Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow connection with load balance

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      clarknova
      last edited by

      Does your default PASS rule on the LAN use the gateway group as its gateway? You may want to post screen shots of the LAN firewall rules page.

      db

      1 Reply Last reply Reply Quote 0
      • A
        argie01
        last edited by

        Hello,

        these are the screenshots of FW rules from LAN and 2 WANs. The rest of tabs hasn't any rule.

        FWr1.jpg
        FWr1.jpg_thumb
        FWr2.jpg
        FWr2.jpg_thumb
        FWr3.jpg
        FWr3.jpg_thumb

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Of the firewall rules you have on LAN only your first rule (gateway WANG1) will ever be used.

          You may have those other rules in place so that you can easily disable the loadbalancing?

          Steve

          1 Reply Last reply Reply Quote 0
          • A
            argie01
            last edited by

            Yes, I realize that only the first rule will ever be used. WANG1 is the Group that contains both WAN.

            I put the others two rules permitting traffic for every WAN just in case.

            But do you see something wrong here that could be the cause for the slow speed?

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              No, not obviously. Your faster WAN (TelWAN?) is set to to tier1 in the gateway group so all your traffic should be going via that.

              What happens if you set the gateway to TelWAN directly, rather than via the group?

              The only thing that you have slightly unusual is your DNS arrangement. I'm just wondering if DNS requests are being routed incorrectly and there is some timeout you have to wait for.

              Incidentally have you tested the failover function? Usually you have ensure you have DNS servers set for each WAN connection in pfSense, or DNS servers that can be reached on each WAN. However since you are using only external DNS this may not be a problem for you. Are you using pfSense for DHCP?

              Steve

              1 Reply Last reply Reply Quote 0
              • A
                argie01
                last edited by

                the faster WAN is VODWAN. TELWAN is a backup WAN.
                When I did a test with every WAN individually the speed was OK.

                I tested the failover unconnecting the wire from one WAN, and the speed still was a little slower. I could browse internet, but the speed was really poor.

                I have internal DNS (LAN) servers setup just in TELWAN. I wasn't able to find a way to assign internal DNS to VODWAN. In fact, the only way I found to setup internal DNS to TELWAN was using CLI.
                But both DNS could be used on both WAN, without problem.

                I'm not using pfSense as DHCP server. I just have enabled DNS Forwarder on PFS, but I don't know if this is necessary on my network.

                FWr4.jpg
                FWr4.jpg_thumb
                FWr5.jpg
                FWr5.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • A
                  argie01
                  last edited by

                  Hi,

                  any help, please?

                  thank you!

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Why do you have a gateway on LAN? Just for monitoring?

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • A
                      argie01
                      last edited by

                      No, that gateway is the main switch, and it also works as a router between VLANs.

                      1 Reply Last reply Reply Quote 0
                      • A
                        argie01
                        last edited by

                        eooo :)

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          I have no answers I'm afraid.  :(

                          So you have VLANs but you're not using pfSense with them directly?
                          I'm still not sure why you need a gateway on LAN.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.