Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Failover on PFsense 2.6

    Scheduled Pinned Locked Moved Routing and Multi WAN
    25 Posts 3 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stephenkwabena @stephenw10
      last edited by

      @stephenw10 Ooops, I've rolled it back to Pfsense 2.5.2 since it was worrying us for three days. I will install PFSense 2.6 on another server and get you the logs.

      1 Reply Last reply Reply Quote 1
      • S
        stephenkwabena @stephenw10
        last edited by

        @stephenw10 also, after enabling captive portal in pfsense 2.6, I can't ping any DNS, e.g. 8.8.8.8 or 9.9.9.9, domain names, but I can browse the internet.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Do you have a rule allowing ping?

          Can you resolve against external DNS servers?

          This seems unrelated to faoilover though. It should be in a separate thread.

          Steve

          S 2 Replies Last reply Reply Quote 0
          • S
            stephenkwabena @stephenw10
            last edited by

            @stephenw10 Yes, all the rules allow ping.

            S 1 Reply Last reply Reply Quote 0
            • S
              stephenkwabena @stephenkwabena
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • S
                stephenkwabena @stephenw10
                last edited by

                @stephenw10 I've raised in a separate thread

                1 Reply Last reply Reply Quote 1
                • S
                  stephenkwabena @stephenw10
                  last edited by

                  @stephenw10 Please, Steve, any update on how to solve the failover issue?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Not without more info.

                    We need to see the routing, gateway and general system logs covering a failover event.

                    I would check the rules file directly to make sure the correct gateway is being applied.

                    Steve

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      stephenkwabena @stephenw10
                      last edited by

                      @stephenw10 Steve, I did but there was no error logs

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        I wouldn't expect there to be any errors. But I would expect to see the gateway fail-over and associated scripts logged.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • S
                          stafast
                          last edited by

                          I just had an issue on 2.6 where our internet went down completely and the gateway stayed up and never went down to trigger the failover. I pinged from PFSense through the gateway that was bad and it had 100% packet loss, but the gateway still showed green and thus we never switched over to the backup internet. This worked perfectly fine before the 2.6 upgrade. Our gateway is set to ping 8.8.8.8 and that is what I tested from the box.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Are you also using 8.8.8.8 for DNS? Is it on the same gateway? You might have a conflicting static route.
                            Do you see the state for the gateway pings on the correct interface?
                            Are your two WANs using different gateway IPs?

                            Steve

                            S stephenw10S 2 Replies Last reply Reply Quote 0
                            • S
                              stafast @stephenw10
                              last edited by

                              @stephenw10 I'm not using 8.8.8.8 for DNS. I am actually using our local Active Directory DNS, two local DNS servers and a 3rd and 4th listed DNS on our two other gateways(U-Verse and DSL) I did notice however, that our two local DNS servers we had set did not have a gateway selected for them anymore, this used to be set before the upgrade I had thought. All WAN's are using different gateway IP's. We have Cable Internet(one having trouble), Fiber(main failover and what covers our VOIP) then U-Verse and DSL still hanging around(soon to be removed as we rarely use them).

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator @stephenw10
                                last edited by

                                @stephenw10 said in Failover on PFsense 2.6:

                                Do you see the state for the gateway pings on the correct interface?

                                The only way I can imagine it still showing as up would be if it's somehow sending the pings from the wrong WAN. As well as checking the state you can run a packet capture to be sure which NIC they are leaving from.

                                Steve

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  stafast @stephenw10
                                  last edited by

                                  @stephenw10 I'm actually not seeing any pings in the state for that interface. I captured the packets on the interface found nothing to 8.8.8.8, i found one ping from the gateway to the interface IP but that was it. There were various other pings to it from outside, some from inside from my monitoring server but that was it.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    stafast
                                    last edited by

                                    @stephenw10 I am seeing under routes for that gateway to 8.8.8.8 > gatewayIP that the uses is not going up at all the Fiber interface on 8.8.4.4 is going up but the WAN2 sits on 1999303 and doesn't move.

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      I assume you are seeing a state for pings to 8.8.8.8 somewhere though?

                                      Otherwise check the gateway logs for the dpinger entries on WAN. You should see the values it's being started with.

                                      Steve

                                      S 2 Replies Last reply Reply Quote 0
                                      • S
                                        stafast @stephenw10
                                        last edited by

                                        @stephenw10 nope nothing in the states for 8.8.8.8, just DNS queries for one of the devices that is manually set to that DNS using that interface. As for the gateway logs there are no dpinger entries past 3/7 which I believe is from before I upgraded PFSense.

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          stafast @stephenw10
                                          last edited by

                                          @stephenw10 I'll try restarting dpinger, see if that does anything.
                                          Restarted and got these for each interface:

                                          send_interval 500ms loss_interval 2000ms time_period 60000ms report_interval 0ms data_len 1 alert_interval 1000ms latency_alarm 500ms loss_alarm 20% dest_addr 8.8.8.8 bind_addr

                                          not sure if it fixed it or if that's just a normal thing when restarting, only time will tell really when it goes down next. I was wondering why when our internet went down for 45min over the previous weekend that it was completely down, turns out just never failed over to the other WAN.

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            That's normal except it should show the interface address for bind_addr. Did you just omit that?

                                            Check the main system logs for that time, are there any errors shown that might indicate dpinger did not start?

                                            S 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.