpinger

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.