• 8300 in HA with dual WAN and BGP

    4
    0 Votes
    4 Posts
    615 Views
    M
    @padrino121 Drop the WAN circuits on a switch will work as far as not having to physically go on site but unfortunately the FRR configuration still requires manual intervention. 8300s is expensive gear. I would follow up with sales and see if they can provide a better solution. The money you paid it’s really unacceptable that there is this level of shortcomings especially with something so basic
  • pfSense dropping PPPoE following update from old version

    8
    0 Votes
    8 Posts
    2k Views
    F
    This was too disruptive to the client to troubleshoot this further. We sent someone out to do a clean install of 2.7, then load the config back in. No issues since.
  • Can't ping 8.8.8.8 or google.com

    5
    0 Votes
    5 Posts
    696 Views
    GertjanG
    @duvel said in Can't ping 8.8.8.8 or google.com: I would rather select TCP/UDP & ICMP than allow Al This works just fine, and is the default : [image: 1737443548632-828b4fd3-e69a-4749-9271-5aa975251d92-image.png] because you don't trust the other 252 ?:
  • netgate 2100 wan2 w/ DHCP - no joy... yet

    2100 vlan dhcp opt1 for wan2 gateway
    4
    0 Votes
    4 Posts
    2k Views
    N
    @chrisjx Hi, I also have a location with two ISPs, one is the primary and the second is a Starlink. So I know how to setup the LAN4 as a OPT and assigned VLAN 40 to it. But how do I make sure the Starlink is on VLAN 40 then? Did you managed to get this working? BR Nick
  • Intermittent Network Drops pfSense

    17
    0 Votes
    17 Posts
    2k Views
    JonathanLeeJ
    @manjotsc great job finding the issue, I had this machine that had a line on the monitor once, guys before me replaced the monitor the cable, I got there and took the cpu off it had a bent pin no lies reseated it or got a new one I can’t remember but that fixed the issue, it is amazing I didn’t understand why everything else worked, one pin caused the issue, also over doing heat compound can cause issues when it gets on pins.
  • 0 Votes
    3 Posts
    324 Views
    J
    @Bob-Dig Because I still saw all the traffic still going out my WAN1 interface and my WAN2 interface is idle.
  • Trouble Bringing up WAN Interface

    1
    0 Votes
    1 Posts
    289 Views
    No one has replied
  • Multi WAN with a DHCP-client interfaces

    4
    0 Votes
    4 Posts
    591 Views
    G
    @0x010C LAN should typically NOT show up as a gateway in that list... You can have a gateway in the LAN segment, like a standalone VPN server or similar. In that case you set up a static route to it though... Are you saying that C automagically became a default gateway when you created it? Have you tried changing the default, saving and changing back again? Also, under gateway group you can create like a failover group, using A, B and C, and setting A to Tier 1 and the others at some higher Tier 2 and 3. Then use this group as the default gateway. All normal traffic wil then go through A, unless A is down. All policy routed traffic will go as per the policy... through B or C.
  • Pfsense cannot port forward to Layer 3 switch

    6
    4
    0 Votes
    6 Posts
    807 Views
    johnpozJ
    @totalimpact said in Pfsense cannot port forward to Layer 3 switch: having static routes requires a gateway on the Transit network. Not on the interface - you create a gateway to the IP on the transit network, but you don't actually put that gateway on the interface of pfsense on the transit.. Or pfsense thinks a wan interface and creates an outbound nat on it. You create the gateway in the routing gateway section not on the specific interface. [image: 1736289218329-pfsense-layer-3-switch.png]
  • IPsec routing problem

    14
    0 Votes
    14 Posts
    1k Views
    G
    @seanr22a said in IPsec routing problem: I have three web sites including Nextcloud on the server at siteB and they are behind Cloudflare CDN (free version). I use an Apache reverse proxy at siteA now to get around the port blocking issue (Sending the traffic over the IPsec to the server at siteB). The ping time is around 230ms and I get around 10Mb up and 45Mb down from siteB to siteA. I spend most of my time in Thailand so the speed I get here is most important. I get the Proxy setup, that's what I use to access my NextCloud server, as well as my Homeassistant and some other stuff. I just happen to use Nginx. But I'm not sure I understand how Cloudflare CDN fits into this setup that you have? If you host your server at your home in Thailand, and you access it via Sweden using some DynDNS service to find your Swedish IP, then you go directly via the VPN to site B. Where does Cloudflare come into play? And I'm curious, which ISP is it, and which ports do they block? And what ports don't they block? I've seen that many users say nginx is faster and use less resources but in my very small setup I really don't think it matters. I agree, probably wouldn't make a noticeable difference if you changed. If you are curious however, and use docker, it's actually super simple to set up and has a very intuitive UI... BUT, what could potentially improve performance quite a bit is if you change VPN to Wireguard. Depends on what HW you run pfsense on of course, but on smaller machines I can see a real difference even at moderate speeds. I have a site with pfsense running on a tiny PC Engines APU2 and I can saturate the 250 Mbit connection to that site over Wireguard. But on an IPSec connection I can perhaps get 80-90 Mbit when testing with e.g. iperf or openspeedtest.
  • Failover WAN being used with Primary is still up

    9
    0 Votes
    9 Posts
    1k Views
    S
    Looks like this is starting to happen again. However it is limited, only some traffic is being routed over the backup connections.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    10 Views
    No one has replied
  • What is wrong with my routing?

    12
    4
    0 Votes
    12 Posts
    1k Views
    D
    @patient0 said in What is wrong with my routing?: fgrep 62.155.245.31 /cf/conf/config.xml shows no (=empty) output but a 'cat /cf/conf/config.xml' reveals that the version of the config file (line 3) is "23.6".
  • ISP with two HSRP link (active/passive)

    1
    0 Votes
    1 Posts
    203 Views
    No one has replied
  • Network Topology How to set up redundancy

    7
    1
    0 Votes
    7 Posts
    739 Views
    LaxarusL
    @johnpoz well, yeah unfortunately. I was looking to strengthen my current setup but it seems there is nothing I can do for now.
  • MultiWAN with P2P connection

    1
    0 Votes
    1 Posts
    155 Views
    No one has replied
  • Switching upstream Modem into Bridge mode blocks PfSense

    7
    0 Votes
    7 Posts
    783 Views
    chpalmerC
    Make sure when you are switching devices behind the modem that you hard reboot the modem as it will stick to one MAC address at a time.. when it is not in bridge mode it becomes that one MAC address by itself so you don't have to worry about the reboot process. But in this case pfSense is the router and the interface of your win needs to be that MAC address..
  • When specifying an exit gateway, the ipv4 route is empty

    3
    2
    0 Votes
    3 Posts
    263 Views
    yon 0Y
    @Bob-Dig I am not said wireguard, i am said the WAN.
  • Running Services from ISP Residential connection

    3
    0 Votes
    3 Posts
    301 Views
    T
    @tgl I looked into that. They combine TV and Internet service and the non-residential TV service sucks. That's why I went this way. At present, it is only personal playing with software development and the extra expense was not warranted for having 2 internet services.
  • Dual WANs: disable default gateway and route without policy routing

    2
    0 Votes
    2 Posts
    291 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.