Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Route withdrawal

    Scheduled Pinned Locked Moved Routing and Multi WAN
    7 Posts 2 Posters 487 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cslayton
      last edited by

      I am running a PFSense FW with one WAN interface and one LAN interface. The WAN is our internet connection and the LAN connects to an OSPF area. I am injecting a default route into the OSPF area. When the WAN is down, I would like the default route withdrawn from the OSPF area so that another OSPF router can handle internet via a backup default route. I have been unable to get this working as described.

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @cslayton
        last edited by michmoor

        @cslayton

        If the physical interface of the WAN drops, then there is no nexthop interface for the default route to use so therefore there is nothing to inject into OSPF.
        So everything is operating correctly. Why would a router remove a default route if it believes the nexthop is still active?

        edit 1
        Thinking about this further, why does it matter if the default route gets removed or not? You have a single WAN connection. If the WAN goes away your traffic has no where to go. If you remove the default is there another route internally that traffic can be routed to?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        C 1 Reply Last reply Reply Quote 0
        • C
          cslayton @michmoor
          last edited by

          @michmoor
          The future state will have another OSPF router with internet access and will inject a default route using a higher metric into the OSPF area. This will be the backup default route.

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @cslayton
            last edited by

            @cslayton
            Well you need a gateway created. Then you can create a route pointing to that gateway . You should be able to redistribute that static route after that

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            C M 2 Replies Last reply Reply Quote 0
            • C
              cslayton @michmoor
              last edited by

              @michmoor
              Got it. The Netgate needs another gateway to this other device, right? See attached diagram.Routing Failover.png

              1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @michmoor
                last edited by

                @michmoor
                So pfsense would need a gateway to Internet A created. Make the interface a WAN type interface.

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                C 1 Reply Last reply Reply Quote 0
                • C
                  cslayton @michmoor
                  last edited by

                  @michmoor
                  Yes, I have a WAN gateway (ISP). For Internet B, I would need another gateway using the LAN interface. The WAN gateway would be Tier 1, the LAN gateway would be Tier 2. Right?

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.