• 4 WAN interfaces but within same WAN subnet

    14
    0 Votes
    14 Posts
    1k Views
    GrimetonG

    @toehl001

    https://forum.netgate.com/topic/60600/gratuitous-arp-from-virtual-ips/17

  • Flush states when primary gateway is online after failover

    4
    0 Votes
    4 Posts
    744 Views
    kiokomanK

    there are more info here
    https://forum.netgate.com/topic/84269/multi-wan-gateway-failover-not-switching-back-to-tier-1-gw-after-back-online/86

  • CARP + Multi Wan (Static and DHCP)

    1
    0 Votes
    1 Posts
    125 Views
    No one has replied
  • Outbound Nat Single Host Secondary Link

    3
    0 Votes
    3 Posts
    374 Views
    D

    thanks @viragomann works here!

  • One WAN. Two LAN's.

    7
    0 Votes
    7 Posts
    580 Views
    johnpozJ

    If your not worried about them talking to each other, since you have any any rules - what is the point of multiple segments in the first place? ;)

  • 0 Votes
    3 Posts
    328 Views
    B

    Fixed it! Yes, I did assign a gateway, however I was confused when I assigned it, because I thought it was the gateway IP of my interface, not the gateway of the internet service IP. Such a silly mistake! Spent all night on it trying to figure it out.

  • Minowboard reboot bug

    Moved
    21
    0 Votes
    21 Posts
    2k Views
    jimpJ

    That's the joke

  • Multi WAN and 1:1 NAT

    6
    0 Votes
    6 Posts
    537 Views
    DerelictD

    Pretty much comes down to usable subnet addresses -3 so a /29 on the interface has 3 addresses usable for HA services, a /28 has 11, /27 27, etc.

  • Question about Layer 3, 10Gbe and 40Gbe

    1
    0 Votes
    1 Posts
    119 Views
    No one has replied
  • XG-7100 / LoadBalancer / IPsec

    1
    0 Votes
    1 Posts
    179 Views
    No one has replied
  • newbie and default gateway settings

    1
    0 Votes
    1 Posts
    172 Views
    No one has replied
  • Failover gateway in a multi-WAN setup has odd packets

    8
    0 Votes
    8 Posts
    550 Views
    M

    I was able to find a solution to this problem with the help of Netgate admin expert (@stephenw10) advice, the trick was to force Unbound to use "localhost" for outgoing queries. Unbound, when it is configured to operate via localhost outbound gateway would use only the gateway currently chosen by the system (i.e. dictated by the failover rules). This allowed me to completely eliminate unwanted unbound DNS/DNSSEC traffic via an expensive SIM-based failover link.

    See more details in the following thread:

    https://forum.netgate.com/topic/150176/php-shell-has-gatewaystatus-but-why-does-it-report-all-gateways-as-status-none

  • Pfsense as a WAN to WAN Router

    1
    0 Votes
    1 Posts
    97 Views
    No one has replied
  • [Feature Request] WAN Gateway Monitoring

    1
    0 Votes
    1 Posts
    108 Views
    No one has replied
  • Fixed: ARP Table reporting routes for entire /22 subnet

    4
    0 Votes
    4 Posts
    396 Views
    johnpozJ

    that is still not a route.. But sure if device answers (your modem) for an IP on your network then it would show in the mac address table.

    Here I tried pinging a bunch of different addresses in my /23 and you can see them now in my arp table, with the mac address of my modem.

    arptablemodem.jpg

    If you had done some sort of scan of /22 then yeah you would of see mac address of your cable modem for all of the IPs.

  • SendTo 65 & MultiWan Failover

    1
    0 Votes
    1 Posts
    199 Views
    No one has replied
  • Strange routing with VTI and 0.0.0.0 phase 2

    3
    0 Votes
    3 Posts
    1k Views
    M

    It's similar, but different, since I am talking about the phase 2 selectors, not phase 1 counterparts.
    The point with phase 2 selectors on VTI is, that they should be ignored for routing. pfSense seems not to support defining routes just via a particular interface, but relies on the remote gateway IP that is derived from the phase 2 network. Consequently, the adjacent 0.0.0.0/0 "network" is parsed as the default route in my case. At least that's my theory.

  • Routing via a LAN client like it's a Gateway

    8
    0 Votes
    8 Posts
    3k Views
    N

    @johnpoz Sorry to bump this thread but I have related question. Does this downstream router need to be on its own network, or can it just stay on a VLAN different from the clients I need to route?

    Let's say I already have a SERVICES VLAN, none of the hosts on this VLAN will be routed via this Wireguard gateway. Would placing this downstream router on this VLAN solve the asymmetric routing issue you explained?

  • 0 Votes
    2 Posts
    623 Views
    DerelictD

    You could send some of that /27 across OpenVPN to the other site if the /27 is routed to you.

    If the interface is a /27 that's going to be much more difficult.

  • VLANs please help

    6
    0 Votes
    6 Posts
    920 Views
    E

    I just figured it out. I wasn't setting the PVID of the switch ports correctly. Once I set the PVID of the untagged ports to the same VLAN ID as what I wanted the packets entering those ports tagged as, as I was able to connect to the cameras.

    Yet again the need to be explicit in your instructions proves itself.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.