• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

default gateway override route ?

Scheduled Pinned Locked Moved Routing and Multi WAN
11 Posts 3 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rynstack
    last edited by Apr 28, 2023, 5:29 PM

    Hi, we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks. I have been running into trouble with obtaining a route out to the internet from the new 2nd lan and came to the conclusion that the default route setting is what is causing this. presuming setting that to "automatic" is what we want now, rather than setting this as a static default gateway. firewall rules appear to be allowing traffic out of the interface on the lan side, but traffic to internet cannot find its route, pings are 100% loss; the wan interface can ping out to the internet, and traffic is coming in to the dmz lan host fine. traffic to other internal lans are working with defined FW rules.
    thoughts, questions and/or comments welcome, thanks!

    *side note- after some trial and error and testing of different options/configs, it seems the routing table is stuck with some config that has been removed [alternate gateways], and now is causing the dmz wan iface to not ping out anymore; i can see the test route still listed in the routes via diagnostics page. manual removal via command line is my best guess to remove unless it will fix itself after a reboot?

    Netgate 1537 - Pfsesne+ v. 22.05 - planning on upgrading to 23.01 very soon

    thanks again.

    V 1 Reply Last reply Apr 29, 2023, 9:51 AM Reply Quote 0
    • V
      viragomann @rynstack
      last edited by Apr 29, 2023, 9:51 AM

      @rynstack said in default gateway override route ?:

      we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

      You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

      R 1 Reply Last reply May 1, 2023, 3:12 PM Reply Quote 0
      • R
        rynstack @viragomann
        last edited by May 1, 2023, 3:12 PM

        @viragomann said in default gateway override route ?:

        @rynstack said in default gateway override route ?:

        we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

        You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

        yes, that is correct @viragomann

        J 1 Reply Last reply May 1, 2023, 3:47 PM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @rynstack
          last edited by May 1, 2023, 3:47 PM

          @rynstack this would be a policy route, via firewall rule you can push traffic out any specific gateway you want.

          https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          R 1 Reply Last reply May 1, 2023, 5:31 PM Reply Quote 1
          • R
            rynstack @johnpoz
            last edited by rynstack May 1, 2023, 6:20 PM May 1, 2023, 5:31 PM

            @johnpoz thanks for the note and ref, I did play with that option before when troubleshooting early on, but was still having some problems with it, though I'd like to try it again some more [it was allowing traffic out when viewing logs, but getting stuck beyond the virtual child interface out to the public for some reason]. granted I did make changes while testing afterwards, still came to the same problem I'm having now, but there may be additional config needed for that to work properly in our setup.
            so technically, policy routing should resolve this issue and no adjustment would be needed to the system default route settings?

            One downside I found after trying that and some other things during testing, is a gateway listed in the routing table is stuck with the gateway IP I want to use pointing at a wrong MAC address [alternate virtual interface] - so now i cannot seem to fix it or use that IP as a gateway now. the gateway is marked as down, though its up on the correct physical interface, even after removing and re-adding from the the system gateway list. concerned some stale config is conflicting with getting this to work properly since the beginning. any advice on how to manually remove the problem gateway from the routing table without affecting other networks or the entire running system is welcome! thanks in advance.
            edit=uploaded image example
            5082e5ed-5c51-466c-a366-2cad35043663-image.png

            V 1 Reply Last reply May 1, 2023, 6:57 PM Reply Quote 0
            • V
              viragomann @rynstack
              last edited by May 1, 2023, 6:57 PM

              @rynstack
              Did you accidentally assign the same subnet to different interfaces by any chance?
              Check out Status > Interfaces.

              R 1 Reply Last reply May 1, 2023, 7:15 PM Reply Quote 0
              • R
                rynstack @viragomann
                last edited by May 1, 2023, 7:15 PM

                @viragomann thanks for the check - here's what I can see currently, this virtual interface for 10.86.151.1 still has the problematic gateway assigned to it, but in the interface config its not set. I checked subnets of all interfaces and they are all unique, but the problem gateway IP is listed for 2 interfaces. bug?
                0f0ed89d-2453-4526-9c2e-d0d2007894e1-image.png e88ab6f1-789b-48d6-903b-fd692af28630-image.png b7fec519-7175-4eb4-8309-168ec89aeff5-image.png

                V 1 Reply Last reply May 1, 2023, 7:31 PM Reply Quote 0
                • V
                  viragomann @rynstack
                  last edited by May 1, 2023, 7:31 PM

                  @rynstack
                  Strange. Chiefly as the gateway is outside of the subnet.

                  What shows System > Routing > Gateways?

                  R 1 Reply Last reply May 1, 2023, 9:54 PM Reply Quote 0
                  • R
                    rynstack @viragomann
                    last edited by rynstack May 1, 2023, 9:59 PM May 1, 2023, 9:54 PM

                    @viragomann basic default route and the problem GW, which I have removed, re-added, disabled, enabled twice but no change.
                    513a03bf-3677-4253-99a7-2cc0369d1360-image.png
                    ed9b32db-c57c-4d77-abd3-938ede59a378-image.png

                    R 1 Reply Last reply May 1, 2023, 10:12 PM Reply Quote 0
                    • R
                      rynstack @rynstack
                      last edited by rynstack May 1, 2023, 10:15 PM May 1, 2023, 10:12 PM

                      i just "re-saved" the interface [10.86.151.1] again with no change / no gateway and it fixed itself! 27f9ebe7-f82a-45c3-9f33-44960775f876-image.png e145081c-993d-456f-92bc-5f983d9f4994-image.png4a1824a3-8356-425d-accf-86d3b4d1fe55-image.png be6083aa-2d46-4f3f-b9ec-75580aa87493-image.png

                      1 Reply Last reply Reply Quote 0
                      • R
                        rynstack
                        last edited by May 1, 2023, 11:06 PM

                        thanks so much for the help @viragomann and @johnpoz , I seem to have a working route out now with FW rules using policy route!

                        1 Reply Last reply Reply Quote 0
                        11 out of 11
                        • First post
                          11/11
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received