Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi-Provider with T1 and Business Cable

    Routing and Multi WAN
    4
    15
    4.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gamerpro2000
      last edited by

      lol, I probably should have asked how, so here I go…....How?

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        I  can't help with loadbalancing cause of i've no such environment but usually you can define what gateway you use by using routes or manual outbound nat

        1 Reply Last reply Reply Quote 0
        • H
          heper
          last edited by

          in pfsense 2.0 you can create gateway groups (system–>routing)
          a gateway group can be configured for failover by using different "Tiers". Setting gw1 at tier1 and gw2 at tier2 for example
          then you can use the firewall rules to assign certain traffic to a gateway group.

          you could even send http traffic over WAN1 while sending ftp only out by WAN2

          1 Reply Last reply Reply Quote 0
          • G
            gamerpro2000
            last edited by

            So, if you want information for the servers to pass over the T1's, how would I accomplish making sure all of their traffic moves over the T1's and everything else over the Charter Cable connection?  I think I've got everything else configured and ready to try.

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by

              Make a rule which makes sure that trafic from certain sources go out via certain gateway

              1 Reply Last reply Reply Quote 0
              • G
                gamerpro2000
                last edited by

                [EDIT]
                Ok, so I changed the original post, because we made a few network changes and I need to do things slightly differently.  Basically, I need a DMZ that has port filtering, but doesn't have NAT
                ing, so transparent filtering on the servers NIC from the T1 and the Cable connection to the workstations with fail-over to the T1 if the cable connection goes down.  How would I accomplish this?

                1 Reply Last reply Reply Quote 0
                • M
                  Metu69salemi
                  last edited by

                  If you have another interface and subnet to servers then you can do it easily with manual outbound nat. there you can control which ip-address it uses at outside world

                  1 Reply Last reply Reply Quote 0
                  • G
                    gamerpro2000
                    last edited by

                    I want the ability to assign the IP's directly to the servers, but still have filtering.  I don't want to NAT the servers.  Just port filtering.

                    1 Reply Last reply Reply Quote 0
                    • M
                      Metu69salemi
                      last edited by

                      Manual outbound nat has check box "Do Not NAT" click on it..

                      1 Reply Last reply Reply Quote 0
                      • G
                        gamerpro2000
                        last edited by

                        Can this be done per interface?  Where is the checkbox for it?

                        1 Reply Last reply Reply Quote 0
                        • T
                          tacfit
                          last edited by

                          Have you got pfsense up and running? The outbound NAT page lets you specify how all your internal hosts are presented to the public web. Typical NAT is the default, but you can change this to your heart's content.  Using multiple gateway groups as described above, with rules directing the traffic from/to specific servers via the specific gateway groups will accomplish everything you've described.

                          1 Reply Last reply Reply Quote 0
                          • G
                            gamerpro2000
                            last edited by

                            tacfit, thanks for your response.  Does this require that I have the servers NAT'ed in the first place, because I'm trying to pass through traffic directly with public addresses assigned to the interfaces on the servers.

                            1 Reply Last reply Reply Quote 0
                            • M
                              Metu69salemi
                              last edited by

                              You don't have to have nat on servers, but if you do it would be easier to access those servers in same subnet. create a virtual pfsense machine to see what it's capable of or try to read documentation. then you see that this product can do almost everything except brew coffee or shave my beard

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.