Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Round Robin Wan Group - PF2 RC3???

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    16 Posts 5 Posters 8.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GruensFroeschliG
      GruensFroeschli
      last edited by

      Also did you actually use this balancing pool in the firewall rules on the interface on which connections are created? (in your case probably LAN).

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        I thought that sticky connections is "must have" for working https browsing?

        1 Reply Last reply Reply Quote 0
        • S
          srs
          last edited by

          @stephenw10: it may be one connection, if it is using full bandwith; I tested pfsense's site ip discover and it really doesnt work for me either, only showing my WAN1 ip no matter how many times I hit F5 key.

          I don't know where to enable 'stick connections', can you guys tell me?

          @GruensFroeschli: yes, I have updated my firewall rules in order that lan traffic is being forwarded to group gateway.

          thanks for your considerations!

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Sticky connections can be set in the gui: System >> Advanced >> Miscellaneous.

            If you try speedtest.net do you still only have traffic on one interface?

            Steve

            1 Reply Last reply Reply Quote 0
            • J
              jikjik101
              last edited by

              Can you post your fw rules? Had you set your DNS server for your WAN2 correctly?

              I have 3 connections in LoadBalance and it's working fine. Although my hardware limits its efficiency sometimes.

              I have also squid(lusca-cache) in transparent mode and a lot of different packages.

              @Metu69salemi:

              I thought that sticky connections is "must have" for working https browsing?

              This also got me into confusion. Some https are ok with loadbalance while some are not. I found out that yahoomail and facebook are ok with loadbalancing.
              It doesn't log me off when my WAN switches connections.

              1 Reply Last reply Reply Quote 0
              • S
                srs
                last edited by

                I have enabled stick connections, but so far doesnt have seen any difference  :-\

                This is my firewall rules, where 'grupo' is my gateway group. I have set up the DNS for both gw!

                hosting images

                One important question: do I must to set up one of the GW as default?

                thanks

                1 Reply Last reply Reply Quote 0
                • J
                  jikjik101
                  last edited by

                  Put this after your anti-lockout rule.

                  • *   *   WAN1 subnet   *   WAN1 GW   none       Allow WAN1 subnet to WAN1 Gateway
                      • WAN2 subnet * WAN2 GW   none   Allow WAN2 subnet to WAN2 Gateway

                  @srs:

                  One important question: do I must to set up one of the GW as default?

                  What's the purpose of your second rule? I think that's the reason why load balance doesn't work. Kindly disable it and check if it works.

                  If it still doesn't work, add this in your floating rule:
                   *   *   *   *   *   grupo   none

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Yes as jikjik101 says, the rules are processed from the top down so you have to have your load balancing rule above your 'l7' rule.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • S
                      srs
                      last edited by

                      ok guys, I have done everything you asked to but it seems not be working yet:

                      • created two rules after my anti-lockout rule (wan1 subnet to wan1 gw and wan2 subnet to want2 gw)
                      • created the floating rule with direction IN
                      • all rules in the top
                      • no gw are defined to default

                      one question: in System> Routing > Routes I have this:
                      Network Gateway Interface Description
                      0.0.0.0/32 WAN1GW WAN

                      Shouldn't I have a rule like this to Wan2gw, or for the group? with this rule am I telling that all the lan traffic should be routed to WAN1?

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ok I'm not sure what you have ended up with in your firewall section.
                        To get loadbalancing working you only need one rule. Once it's working then add other rules to do other things. Take a look at my rules for my LAN2 interface below.

                        I have three rules:
                        1. This allows me to route to other internal subnets, e.g. Lan1 and Lan3. I need this because otherwise traffic for Lan1 would be routed to the external gateway instead of internally.

                        2. This rule routes outgoing traffic to the loadbalancing gateway. This is the only rule you need!

                        3. This rule allow outgoing traffic to pass if I have disabled the loadbalancing rule. Some sites won't work with loadbalancing.

                        I don't know why you have that route in the static route table. If you don't have a good reason to have it there I would delete it.

                        I don't have sticky connections enabled.
                        I don't have any floating rules.
                        I have WAN1 set as the default gateway. This mean that traffic not routed to the Loadbalancing gateway will use WAN1.

                        Steve

                        firewallrules1.jpg
                        firewallrules1.jpg_thumb

                        1 Reply Last reply Reply Quote 0
                        • S
                          srs
                          last edited by

                          @stephenw10

                          it's working now  ;D  ;D

                          I think the problem was with that static route, in Gateways > Route. I deleted it and now when I use pfsense's show IP page, it rotates between my gw!

                          Now, I supose that when one gw is down, based on latency and packat loss entered information, on every GW configuration, it will route traffic to the other, isn't?

                          thanks a lot for your help!

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            In the event of one gateway going down it will be removed from the group leaving only the other one.
                            This is dependant on what you have set the trigger level to in the group settings.
                            It's important that you set the system dns servers to have at least one using each gateway otherwise you could loose dns.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • J
                              jikjik101
                              last edited by

                              for simplicity sake, to make the system do a loadbalance,

                              put your gw in same tier and in the fw under lan rule set your gw = loadbalance gw.
                              fw rules as stephenw10 said is processed from top to bottom.

                              cheers…

                              1 Reply Last reply Reply Quote 0
                              • S
                                srs
                                last edited by

                                thanks a lot for the tips!
                                ;)

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.