• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

5 WAN on 3 Interface. How?

Scheduled Pinned Locked Moved Routing and Multi WAN
26 Posts 3 Posters 2.9k Views 4 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    befree2
    last edited by May 26, 2022, 12:02 PM

    Hi everyone,
    I'm Roberto.
    I would like to use 5 wan router on my firewall which only has 3 nic interface for wan use though

    my scenario is as follows:
    my router owns 4 Nic interfaces
    1 for LAN 192.168.200.0/21
    2 for WANGW 172.21.71.2 GW 172.21.71.1
    3 for OPT1GW 172.22.71.2 GW 172.22.71.1
    4 for OPT1GW 172.23.71.2 GW 172.23.71.1

    My problem is that I have 2 other wan routers 172.24.71.2 and 172.25.71.2 respectively with GW 172.24.71.1 and GW 172.25.71.1
    I tried to configure them by putting them on the same external switch together with OPT1GW as Virtual IP, I can ping their GWs but not ping outside on the internet.
    Could someone please help me?

    Thanks

    Roberto

    V 1 Reply Last reply May 26, 2022, 6:53 PM Reply Quote 0
    • V Offline
      viragomann @befree2
      last edited by May 26, 2022, 6:53 PM

      @befree2
      What's the sense of these IPs? They are all private IPs. Do each IP nat the traffic to a public one?

      I can ping their GWs but not ping outside on the internet.

      Did you state the gateway in the interface settings on pfSense?
      Does the router nat the traffic properly?

      B 1 Reply Last reply May 26, 2022, 7:46 PM Reply Quote 0
      • B Offline
        befree2 @viragomann
        last edited by May 26, 2022, 7:46 PM

        @viragomann
        Hi and thank you for replying.

        Yes, each ip on each router, nat to public IP addresses. (My isp provide it in that way, I can't use public ip address)

        Yes, I state all gateways for each Interface. my question is how do I configure the other 2 routers not having nic interfaces?
        If think the NAT is OK, I mean say, for the 3 Wan is working.

        I tried to use Virtual IP in CARP mode, for 172.24.71.1 and 172.25.71.1 I can ping the gateway but It won't go on internet
        If you want, I could get you into the pfsense remotely to check it out

        Sorry for my bad English.

        Roberto

        J V 2 Replies Last reply May 26, 2022, 7:59 PM Reply Quote 0
        • J Online
          johnpoz LAYER 8 Global Moderator @befree2
          last edited by johnpoz May 26, 2022, 8:04 PM May 26, 2022, 7:59 PM

          @befree2 How I would do it.. As long as these IPs from the different wan routers do not overlap.

          Get a cheap 8 port smart switch.. run your isp routers into this switch on different vlans. Setup the vlans on on pfsense ..

          You end up with say this.

          5wans.jpg

          I mean the better option would be to get a better router with more interfaces. But you can pick up a 8 port gig smart switch that can do vlans and lagg for like $40

          Your vlans would be untagged going to the isp devices, and tagged going into pfsense. Setup the vlans on your lagg you setup. Easy Peasy Lemon Squeazy ;)

          If your total bandwidth with all your isp isnt over gig, you could just get by with 1 port connected to pfsense from your switch with the vlans on it.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann @befree2
            last edited by May 26, 2022, 8:01 PM

            @befree2 said in 5 WAN on 3 Interface. How?:

            I can't use public ip address

            That's bad. pfSense could handle the public IPs quite well.
            But with your setup you need to have each gateway (public IP) on an separate interface on pfSense, because there can naturally only be one gateway for the default route per interface.

            So the solution for your setup is to get a an VLAN capable switch as @johnpoz already illustrated very nice.

            1 Reply Last reply Reply Quote 0
            • B Offline
              befree2
              last edited by May 26, 2022, 8:13 PM

              First of all, many thanks @virgomann and @johnpoz for answering me and giving me great solutions
              I am not very familiar with Vlan but I will make it.
              I will use one port on pfsense while on the switch (vlan support) I will use 3 ports.
              Just long enough to find a suitable switch, I believe the netgear gs308t should go and I'll let you know.
              In the meantime, many many thanks

              1 Reply Last reply Reply Quote 0
              • B Offline
                befree2
                last edited by May 26, 2022, 8:19 PM

                26290c6e-cbe1-4456-a3e9-f84e5f782972-immagine.png

                I'm starting to see how to configure interfaces. So is that correct?

                V 1 Reply Last reply May 26, 2022, 8:27 PM Reply Quote 0
                • V Offline
                  viragomann @befree2
                  last edited by May 26, 2022, 8:27 PM

                  @befree2
                  Yes, the VLANs are ok.
                  But some cheap switches cannot properly separate networks, when running tagged and untagged traffic on the same port. So you should better also turn the existing TIM1 on em3 network port into a VLAN.

                  B J 2 Replies Last reply May 26, 2022, 8:45 PM Reply Quote 0
                  • B Offline
                    befree2 @viragomann
                    last edited by May 26, 2022, 8:45 PM

                    @viragomann
                    Ok I will VLAN 4 TIM1

                    1 Reply Last reply Reply Quote 0
                    • J Online
                      johnpoz LAYER 8 Global Moderator @viragomann
                      last edited by johnpoz May 27, 2022, 1:44 AM May 27, 2022, 1:38 AM

                      @viragomann said in 5 WAN on 3 Interface. How?:

                      when running tagged and untagged traffic on the same port.

                      What switch is this - tplink has had issues with vlans for sure, not able to remove vlan 1 in the past.

                      But in all my years in networking have never seen an issue where you couldn't run a native vlan, ie untagged along with tagged vlans. Now you can only run 1 untagged vlan that is for sure. But you should be able to run 1 untagged vlan with other tagged vlans.

                      But in such a setup I would prob just run them all tagged. I don't see any advantage of running a native vlan in such a setup.

                      But sure if he had say a 5 port switch he could run run some of his wan into pfsense native, and then run the extra ones into a switch and tagg the traffic into 1 pfsense interface, etc.

                      Personally if was me, I would just get a better router with more interfaces ;) But if couldn't do that and I had to do such a setup.. I would do it as drawn with the lagg and the vlans over the lagg. This gives you most through put to any of the wan routers..

                      I really don't understand such a setup - I could see 2 wan, or maybe even 3 in ultimate failover sort of setup.. But I am curious to why anyone would want/need 5 different wan providers.. My "guess" is providers don't have away to bring in the bandwidth required on 1 line.. So have to have multiple lines.. If that is the case, then lagg on pfsense gives highest possible physical interface bandwidth that could be shared across the 5 wan connections.. So in theory you could hit 3gig.. Assuming that is the pfsense wan interfaces are gig ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      B 1 Reply Last reply May 27, 2022, 10:06 PM Reply Quote 0
                      • B Offline
                        befree2 @johnpoz
                        last edited by May 27, 2022, 10:06 PM

                        @johnpoz
                        Hi,
                        first of all thank you for you help.
                        So, if Im not wrong I will setup pfsense as follow:

                        em3 interface should be turn in lagg mode with the 3 vlans
                        and the netgear gs-308t seems to be the right one
                        https://www.netgear.it/support/product/gs308t.aspx
                        Once I get the switch at home I will setting up with untagged and tagged port ,
                        I will keep you informed if you don't mind.
                        Bye
                        Roberto

                        J B 2 Replies Last reply May 28, 2022, 2:44 AM Reply Quote 0
                        • J Online
                          johnpoz LAYER 8 Global Moderator @befree2
                          last edited by johnpoz May 28, 2022, 2:45 AM May 28, 2022, 2:44 AM

                          @befree2 said in 5 WAN on 3 Interface. How?:

                          https://www.netgear.it/support/product/gs308t.aspx

                          Yeah that will do vlans and lagg, but for a lagg you need more than just 1 interface..

                          https://docs.netgate.com/pfsense/en/latest/interfaces/lagg.html

                          If your just going to use 1 interface, then no lagg would be setup and you would just setup vlans on it.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          B 1 Reply Last reply May 30, 2022, 6:51 AM Reply Quote 0
                          • B Offline
                            befree2 @johnpoz
                            last edited by May 30, 2022, 6:51 AM

                            @johnpoz
                            Good morning. Ok, I will do it with no LAGG at the moment.
                            Thank you very much

                            1 Reply Last reply Reply Quote 0
                            • B Offline
                              befree2 @befree2
                              last edited by befree2 Jun 2, 2022, 7:05 AM Jun 2, 2022, 7:03 AM

                              Hi,
                              everything is working fine now!!!
                              Here is the scenario after the Vlan were created

                              90df7754-d863-4bd5-8595-275aa5e16baf-immagine.png

                              458b9321-7211-4fa0-ac6e-90e60a7ad2a2-immagine.png

                              I did not create a LAGG because the switch they gave me doesn't support. That's why the LAGG port is still available.
                              Thank you everyone for supporting me.

                              Bye
                              Roberto

                              J 1 Reply Last reply Jun 2, 2022, 11:39 AM Reply Quote 0
                              • J Online
                                johnpoz LAYER 8 Global Moderator @befree2
                                last edited by johnpoz Jun 2, 2022, 11:42 AM Jun 2, 2022, 11:39 AM

                                @befree2 said in 5 WAN on 3 Interface. How?:

                                the switch they gave me doesn't support.

                                And what switch is that? You said you were getting a gs308T which clearly supports lag per its manual

                                https://www.downloads.netgear.com/files/GDC/GS308T/GS308T_GS310TP_IG_EN.pdf

                                lag.jpg

                                From what you posted - you have your vlans on a lag - with what 1 port? If your not going to use lag I would remove putting your vlans on it.. And just put the vlans on em3..

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • B Offline
                                  befree2
                                  last edited by Jun 3, 2022, 12:19 PM

                                  Hi.
                                  I know but the client provide a GS108E .....

                                  J B 2 Replies Last reply Jun 3, 2022, 12:29 PM Reply Quote 0
                                  • J Online
                                    johnpoz LAYER 8 Global Moderator @befree2
                                    last edited by Jun 3, 2022, 12:29 PM

                                    @befree2 well if the total bandwidth available from these 5 connections is less than gig - still seems crazy to me then it not really a problem.

                                    Out of pure curiosity - why do they have 5 connections? Is there limit on what 1 connection can provide in form of bandwidth?

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • B Offline
                                      befree2 @befree2
                                      last edited by Jun 3, 2022, 12:42 PM

                                      @befree2
                                      Yes there is. ISP cannot provide a single connectivity and that's why we join all routers..
                                      On pfsense I have set LOAD BALANCE to get more bandwidth and fail over as well

                                      1 Reply Last reply Reply Quote 0
                                      • B Offline
                                        befree2
                                        last edited by befree2 Jul 27, 2022, 1:45 PM Jul 27, 2022, 1:27 PM

                                        Hi.
                                        I got the GS308T Switch !!
                                        What Should I create first the LAG o Vlan? I'would like to set port 1to 6 as Vlan3,4,5,6,7 and 8.
                                        What LAGG ports to pfsense assuming that port 8 should be connected to PFsense wan port?
                                        I'm struggling with that. Hope you can help.
                                        In case we can use teamviewer ...
                                        Thanks

                                        Robin

                                        0206d03c-7fa4-4692-9415-2fbfd57a40d6-vlan.jpg

                                        6b82a8d2-7df7-4460-8e00-390171ee6678-lag.jpg

                                        4420d893-cfff-489f-8517-ca3ee374b4d2-lag.jpg

                                        J 1 Reply Last reply Jul 27, 2022, 2:10 PM Reply Quote 0
                                        • J Online
                                          johnpoz LAYER 8 Global Moderator @befree2
                                          last edited by johnpoz Jul 27, 2022, 2:14 PM Jul 27, 2022, 2:10 PM

                                          @befree2 unless your total bandwidth from the internet lines is over 1 gig, I would just go with no lagg - lagg adds complexity. I am a huge fan of the KISS principle (Keep it Simple Stupid) hehehe

                                          Thought you said it was working with your other switch that didn't do lagg? Were you not seeing the full bandwidth your different isp lines can provide?

                                          https://en.wikipedia.org/wiki/KISS_principle

                                          Maybe because it originated in the Navy, and I'm ex-navy.. That was a bit before my time ;) but was still a saying when I was in during the 80s and 90s

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          B 1 Reply Last reply Jul 27, 2022, 2:44 PM Reply Quote 1
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            [[user:consent.lead]]
                                            [[user:consent.not_received]]