Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    default gateway override route ?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rynstack
      last edited by

      Hi, we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks. I have been running into trouble with obtaining a route out to the internet from the new 2nd lan and came to the conclusion that the default route setting is what is causing this. presuming setting that to "automatic" is what we want now, rather than setting this as a static default gateway. firewall rules appear to be allowing traffic out of the interface on the lan side, but traffic to internet cannot find its route, pings are 100% loss; the wan interface can ping out to the internet, and traffic is coming in to the dmz lan host fine. traffic to other internal lans are working with defined FW rules.
      thoughts, questions and/or comments welcome, thanks!

      *side note- after some trial and error and testing of different options/configs, it seems the routing table is stuck with some config that has been removed [alternate gateways], and now is causing the dmz wan iface to not ping out anymore; i can see the test route still listed in the routes via diagnostics page. manual removal via command line is my best guess to remove unless it will fix itself after a reboot?

      Netgate 1537 - Pfsesne+ v. 22.05 - planning on upgrading to 23.01 very soon

      thanks again.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @rynstack
        last edited by

        @rynstack said in default gateway override route ?:

        we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

        You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

        R 1 Reply Last reply Reply Quote 0
        • R
          rynstack @viragomann
          last edited by

          @viragomann said in default gateway override route ?:

          @rynstack said in default gateway override route ?:

          we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

          You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

          yes, that is correct @viragomann

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @rynstack
            last edited by

            @rynstack this would be a policy route, via firewall rule you can push traffic out any specific gateway you want.

            https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            R 1 Reply Last reply Reply Quote 1
            • R
              rynstack @johnpoz
              last edited by rynstack

              @johnpoz thanks for the note and ref, I did play with that option before when troubleshooting early on, but was still having some problems with it, though I'd like to try it again some more [it was allowing traffic out when viewing logs, but getting stuck beyond the virtual child interface out to the public for some reason]. granted I did make changes while testing afterwards, still came to the same problem I'm having now, but there may be additional config needed for that to work properly in our setup.
              so technically, policy routing should resolve this issue and no adjustment would be needed to the system default route settings?

              One downside I found after trying that and some other things during testing, is a gateway listed in the routing table is stuck with the gateway IP I want to use pointing at a wrong MAC address [alternate virtual interface] - so now i cannot seem to fix it or use that IP as a gateway now. the gateway is marked as down, though its up on the correct physical interface, even after removing and re-adding from the the system gateway list. concerned some stale config is conflicting with getting this to work properly since the beginning. any advice on how to manually remove the problem gateway from the routing table without affecting other networks or the entire running system is welcome! thanks in advance.
              edit=uploaded image example
              5082e5ed-5c51-466c-a366-2cad35043663-image.png

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @rynstack
                last edited by

                @rynstack
                Did you accidentally assign the same subnet to different interfaces by any chance?
                Check out Status > Interfaces.

                R 1 Reply Last reply Reply Quote 0
                • R
                  rynstack @viragomann
                  last edited by

                  @viragomann thanks for the check - here's what I can see currently, this virtual interface for 10.86.151.1 still has the problematic gateway assigned to it, but in the interface config its not set. I checked subnets of all interfaces and they are all unique, but the problem gateway IP is listed for 2 interfaces. bug?
                  0f0ed89d-2453-4526-9c2e-d0d2007894e1-image.png e88ab6f1-789b-48d6-903b-fd692af28630-image.png b7fec519-7175-4eb4-8309-168ec89aeff5-image.png

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @rynstack
                    last edited by

                    @rynstack
                    Strange. Chiefly as the gateway is outside of the subnet.

                    What shows System > Routing > Gateways?

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      rynstack @viragomann
                      last edited by rynstack

                      @viragomann basic default route and the problem GW, which I have removed, re-added, disabled, enabled twice but no change.
                      513a03bf-3677-4253-99a7-2cc0369d1360-image.png
                      ed9b32db-c57c-4d77-abd3-938ede59a378-image.png

                      R 1 Reply Last reply Reply Quote 0
                      • R
                        rynstack @rynstack
                        last edited by rynstack

                        i just "re-saved" the interface [10.86.151.1] again with no change / no gateway and it fixed itself! 27f9ebe7-f82a-45c3-9f33-44960775f876-image.png e145081c-993d-456f-92bc-5f983d9f4994-image.png4a1824a3-8356-425d-accf-86d3b4d1fe55-image.png be6083aa-2d46-4f3f-b9ec-75580aa87493-image.png

                        1 Reply Last reply Reply Quote 0
                        • R
                          rynstack
                          last edited by

                          thanks so much for the help @viragomann and @johnpoz , I seem to have a working route out now with FW rules using policy route!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.