Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Symmetric setup with two houses

    Scheduled Pinned Locked Moved Routing and Multi WAN
    8 Posts 5 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      john duff
      last edited by

      Hi everybody

      I'm trying to install the following network, between my house and my brother's. There is only one ethernet cable inbetween.
      Both houses have a WAN connection, with a different provider.

      So here we go:

      House A:
      Router PFSENSE
      WAN Provider 1
      LAN A (192.168.10.X for instance)
      OPT1 interconnection
      Uses Provider 1 by default and Provider 2 in case of failure.
      Can access LAN B and can be accessed from LAN B

      House B:
      Router PFSENSE
      WAN Provider 2
      LAN B (192.168.20.X for instance)
      OPT1 interconnection
      Uses Provider 2 by default and Provider 1 in case of failure.
      Can access LAN A and can be accessed from LAN A

      What I don't get is how to setup the interconnection port, with the appropriate firewall rules.

      I've searched quite a lot but didn't find the solution. If the answer is somewhere on this forum in a place you know, please be kind enough to point it out.

      Cheers !
      ![two houses.jpg_thumb](/public/imported_attachments/1/two houses.jpg_thumb)
      ![two houses.jpg](/public/imported_attachments/1/two houses.jpg)

      1 Reply Last reply Reply Quote 0
      • P
        Perry
        last edited by

        Use VLAN with a managed switch at both sites. Some switch recommendations http://forum.pfsense.org/index.php/topic,36749.0.html

        /Perry
        doc.pfsense.org

        1 Reply Last reply Reply Quote 0
        • J
          john duff
          last edited by

          Thanks Perry for your advice. :) I've also been told this earlier, but managed switches cost something.

          Isn't it possible to do this directly with routing or vlan capabilities of pfsense ?

          I already have 2 "Openbrick E" small computers with 3 ethernet ports each that cost me almost nothing, and if I can avoid buying more equipment I wouldn't mind.

          Yeah, I know, I'm not only ignorant, I'm also poor…  :)

          1 Reply Last reply Reply Quote 0
          • G
            gollo
            last edited by

            I'm not 100% sure since I have never done it but you might be able to setup a Lan-to-Lan IPSEC tunnel over the OPT1 (aka interconnect) interface.  This would give you the benefit of hitting house 2 subnet direct from house 1 subnet and vice-versa.

            You could then firewall traffic coming out on your end and your brother could firewall traffic coming out on his end.

            1 Reply Last reply Reply Quote 0
            • J
              john duff
              last edited by

              Thanks gollo. It's a good idea, I'll give it a try.

              But then, how do I send incoming traffic on OPT1 to wan ? We also need to use each other's WAN in case the primary wan fails.

              1 Reply Last reply Reply Quote 0
              • X
                XIII
                last edited by

                You have the interconnect for the LANs working, though to have it do dual WAN at the same time you will need to either have another cable (or if you are doing 100mb networking you could use 4 pair for the LAN interconnect and the other 4 pair for the dual WAN) or do VLANs as Perry suggested.

                -Chris Stutzman
                Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
                Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
                freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
                Check out the pfSense Wiki

                1 Reply Last reply Reply Quote 0
                • H
                  heper
                  last edited by

                  i would think you could look into this scenario:

                  site-to-site openvpn between the 2 houses over the WAN connections (do not let it create routes)

                  on the interconnects  you set static ip's on the same subnet on both ends with rules to allow traffic from  and to lan <–> opts

                  figure out how OSPF package can help you with routing all traffic over interconnects and if fails over WAN (i'm guessing you probably have to mess with metrics)

                  1 Reply Last reply Reply Quote 0
                  • J
                    john duff
                    last edited by

                    @heper:

                    figure out how OSPF package can help you with routing all traffic over interconnects and if fails over WAN

                    Brilliant idea. I'll try that too.
                    Once I get a working setup I'll share it here.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.