Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense with Syswan SW88 Multi Wan Router in front

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 4 Posters 6.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dschmid
      last edited by

      Hello, I'm planning in Installation with seven 16000 DSL Lines. It's important that I can use Squid and Snort  and probably Captive Portal on my Pfsense Box. So doing the Multi WAN Load Balancing/Failover Stuff on the Pfsense Box is no option. So I searched the Internet and  found this Syswan Router for about 650 Bugs with up to 8! Wan Ports. The most Solutions I found only have 4 Ports for Wan or are much much more expensive. The Solution should look like this:

      Modem        Modem        Modem        Modem        Modem          Modem          Modem
            |              |                |                    |                |                |                |
            |              |                |                    |                |                |                |
            –-----------------------------------------------------------------------------
                                                                    |
                                                                    |
                                                                    |
                                                                    |
                                                        Syswan SW 88
                                                                    |
                                                                    |
                                                                    |  DMZ
                                                                    |
                                              PFsense Box (Captive Portal, Proxy, IDS)
                                                                    |
                                                                    |
                                                                    |
                                                              Local Lan

      Has someone running a similar solution running doing Dual or Multi Wan on an other Box. I appreciate any hint and tip for setting up such a solution.

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        You would be far better served to use pfSense as your router/firewall, and offload snort and squid to separate boxes.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          Yeah this was my first thought too.
          If you're already going to have 2 boxes, why not 2x pfSense?
          Or pfSense for loadbalancing and another system for snort/squid if you cannot get it to run on pfsense.

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • D
            dschmid
            last edited by

            Hello, I only got an small IBM ThinkCenter as pfsense box and I have to connect seven DSL Modems to it. But I only got one nic for my internal and one for my wan. Is it possible to connect the modems to a switch wich supports vlan?

            1 Reply Last reply Reply Quote 0
            • P
              Perry
              last edited by

              yes they just need to have a different gateways
              http://pfsense.site88.net/mysetup/index.html

              /Perry
              doc.pfsense.org

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                Yes.
                Or if the modems are in NAT/routing mode you could even have all their LANs in a single subnet and modify the config.xml manually so you balance between the LAN-IP's of the modems.
                –> Different gateways as perry said.

                [WAN]          [WAN]         [WAN]          [WAN]          [WAN]          [WAN]           [WAN]
                  Modem         Modem         Modem         Modem         Modem          Modem          Modem
                       |      172.17.10.2/24      |         172.17.10.4/24         |        172.17.10.6/24      |
                  [LAN]           [LAN]          [LAN]              [LAN]          [LAN]            [LAN]          [LAN]
                172.17.10.1/24   |        172.17.10.3/24         |       172.17.10.5/24       |          172.17.10.7/24
                       |               |                |                    |                 |                |                 |
                       |               |                |                    |                 |                |                 |
                       –-----------------------------------------------------------------------------
                                                                          switch
                                                                              |                   
                                                                              |
                                                                              |
                                                                              |
                                                                              |
                                                                [WAN] 172.17.10.100/24
                                                                         pfSense
                                                                  [LAN] 10.0.0.1/24
                                                                              |
                                                                              |
                                                                              |
                                                                           clients

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • D
                  dschmid
                  last edited by

                  The problem I've got is that I can't enable dmz on the cheap modem routers from the provider or can I forward all ports 1-65535 tcp/udp to the pfsense box?

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    @dschmid:

                    Or can I forward all ports 1-65535 tcp/udp to the pfsense box?

                    Yes.
                    I have to do that on my modem at home too because it's a piece of shit (never came around to buy a better modem ^^" )

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • D
                      dschmid
                      last edited by

                      OK I try this this weekend. Thank you very much.

                      1 Reply Last reply Reply Quote 0
                      • D
                        dschmid
                        last edited by

                        Sorry I forgot to ask how to insert the different gateways into the config.xml and activate Load Balancing.

                        1 Reply Last reply Reply Quote 0
                        • GruensFroeschliG
                          GruensFroeschli
                          last edited by

                          1: Create a balancing pool and add a dummy-entry.
                          2: Download the config.xml and find the part with the info you add.
                          3: Copy/Paste your dummy entry and fill in the real gateway/monitor IPs.

                          As monitoring IP use one of the immediate hops on your ISP's side.
                          You cannot have the same monitoring IP for different WANs.

                          4: Restore the config.xml.

                          Now your manually added infos should show up.

                          We do what we must, because we can.

                          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.