Dual wan- wan1 down - no web browsing
-
jimp,
Thank You much for the reply. I do not have any staic route for either of the dns servers. I must have misunderstood the doc on the multi wan setup. I took it to be if you used the dns servers for each of the two wan monitor ip's you didnt need to do a static route entry.
I'll go back through the multi-wan doc on here and look it over again,
What you say makes sense in that if no static route no dns being served to the still working wan link.
OK. I did check again and the downed wan link I can not ping that wans gateway.my static route would be Interface WAN > dest=d.n.s.ip/32 gateway = wan.gateway.ip
Barry
-
Normally setting a monitor IP will add a route automatically. I'm not sure why that did not appear in the route output you showed.
That static route sounds fine.
-
jimp,
If you look at the screenshot i attached at line # two(opt1/wan2/fxp3) you can see the .242(dns-ip) shows a route to .33(gateway). This is without any static route added manually.
What puzzles me(if you look a few lines down) is the .34 address which is in fact the opt1/wan2 (public-static ipaddress)shows as interface 'lo'? If I look at the same Diagnostics>Routes today that entry is not there. I have not changed a thing or even rebooted the pfSense machine.
I did manually add the static route just earlier today for the opt1/wan2 for dnsip/32 to opt1 gateway, & when I unplug wan ethernet I can no longer ping opt1>dns ip address? strange.
I know this gets very frustrating for someone to try and give help,without knowing so many variables involved in each pfSense setup.Wanted to add:
I am seeing the exact same behavior on two pfSense boxes that I set up for two different school buildings.
I may add that at each of the buildings:
WAN= plugs into an bridge that is fed to the building from a "wireless consortium of a few local schools" that is equivilant to a t1 line. This has a static IP.
OPT1= plugs into a convention dsl router that is supplied by Frontier.This is a static IP.
Didn't know if this info may help someone with a possible idea.
My problem is we have an internal email server so I can not have either one of the two down for any length of time, as I will be getting phone calls big time! Everyone now has blackberries that hit the email server every 5 mins!,,,:(.
I'll try and go in on a Sunday eve. and do some extensive hit and miss with this delima.It's a puzzler that when the WAN ethernet is unplugged the OPT1 dns server is no longer pingable,and hence no web browsing? This is with or without adding the two wan's dns servers to a static route.
Thank You,
Barry -
More info on the setup.
Should i be seeing on any client on the network my actual internal ip address? This is what the client machines sees as their ip address.
Web browsing does work fine, but it seems each client should be seeing one of the two public ip addresses that pfSense box runs on?
I thought I was fairly familiar with Squid (and Squidguard) but I am guessing this needs to be adjusted somewere to make the clients see their public ip address?
I have not enabled nat reflection. Should I enable this?Thank you,
Barry -
I didn't notice you were using squid before (an oversight on my part) – squid does not work with multi-WAN on 1.2.x. It only routes out WAN -- which is why you are not able to browse when WAN1 is down.
Your local network clients will only talk to your pfSense box on the LAN side. They don't talk directly to the 'public' IPs in most cases. (NAT reflection makes it look like they do, but they really don't) That will have no bearing on squid being compatible with multi-WAN setups.
It is possible to load balance squid in the 2.0 beta, but it's a bit complex yet and not very intuitive. There are some threads in the 2.0 forum with input on how to do this.
-
jimp,
Thank You much for the good explanation. At least now I know what the prob is. Soo, If I simply disable Squid( or uninstall Squid/Squidguard),,the clients should be able to web browse OK? I am guessing with my setup.
That's a bummer as for a school scenario we have to have some sort of content filtering in place.
I must have missed this altogether in that Squid will only work on WAN(1).
I'll do some better searching next time I guess.Thank You,
Barry -
If you use a separate squid server (in a DMZ) you could get that to balance and still have your content filtering. It's just that the squid process runs on the router itself, and the policy routing needed for multi-wan only works in 1.2.3 when traffic enters the LAN, not when it leaves WAN.
-
jimp,
is there anyway I could enter a lan rule that if WAN went down that port 80 would bypass squid and come/go directly out OPT1? This will still make web browsing transparent(although unfiltered) for users and wouldn't have to babysit the pfSense box should WAN go down?
Thanks,
Barry -
No, that isn't possible. The transparent redirect is a NAT rule, not a firewall rule, and can't be overridden in that manner.
-
That's a bummer as for a school scenario we have to have some sort of content filtering in place.
Have you tried using OpenDNS.
-
Hi Perry,
Thanks for the suggestion. I have 'heard' a lot about OpenDNS,but never really checked into how it works. I'll do a search here in the forums to see what I can find. Have you set up a pfSense box to work with OpeDNS,and squid to work on either of the two WAN links?
Thanks,
Barry -
Hello All,
Thanks to All of suggestions made. I have decided a pretty easy workaround for our setup is to ( if WAN goes down) to do Squid,uncheck allow users on proxy, Squidguard,uncheck enable SquidGuard, Do status>Services, stop Squidguard,stop Squid.
This will allow web browsing,on WAN2 although unfiltered of course. This will be much simpler as our previous firewall setup,as with it,if either WAN went down I had to physically go to server room and readjust wires on the firewall. ( I have to be a two remote buildings besides here during the day.
Once the WAN is restored I can reset Squid back to original setup.
With this setup I can at least WEB-UI into the pfsense from any building I am at,and make changes and web browsing will be restored in just a few minutes after I start getting phone calls telling me internet is down,,,:)
BTW: I did try the Opendns suggestion and I got the same results as with the two ISP dns servers.
I may eventually try pfSense 2.0 and see if I can get Squid to work on both WANs.
I have quite a time getting everything ironed out on these two pfSense boxes at two buildings I would like to leave them as they are for right now.Thank You,
Barry Cisna