• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Dual WAN + LoadBalancing + Fail over + Multiply Public IPs

Scheduled Pinned Locked Moved Routing and Multi WAN
36 Posts 4 Posters 15.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    KDB9000
    last edited by Mar 1, 2007, 2:37 PM

    Here is the error I get:

    Acknowledge All    .:.    03-01-07 09:32:43 - [filter_load]There were error(s) loading the rules: /tmp/rules.debug:138: syntax errorpfctl: Syntax error in config file: pf rules not loaded The line in question reads [138]: pass in quick on $lan route-to { ( fxp0 ) , ( fxp1 64.20.192.185 ) } round-robin from 192.168.1.0/24 to keep state label USER_RULE: LAN > WAN + WAN 2    .:.

    1 Reply Last reply Reply Quote 0
    • H
      hoba
      last edited by Mar 1, 2007, 4:51 PM

      Try to convert this rule to 2 rules. 1 that blocks access to the alias through default gateway and another one that passes traffic to any through the pool. That's the same like the one rule with the NOT option.

      Does that solve the problem? Looks like there is something wrong with the NOT option to me.

      1 Reply Last reply Reply Quote 0
      • K
        KDB9000
        last edited by Mar 1, 2007, 5:28 PM Mar 1, 2007, 5:20 PM

        What about the DNS? I just want to know if that is OK. Right now both lines are shown as down and one of them is plugged in and running.

        Nope, still getting the error message, but it is narrowed down.

        Acknowledge All    .:.    03-01-07 12:15:32 - [filter_load]There were error(s) loading the rules: /tmp/rules.debug:141: syntax errorpfctl: Syntax error in config file: pf rules not loaded The line in question reads [141]: pass in quick on $lan route-to { ( fxp0 ) , ( fxp1 64.20.192.185 ) } round-robin from 192.168.1.0/24 to any keep state label USER_RULE: LAN > WAN + WAN 2    .:.

        Status  Proto  Source    Port  Destination    Port            Gateway                      Description
        pass      TCP    LAN net    *        *            HTTPsall    Wan2FailoverWan1      LAN > WAN2|WAN1 HTTPS
        block    *        LAN net    *    Internal        *                  *                      LAN > Default (block)
        pass      *        LAN net    *      *              *            LoadBalancer              LAN > WAN + WAN 2

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by Mar 1, 2007, 6:55 PM

          What version are you running? If this is not the latest snapshot please upgrade. Something is pretty strange with your setup.

          1 Reply Last reply Reply Quote 0
          • K
            KDB9000
            last edited by Mar 1, 2007, 7:50 PM

            Updated it this morning before a posted. it is like 2-27-07.

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by Mar 1, 2007, 8:53 PM

              Then I'm at a loss. I recommend starting over. There must be something somewhere wrong that we don't find this way. I recommend setting up and testing step by step to see where things break.

              1 Reply Last reply Reply Quote 0
              • K
                KDB9000
                last edited by Mar 2, 2007, 2:57 AM

                This was a start over. Followed everything in that wiki for the load balancing. Bet if I followed it again, I will still get the same error and I am nit sure why I am getting the error. Everything looks good.

                1 Reply Last reply Reply Quote 0
                • K
                  KDB9000
                  last edited by Mar 2, 2007, 1:10 PM

                  Everything is working now. It might have been hitting the error because the internet wasn't working right. I had a subnet problem in WAN and WAN2 finally got up yesterday. Plugged it all in and load balancing shows both running and did a restart and no rule errors came up. Everything seems to be OK. Do you know if I can block the DHCP range from the internet? This is for a school and the students will bypass the proxy if there is a way to, so we block the DHCP range and put a proxy into there computers so it gos to the proxy then out.

                  1 Reply Last reply Reply Quote 0
                  • K
                    KDB9000
                    last edited by Mar 2, 2007, 2:39 PM

                    I was also wondering about the multiply Public IPs and how I set them up. I made virtual IPs for it and set up NAT Routing with it. I noticed the NAT 1:1 and looked it up. Do I need to put anything in that? I did to see if it would do anything and now I get errors from it.

                    1 Reply Last reply Reply Quote 0
                    • K
                      KDB9000
                      last edited by Mar 22, 2007, 12:38 PM Mar 21, 2007, 5:03 PM

                      Well I have everything working. Just down to one problem, FTP on the load balance. I put the work around in and it is at the top but it doesn't seem to work. Anyone have any ideas why or what I need to do to get FTP to work on our load balance?

                      The work around was:

                      Proto Source  Port  Destination    Port    Gateway
                      TCP  LAN net  *    127.0.0.1    1-65535      *

                      1 Reply Last reply Reply Quote 0
                      • S
                        sullrich
                        last edited by Mar 21, 2007, 6:43 PM

                        Change the rule to include ports 8000-8020 instead of 65535

                        1 Reply Last reply Reply Quote 0
                        • H
                          hoba
                          last edited by Mar 21, 2007, 8:04 PM

                          You only have set 65535 and not the whole range 1-65535. There is an even easier rule to accomplish this:
                          pass, protocol any, source any, destination 127.0.0.1, gateway default.

                          That should do the trick when it is at the top of your rules at LAN.

                          1 Reply Last reply Reply Quote 0
                          • K
                            KDB9000
                            last edited by Mar 22, 2007, 12:37 PM Mar 22, 2007, 12:24 PM

                            I have it going from 1 - 65535 hoba, so that not the problem. Sorry about that I spaced it wrong. there is an extra 1 that is for the 1 - 65535 next to the 127.0.0.1. I will try your way and see what I get.

                            1 Reply Last reply Reply Quote 0
                            • K
                              KDB9000
                              last edited by Mar 22, 2007, 1:07 PM

                              Neither one seem to work. I tried to download a file of an FTP and it just times out. sullrich, I am not sure what you mean by have the rule in ports 8000-8020. If it gos to 65535 then it should already have 8000-8020 included. I tried both ways, here is a screen shot of the 2 rules. One is disabled right now so I could test. Then I remembered that only one WAN is hooked up so I switched from the default to the working WAN (WAN2) and tried it again. And yes, the FTP site I was using to test is working.

                              BTW hoba, remember when I asked about weighting a Load Balance system so it gos down one line more the the other? I had a though and was wondering what your thoughts were on it, we are looking for more of a redundant system for our internet. So couldn't I use a Failover? WANfailoverWAN2 would go down the WAN and then use WAN2 when WAN gos down, but will it switch back to WAN when it s up again?

                              FTPworkaround.PNG
                              FTPworkaround.PNG_thumb

                              1 Reply Last reply Reply Quote 0
                              • K
                                KDB9000
                                last edited by Mar 22, 2007, 2:10 PM

                                Never mind about the FTP, it seems to be working now. I guess it only works with the default.

                                1 Reply Last reply Reply Quote 0
                                • K
                                  KDB9000
                                  last edited by Mar 29, 2007, 3:04 PM

                                  OK, everything is working…... OK not everything. I am having trouble with one of my Internet lines now. It is Comcast and they give out a DHCP address. So I got a Linksys BEFSR41 and I put it between the Router and the Modem (see picture). I am doing load balancing with Comcast and another ISP but the Linksys router keeps going down after it runs for like 10 - 20 minutes. Tech support can't help me because of the way it is set up and the router works good. I can plug into it and just use that router to go out. I did 539 some odd pings to it's DNS server to see if it would handle the pings and it did fine. It is just when it is plugged into the pfSense. I have tried making it DMZ pfSense but that doesn't help. Anyone have any ideas that can help me? pfSense is configured right and all because it worked with a similar set up using a Cisco 806. Just need to find out if it is the Linksys or if maybe I did configure something wrong.

                                  layout.PNG
                                  layout.PNG_thumb

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    KDB9000
                                    last edited by Apr 10, 2007, 1:58 PM

                                    Update on the problem. I found out that I can switch ports and the internet for that ISP will start working for me for a while, after that it fails and I have to switch ports. Anyone have any idea what could be causing this and how to fix it?

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      [[user:consent.lead]]
                                      [[user:consent.not_received]]