Round Robin Wan Group - PF2 RC3???
-
Can you post your fw rules? Had you set your DNS server for your WAN2 correctly?
I have 3 connections in LoadBalance and it's working fine. Although my hardware limits its efficiency sometimes.
I have also squid(lusca-cache) in transparent mode and a lot of different packages.
I thought that sticky connections is "must have" for working https browsing?
This also got me into confusion. Some https are ok with loadbalance while some are not. I found out that yahoomail and facebook are ok with loadbalancing.
It doesn't log me off when my WAN switches connections. -
I have enabled stick connections, but so far doesnt have seen any difference :-\
This is my firewall rules, where 'grupo' is my gateway group. I have set up the DNS for both gw!
hosting imagesOne important question: do I must to set up one of the GW as default?
thanks
-
Put this after your anti-lockout rule.
- * * WAN1 subnet * WAN1 GW none Allow WAN1 subnet to WAN1 Gateway
-
-
- WAN2 subnet * WAN2 GW none Allow WAN2 subnet to WAN2 Gateway
-
@srs:
One important question: do I must to set up one of the GW as default?
What's the purpose of your second rule? I think that's the reason why load balance doesn't work. Kindly disable it and check if it works.
If it still doesn't work, add this in your floating rule:
* * * * * grupo none -
Yes as jikjik101 says, the rules are processed from the top down so you have to have your load balancing rule above your 'l7' rule.
Steve
-
ok guys, I have done everything you asked to but it seems not be working yet:
- created two rules after my anti-lockout rule (wan1 subnet to wan1 gw and wan2 subnet to want2 gw)
- created the floating rule with direction IN
- all rules in the top
- no gw are defined to default
one question: in System> Routing > Routes I have this:
Network Gateway Interface Description
0.0.0.0/32 WAN1GW WANShouldn't I have a rule like this to Wan2gw, or for the group? with this rule am I telling that all the lan traffic should be routed to WAN1?
-
Ok I'm not sure what you have ended up with in your firewall section.
To get loadbalancing working you only need one rule. Once it's working then add other rules to do other things. Take a look at my rules for my LAN2 interface below.I have three rules:
1. This allows me to route to other internal subnets, e.g. Lan1 and Lan3. I need this because otherwise traffic for Lan1 would be routed to the external gateway instead of internally.2. This rule routes outgoing traffic to the loadbalancing gateway. This is the only rule you need!
3. This rule allow outgoing traffic to pass if I have disabled the loadbalancing rule. Some sites won't work with loadbalancing.
I don't know why you have that route in the static route table. If you don't have a good reason to have it there I would delete it.
I don't have sticky connections enabled.
I don't have any floating rules.
I have WAN1 set as the default gateway. This mean that traffic not routed to the Loadbalancing gateway will use WAN1.Steve
-
it's working now ;D ;D
I think the problem was with that static route, in Gateways > Route. I deleted it and now when I use pfsense's show IP page, it rotates between my gw!
Now, I supose that when one gw is down, based on latency and packat loss entered information, on every GW configuration, it will route traffic to the other, isn't?
thanks a lot for your help!
-
In the event of one gateway going down it will be removed from the group leaving only the other one.
This is dependant on what you have set the trigger level to in the group settings.
It's important that you set the system dns servers to have at least one using each gateway otherwise you could loose dns.Steve
-
for simplicity sake, to make the system do a loadbalance,
put your gw in same tier and in the fw under lan rule set your gw = loadbalance gw.
fw rules as stephenw10 said is processed from top to bottom.cheers…
-
thanks a lot for the tips!
;)