Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help me fix my ruleset

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      naughtyusmaximus
      last edited by

      I have a multi wan setup with three WAN connections.

      WAN1 is used for my email server only
      WAN2 and WAN3 are used for VPN, Web Servers, and load balanced for my local user's internet access

      Basically, the email server uses the 'Email Failover' pool.  The WAN connection died, and for some reason none of my users could access the internet anymore until it came back up.  I was able to ping my DNS servers though.  Normal users shouldn't even be using the WAN1 connection though, so I'm not quite sure why its dying would lead to interupted access.  I've posted my rulesets, did I do something obviously wrong?

      LBRuleset.PNG
      LBRuleset.PNG_thumb
      LBPools.PNG
      LBPools.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • P Offline
        Perry
        last edited by

        You could try with a dns rule http://pfsense.site88.net/multiwan.html
        2 check's I normally do:
        Trace route to your dns server from pfSense to see if they are going through the right wan.
        browse with the ip of a website

        /Perry
        doc.pfsense.org

        1 Reply Last reply Reply Quote 0
        • N Offline
          naughtyusmaximus
          last edited by

          I've tested everything again since the WAN1 connection came back up, and there don't appear to be any oddities - but I don't really want to start unplugging things to really test them out until the end of the week.

          I've taken your suggestion, and have started using OpenDNS.  In the guide you posted, they set up a static route, one on each of the two WAN connections.  Since I have 3 WAN connections, what is the best way for me to do this?  Just leave out the static routes altogether?

          1 Reply Last reply Reply Quote 0
          • P Offline
            Perry
            last edited by

            You could manual edit config.xml and add a extra dns server

            /Perry
            doc.pfsense.org

            1 Reply Last reply Reply Quote 0
            • N Offline
              naughtyusmaximus
              last edited by

              AFIK though, OpenDNS only has two IP addresses.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.