• Netgear LB2120 as WAN failover

    7
    0 Votes
    7 Posts
    2k Views
    M
    @SR190 You seem to be way more knowledgeable about this stuff than I, so maybe you can help me. I don't have a pfSense. I have Arris surfboard (optimum) -> LB2120 -> Netgear AC series WiFi access point. I have a lot of static IPs and since the LB2120 doesn't support this, I don't want to use the DHCP service on that. Optimum provided IP address is dynamic. My first setup was to have LB2120 in bridge mode with IP as default with 192.168.5.1. My current LAN range (DHCP from Wifi AP) is 192.168.1.x. In bridge mode, I'm fine with the wired connection to optimum and can open the LB's browser at 192.168.5.1. When I disconnect the Optimum connection, it doesn't seem to failover and I can't get to the LB address. I know I'm getting LTE data because FreedomPop shows my data usage ticking up (presumably modem pings). I also tried putting it in router mode and disabling the DHCP service, but no go. I managed to screw it up so badly by enabling VPN that I had to do a factory reset because I couldn't get to the LB. So I'm wondering if changing the LB address to within my LAN range of 192.168.1.x is necessary or if you had any other thoughts. Appreciate any help.
  • Openbgpd

    2
    0 Votes
    2 Posts
    277 Views
    J
    This got resolved by having the ISP configure /25 at their end and we advertising /25.
  • Failover WAN VPN connection status

    1
    0 Votes
    1 Posts
    110 Views
    No one has replied
  • Upstream gateway vs default gateway

    8
    0 Votes
    8 Posts
    14k Views
    M
    @marcus_1302 btw. just saw that even when you set the upstream gateway on the WAN interface, you can prevent pfSense from adding a reply-to userrule. Under System - Advanced - Firewall & Nat there is a checkbox Disable reply-to on WAN rules With Multi-WAN it is generally desired to ensure traffic leaves the same interface it arrives on, hence reply-to is added automatically by default. When using bridging, this behavior must be disabled if the WAN gateway IP is different from the gateway IP of the hosts behind the bridged interface.
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    11 Views
  • Gateways goes offline after ~1h

    1
    0 Votes
    1 Posts
    101 Views
    No one has replied
  • Issues with VLANs and Multiple Gateways

    1
    0 Votes
    1 Posts
    123 Views
    No one has replied
  • Two VRRP problem

    6
    0 Votes
    6 Posts
    729 Views
    N
    In hq are you sure you have two lans? They overlapp. (/16) and are rather big. Yes, you can send specific traffic to specific gw with policy routing. As for the return packets, at remote site lan you also need to have some policy routing so packets return the same way. You can do it at the ospf level, but it is starting to get complicated. I would eliminate ospf altogheter, direct connect two pf at sites and do assymetric load balance for the two links.
  • Moving from VPN to SD-WAN

    6
    0 Votes
    6 Posts
    3k Views
    N
    Sorry, but I don't get it An sd wan, a cloud in the middle and suddenly a vpn tunnel across the cloud??? It might work, but it doesn't feel right as a concept. If you need firewalling, why the sdwan is not doing it? It seems you have an authority issue to solve, not a technical one.
  • OpenVPN-client - how?

    3
    0 Votes
    3 Posts
    403 Views
    L
    Or: https://administrator.de/wissen/openvpn-server-installieren-pfsense-firewall-mikrotik-dd-wrt-gl-inet-router-123285.html#toc-7 Google Translator maybe your friend here... ;-)
  • No LAN connection on dual firewall DMZ setup

    4
    0 Votes
    4 Posts
    876 Views
    G
    @viragomann Thank you for your answer. My bad: I meant the 172.30.192.0 network. My problem is I can't connect the LAN to the internet from Firewall B. Thanks.
  • how is localhost still reaching domains without localhost NAT rules?

    6
    0 Votes
    6 Posts
    595 Views
    J
    @jimp Ah yes, I do remember reading about binding to localhost for dual WAN OpenVPN setups. Thanks for the info, it's great to have such a knowledgeable and helpfull community.
  • Cannot access webpage on different subnet.

    1
    0 Votes
    1 Posts
    135 Views
    No one has replied
  • Hurricane Electric tunnel fallback with 2 Internet WANs

    3
    0 Votes
    3 Posts
    138 Views
    BoabB
    Tried adding the second GIF, it brought the HE link down. The Gateway status only showed one HE. Removed the extra GIF to restore normal operation. Thanks
  • Android DHCP, DNS issue.

    4
    0 Votes
    4 Posts
    835 Views
    kiokomanK
    i have bind9 dns server configured with internal/external view on my locations, i just permit only my internal dns server and block everything else,
  • pfSense not monitoring right ip with multi client openVPN connections

    2
    0 Votes
    2 Posts
    202 Views
    C
    Well, by design pfsense dpinger and related routing table updates of bsd won't let you use the same ip address. A routing table for specific IP is just that: it allows an exit on a specific interface. If you connect to your vpn provider through different servers , a new gateway is created for each connection . Also, If your provider happen to give you the same IP for 2 or more connections , it might be game over conflict for connectivity tests and maybe gateway status. The solution to your problem is not to monitor the vpn gateway ip which is the same on every server , except the first connection, but choose a well known ip , e.g 1.1.1.1 or 8.8.8.8 as monitor IP for each vpn gateway. If you need to compare vpn connections , it will not be a stable basis for comparisson , as the external ip will have longer ping times by a 25% margin approx. I understand your concern from a paranoid security point of view, as pinging a vpn gateway does not leave any traceable exposure on vpn exits for your pings..where advanced adversaries might interfere with.. The limit of monitoring with a single IP the connection status tries to tackle a new advanced plugin which is under development for the time being..Since then, try, to diferentiate your monitor IPs for each gateway manually..
  • how to connect the PFsense to another LAN firewall

    3
    0 Votes
    3 Posts
    200 Views
    johnpozJ
    Took you since june to do that? ;) This is connection is via a transit network I hope, you don't have hosts on the network your using to connect to your downstream?
  • 0 Votes
    1 Posts
    133 Views
    No one has replied
  • Multi WAN Site-to-Site VPN with OpenVPN HELP!!!

    1
    0 Votes
    1 Posts
    100 Views
    No one has replied
  • Two WAN connections and 3 VLAN

    4
    0 Votes
    4 Posts
    277 Views
    DerelictD
    No. DHCP on LAN is enabled by default and all traffic from LAN clients is passed by default. Hard to say what you might have done wrong with the information available.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.