Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Gateway Groups

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    11 Posts 7 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cmb
      last edited by

      @thermionic:

      I presume that with the new Gateway Groups, I add interfaces into a group, and then set the gateway for the traffic that I want to go over the group in the firewall rules.

      Yes.

      @thermionic:

      Do I need to set multiple gateways to "default" as well ?

      No, only the one you want to be the default route. There can only be one default. Some changes related to that will be coming soon, for the time being check the one you consider your primary WAN.

      1 Reply Last reply Reply Quote 0
      • T
        thermionic
        last edited by

        Thanks!

        my follow on question…

        If Gateway groups are being used, do you "need" a default route ?

        Cheers

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          @thermionic:

          If Gateway groups are being used, do you "need" a default route ?

          Yes, you'll still want the firewall to be able to access the Internet, for NTP time sync, update checking, auto update, etc. It won't affect inside hosts if they all hit a rule with a gateway group, but does affect the firewall itself.

          1 Reply Last reply Reply Quote 0
          • L
            lotacus
            last edited by

            For fail-over, if wan1 fails, and later the link is re-established will all traffic move back to wan1 since it's gateway is set to "default"?

            1 Reply Last reply Reply Quote 0
            • D
              DennisBagley
              last edited by

              related question : if I have multi wan and the default route wan goes down does that stop pfsense being able to see the internet [ for its own purposes - e.g. update check etc… ] or will it fall back to the other defined gateways ???

              in the 'future changes' will it be possible to define a wan group as teh default route ??
              and will checking default on a gateway automatically uncheck default on the other gateways ???

              1 Reply Last reply Reply Quote 0
              • G
                geeknik
                last edited by

                @DennisBagley:

                related question : if I have multi wan and the default route wan goes down does that stop pfsense being able to see the internet [ for its own purposes - e.g. update check etc… ] or will it fall back to the other defined gateways ???

                in the 'future changes' will it be possible to define a wan group as teh default route ??
                and will checking default on a gateway automatically uncheck default on the other gateways ???

                I don't have either WAN or WAN2 marked as default and pfSense sees the Internet just fine (checks for updates, syncs time, etc).

                1 Reply Last reply Reply Quote 0
                • L
                  lotacus
                  last edited by

                  I added two gateways in the gateway group and when one gateway went down, PFSense was still able to route traffic to the other gateway, so it seems that having seperate rules/groups for fail-over isn't necessary. At least under simple configurations.

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    I'm using 64 bit pfsense and am having difficulties.  Fail over seems to work just fine, however all traffic seems to go through only one of the two gateways (Which ever is set to default).  I have both gateways set for tier 1.  I have a rule set up to allow all traffic to go through the gateway group.  I even set up rules to try to force certain traffic to go through the inactive gateway.  It didn't seem to help.  Can anyone confirm working gateway load balancing?  Do I need to setup manual outbound NAT rules?

                    -V

                    1 Reply Last reply Reply Quote 0
                    • H
                      horsedragon
                      last edited by

                      Can Gateway-Group work fine with PBR in last snap-version?

                      1 Reply Last reply Reply Quote 0
                      • C
                        cmb
                        last edited by

                        People, please stop hijacking threads. Do not post things in a thread that aren't addressing the original purpose/question of the thread. Start a new thread.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.