Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Loadbalancer

    Scheduled Pinned Locked Moved Routing and Multi WAN
    25 Posts 5 Posters 7.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      That looks correct. Is it working?

      1 Reply Last reply Reply Quote 0
      • Z
        zetar
        last edited by

        hello, the same can not be closed immediately, the session will attach screenshots. of the entire page, I do not use port 443.
        Thanks.

        login.png_thumb
        ![Session out.png](/public/imported_attachments/1/Session out.png)
        login.png
        ![Session out.png_thumb](/public/imported_attachments/1/Session out.png_thumb)

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Hmmm,
          Seems strange not to be using https.
          You could still try adding a rule to send all traffic with destination mail.virgilio.it to one gateway.
          You cannot enter a URL though you have to enter it as a single host: 212.48.10.165.

          Steve

          1 Reply Last reply Reply Quote 0
          • Z
            zetar
            last edited by

            It should not be in any of the ways I've tried.
            We do this, if I wanted to make an address on the LAN should be on a single gateway, that rule should apply, make me an example.
            Thanks.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              If you wanted to just have a single LAN address use one WAN then your rule should be:

              
              Proto 	Source 	   Port Destination Port Gateway Queue
              *	yourIP     *	* 	    *    WAN1    none	
              

              Steve

              1 Reply Last reply Reply Quote 0
              • A
                aries
                last edited by

                my experience in virgilio.it that is not properly loaded or redirected is when i used squid with filtering…but i guess your not using squid and do some filtering right?

                1 Reply Last reply Reply Quote 0
                • Z
                  zetar
                  last edited by

                  Thank you for your reply.
                  That rule works fine.
                  I do not think there is a solution to the problem in question, at least I have done many tests but have not solved, if the other ideas to try, I'd be happy to try.
                  Thanks again.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    If you enable logging on that rule and then login to your webmail then you can check the logs to see exactly what connections are required. Then you can make a rule to fit that information.
                    Remember to turn off logging on the rule afterwards or you will quickly fill the logs.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • Z
                      zetar
                      last edited by

                      @aries:

                      my experience in virgilio.it that is not properly loaded or redirected is when i used squid with filtering…but i guess your not using squid and do some filtering right?

                      I do not understand, do not use Squid.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        It that from a packet capture?
                        You should probably remove it since it lists your own IP.

                        I had intended you to use the firewall log.

                        Anyway I can see your address performing a DNS lookup on three separate URLs.
                        www.virgilio.it, i.plug.it and secure-it.imrworldwide.com.

                        imrworldwide appears to be a vendor of tracking software so probably not needed.
                        This is not a complete log of your sign in so I can't tell you what rule you might use.

                        You need to turn on logging on your firewall LAN rule. Then log into your mail. Then look at the firewall logs.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • Z
                          zetar
                          last edited by

                          Thanks, I removed the previous post, if I understand it was not necessary to enter.
                          I can not understand how to make the registration of firewall log.
                          Would you give me a hint on how to do things I have not yet understood well
                          Thanks.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Ok.
                            Go to Firewall>>Rules>>Lan edit your rule for webmail access from your IP. (click the 'e')
                            You need to enable logging on that rule.

                            Now 'save' and 'apply settings'. You rules should look something like this:

                            Note: The blue 'i' shows that logging is enabled. Your IP address will be different.

                            Now everything that uses that rule will be logged in the firewall log: status>>system logs>>firewall.

                            So log into your webmail and then check the log to see what connections were made.

                            Disable logging again afterwards.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • Z
                              zetar
                              last edited by

                              Thanks for the advice.
                              This is the place to be when I put user name and password and open the folder "inbox".

                              May 25 19:11:02 LAN 172.25.14.6:53793 212.48.8.171:443 TCP:S
                              pass
                              May 25 19:11:02 LAN 172.25.14.6:53794 212.48.8.171:80 TCP:S
                              pass
                              May 25 19:11:02 LAN 172.25.14.6:53795 212.48.8.171:80 TCP:S
                              pass
                              May 25 19:11:02 LAN 172.25.14.6:53796 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:03 LAN 172.25.14.6:53797 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53798 212.239.41.101:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53799 66.235.156.132:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53800 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53801 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53802 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53803 212.48.11.161:80 TCP:S
                              pass
                              May 25 19:11:05 LAN 172.25.14.6:53804 212.48.11.161:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53805 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53806 212.48.1.154:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53807 212.48.1.154:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53808 80.252.91.41:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53809 80.252.91.41:80 TCP:S
                              pass
                              May 25 19:11:06 LAN 172.25.14.6:53810 212.48.1.156:80 TCP:S
                              pass
                              May 25 19:11:21 LAN 172.25.14.6:53816 195.128.234.84:80 TCP:S
                              pass
                              May 25 19:12:01 LAN 172.25.14.6:53835 209.85.229.100:80 TCP:S
                              pass
                              May 25 19:12:21 LAN 172.25.14.6:53842 195.128.234.84:80 TCP:S
                              pass
                              May 25 19:12:40 LAN 172.25.14.6:53856 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:13:11 LAN 172.25.14.6:53862 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:13:21 LAN 172.25.14.6:53867 195.128.234.84:80 TCP:S
                              pass
                              May 25 19:13:42 LAN 172.25.14.6:53885 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:14:13 LAN 172.25.14.6:53895 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:14:21 LAN 172.25.14.6:53897 195.128.234.84:80 TCP:S
                              pass
                              May 25 19:14:44 LAN 172.25.14.6:53912 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:15:05 LAN 172.25.14.6:53916 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:15:06 LAN 172.25.14.6:53917 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:15:08 LAN 172.25.14.6:53918 62.211.72.133:80 TCP:S
                              pass
                              May 25 19:15:08 LAN 172.25.14.6:53920 212.239.41.101:80 TCP:S
                              pass
                              May 25 19:15:09 LAN 172.25.14.6:53921 66.235.156.132:80 TCP:S
                              pass
                              May 25 19:15:09 LAN 172.25.14.6:53922 212.48.1.154:80 TCP:S
                              pass
                              May 25 19:15:09 LAN 172.25.14.6:53923 212.48.1.154:80 TCP:S
                              pass
                              May 25 19:15:09 LAN 172.25.14.6:53924 80.252.91.41:80 TCP:S
                              pass
                              May 25 19:15:09 LAN 172.25.14.6:53925 80.252.91.41:80 TCP:S
                              pass
                              May 25 19:15:10 LAN 172.25.14.6:53926 212.48.1.156:80 TCP:S
                              pass
                              May 25 19:15:21 LAN 172.25.14.6:53931 195.128.234.84:80 TCP:S

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Hmm, OK.
                                So it looks like:
                                212.48.8.171
                                62.211.72.133
                                At least are involved. But also 212.48.10.165 is mail.virgilio.it. so maybe we should include 212.48.0.0/16.

                                So change your lan rules to:

                                Try that.

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • Z
                                  zetar
                                  last edited by

                                  You're a really great, now works without problems.
                                  I replaced the single IP subnet with all the LAN and I think that works by any location.
                                  Thanks, but thank you very much for your cooperation.
                                  Known, but those of Virgil can not do like the others …
                                  hei hei ..

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.