Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense 2.0 - load balancing between 2 ISP's

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    19 Posts 4 Posters 22.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      krisken
      last edited by

      @jimp:

      You don't have to delete the other rules, but perhaps you don't understand their purpose, and some other rule basics.

      First, rules are processed top-down, so the most specific rules need to go first. Anything that is the equivalent of a "pass all" rule should be at the very end, under any other specific rules.

      Second, you need to match specific traffic to direct them into those groups. Such as: pass * from <ip of="" a="" game="" console="">to * gateway: FO_WAN2_WAN1 - That would make traffic from that IP use WAN2 primarily, and fail to WAN1. Similar rules can be made for other traffic to prefer either WAN1 or WAN2.

      You didn't answer my question about the system logs. Are there any entries there that reference gateways?

      And are you using i386 or amd64? There isn't an i386 snapshot from today.</ip>

      Sorry, the version i use seems to be from yesterday.2.0-BETA4  (i386)
      built on Wed Sep 15 09:52:13 EDT 2010 FreeBSD 8.1-RELEASE

      The meaning of the thing i want to do is auto-loadbalancing.  So that the system use the LB_WAN1andWAN2 gateway everytime (so all traffic will be spread betwean WAN1 and WAN2).  When there is too much traffic using WAN1 (eg http download, ftp, newsservers, …), all the other traffic goes to WAN2.  In that case i can download and eg play some games at the same time without high latency.  Or i can download big files (several GB's) without slowing down the other users on the network.  Only in case WAN 1 or WAN2 is down (broken modem, link problemns, ...), everything (all traffic) have to go take the other gateway as default gateway.

      How can i see the logs of pfsense?

      And indeed, i'm just learning about some network stuff, and that little thing above is something i really want to use :-)

      WAN1 = Scarlet = 25mbit down, 3.5 mbit up (unmetered)
      WAN2 = Dommel = 30mbit down, 4.5mbit up (unmetered)

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That snapshot will have broken load balancing. Wait for a new snapshot.

        Logs are under Status > System Logs

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • K
          krisken
          last edited by

          Do i understand you that when there is a new snapshot available (without the bug), everything should work like i want to (see above)?

          And that the logs will be at status=> logs…sorry so logic that i didn't see it :)

          Sep 16 17:20:31 dhcpd: Copyright 2004-2008 Internet Systems Consortium.
          Sep 16 17:20:31 dhcpd: All rights reserved.
          Sep 16 17:20:31 dhcpd: For info, please visit http://www.isc.org/sw/dhcp/
          Sep 16 17:20:31 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 17:20:31 last message repeated 2 times
          Sep 16 17:20:31 check_reload_status: reloading filter
          Sep 16 17:20:31 php: : Gateways status could not be determined, considering all as up/active.
          Sep 16 17:20:31 last message repeated 2 times
          Sep 16 17:20:31 php: : The gateway: LB_WAN1andWAN2 is invalid/unkown not using it.
          Sep 16 17:20:32 php: : The gateway: FO_WAN2_WAN1 is invalid/unkown not using it.
          Sep 16 17:20:32 php: : The gateway: FO_WAN1_WAN2 is invalid/unkown not using it.
          Sep 16 17:22:08 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 17:22:08 dnsmasq[8859]: read /etc/hosts - 2 addresses
          Sep 16 17:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 17:46:52 dnsmasq[8859]: read /etc/hosts - 2 addresses
          Sep 16 17:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 17:51:45 php: /index.php: Successful login for user 'admin' from: 10.0.0.243
          Sep 16 17:51:45 check_reload_status: syncing firewall
          Sep 16 17:51:47 check_reload_status: reloading filter
          Sep 16 17:51:48 php: : Gateways status could not be determined, considering all as up/active.
          Sep 16 17:51:48 last message repeated 2 times
          Sep 16 17:51:48 php: : The gateway: LB_WAN1andWAN2 is invalid/unkown not using it.
          Sep 16 17:51:48 php: : The gateway: FO_WAN2_WAN1 is invalid/unkown not using it.
          Sep 16 17:51:48 php: : The gateway: FO_WAN1_WAN2 is invalid/unkown not using it.
          Sep 16 17:52:08 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 17:52:08 dnsmasq[8859]: read /etc/hosts - 2 addresses
          Sep 16 17:52:08 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 18:13:12 check_reload_status: syncing firewall
          Sep 16 18:16:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 18:16:52 dnsmasq[8859]: read /etc/hosts - 2 addresses
          Sep 16 18:16:52 last message repeated 2 times
          Sep 16 18:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 18:46:52 dnsmasq[8859]: read /etc/hosts - 2 addresses
          Sep 16 18:52:08 last message repeated 4 times
          Sep 16 18:52:08 last message repeated 2 times
          Sep 16 19:16:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 19:16:52 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 19:16:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 19:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 19:46:52 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 19:46:52 last message repeated 2 times
          Sep 16 20:16:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 20:16:52 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 20:16:52 last message repeated 3 times
          Sep 16 20:16:52 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 20:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 20:46:52 dnsmasq[8859]: read /etc/hosts - 1 addresses
          Sep 16 20:46:52 dhcpleases: Ignoring DHCP lease for wifi.office.it2go.eu because it has an illegal domain part
          Sep 16 20:54:24 php: /index.php: Successful login for user 'admin' from: 10.0.0.235
          Sep 16 21:11:46 php: /index.php: Successful login for user 'admin' from: 10.0.0.235

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            The next new snapshot should have enough of the fixes to let your load balancing work, yes.

            Sep 16 17:20:31    php: : The gateway: LB_WAN1andWAN2 is invalid/unkown not using it.
            Sep 16 17:20:32    php: : The gateway: FO_WAN2_WAN1 is invalid/unkown not using it.
            Sep 16 17:20:32    php: : The gateway: FO_WAN1_WAN2 is invalid/unkown not using it.
            

            That is what I was referring to, which indicates you are on a snapshot with broken load balancing for dynamic gateways.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • K
              krisken
              last edited by

              Super!  So the only thing i have to do is … wait for a new snapshot. 
              When the update is there, i shouldn't change a thing to my config?  Neither in the firewall rules?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                The config should be ok. Just install the update and when it boots up it should hopefully all work.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • K
                  krisken
                  last edited by

                  @jimp:

                  The config should be ok. Just install the update and when it boots up it should hopefully all work.

                  OK, i'll let you know using this thread.
                  Any idea when a snapshot should be available with that bug fixed?

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    A few more hours. It's building now.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • K
                      krisken
                      last edited by

                      @jimp:

                      A few more hours. It's building now.

                      Super!  i'm waiting for it
                      Thank you for the great help!

                      1 Reply Last reply Reply Quote 0
                      • K
                        krisken
                        last edited by

                        Just downloaded this new firmware to my pfsense router and it works great now.  If i hit F5 several times on www.watismijnip.be (kind of whatismyip.com) i get a mix between dommel and scarlet.
                        Thanks guys!!

                        1 Reply Last reply Reply Quote 0
                        • L
                          leap
                          last edited by

                          Is the hotfixed available for load balancing now?

                          Cheer
                          Leap

                          1 Reply Last reply Reply Quote 0
                          • jimpJ
                            jimp Rebel Alliance Developer Netgate
                            last edited by

                            @leap:

                            Is the hotfixed available for load balancing now?

                            Yes, It should be fixed in current snapshots.

                            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            1 Reply Last reply Reply Quote 0
                            • M
                              muffin
                              last edited by

                              Hi jimp,
                              Should this have fixed the failover issue as well? Since updating to BETA4 WAN failover is no longer working correctly.
                              I have the same issue posted here: http://forum.pfsense.org/index.php/topic,28415.0.html
                              When a link goes down it will not automatically flick over… im guessing because its not retrieving the info for the gateways?
                              This is the error appearing in the logs:

                              php: : Gateways status could not be determined, considering all as up/active.
                              

                              Also i am running the latest snapshot:

                              2.0-BETA4  (i386)
                              built on Sat Sep 18 23:15:00 EDT 2010

                              Cheers.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.