Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Correct gateway is not used

    Scheduled Pinned Locked Moved Routing and Multi WAN
    10 Posts 4 Posters 518 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U Offline
      uggiz
      last edited by

      Hello,

      I have a setup with two WAN`S, one slow (VSAT) and one faster (Starlink).

      I have setup a Failover Gateway group, and this is working fine. (Failing from fast to slow)

      But I want to force one of the LAN`s to use only the slow WAN, how can i do this? I have tried to make firewall rules and setting the slow WAN as the default gateway there, but the System/Routing/Gateways - Default Gateway IPv4 seems to override this.

      Any tips?

      Bob.DigB V 2 Replies Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @uggiz
        last edited by

        @uggiz said in Correct gateway is not used:

        I have tried to make firewall rules and setting the slow WAN as the default gateway there,

        Show it.

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann @uggiz
          last edited by

          @uggiz
          Yes, policy routing is the correct way to route traffic from certain devices to a specific gateway.
          However, you have to ensure that the rule is applied before others, which allow public access over the default gateway.
          So maybe you have to correct the rule order.

          U 1 Reply Last reply Reply Quote 0
          • U Offline
            uggiz @viragomann
            last edited by

            @viragomann
            3a89001d-27a3-479d-9e25-b212685b682e-image.png

            This rule is applied on top now for the test. But the traffic still goes to the wrong WAN

            V 1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann @uggiz
              last edited by

              @uggiz
              Possibly there is still an existing state for the connection. Try to flush the states.

              Also remember, that floating rules and interface group rules have precedence.

              U 1 Reply Last reply Reply Quote 0
              • U Offline
                uggiz @viragomann
                last edited by

                @viragomann
                Tried flushing the states, and there are no floating rules or interface groups.
                When i change this to the VSAT (WAN_DHCP) the traffic flows correctly:
                0f75aff8-c3e2-4647-8fa4-e4f6d0bbd74c-image.png

                Do I need to set this to none, and add firewall rules with gateway to the different interfaces?

                V 1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann @uggiz
                  last edited by

                  @uggiz
                  No, this is the default gateway setting and is needed by pfSense for proper routing.
                  This is used for all traffic apart from policy routing.

                  If your rule doesn't work, I'd assume that it isn't applied due to not matching conditions.
                  However, your rule shows states and traffic:
                  cc81e910-2650-4dd0-a4b7-df2cd5b7203c-grafik.png

                  So it obviously matched some traffic already. And I'd expect that the stated gateway was used for it then.
                  Why do you think, that it doesn't work?

                  U 1 Reply Last reply Reply Quote 0
                  • U Offline
                    uggiz @viragomann
                    last edited by

                    @viragomann

                    When I do a traceroute on the Pfsense it shows the wrong WAN interface ip. If i switch the default gateway here and try again, the correct WAN interface ip is show on the traceroute.
                    2aff04e0-e1fa-42bb-9f75-fceb22a643e8-image.png

                    V G 2 Replies Last reply Reply Quote 0
                    • V Offline
                      viragomann @uggiz
                      last edited by

                      @uggiz said in Correct gateway is not used:

                      When I do a traceroute on the Pfsense it shows the wrong WAN interface ip.

                      pfSense itself doesn't obey the policy routing rule. Only the devices in the source alias are directed to the gateway in question.

                      1 Reply Last reply Reply Quote 0
                      • G Offline
                        Gblenn @uggiz
                        last edited by

                        @uggiz A simple test would be to open a browser on a PC that is on the CREWVSAT73 subnet and check "whatismyip.com"...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.