Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow connection with load balance

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      argie01
      last edited by

      Hello,

      these are the screenshots of FW rules from LAN and 2 WANs. The rest of tabs hasn't any rule.

      FWr1.jpg
      FWr1.jpg_thumb
      FWr2.jpg
      FWr2.jpg_thumb
      FWr3.jpg
      FWr3.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Of the firewall rules you have on LAN only your first rule (gateway WANG1) will ever be used.

        You may have those other rules in place so that you can easily disable the loadbalancing?

        Steve

        1 Reply Last reply Reply Quote 0
        • A
          argie01
          last edited by

          Yes, I realize that only the first rule will ever be used. WANG1 is the Group that contains both WAN.

          I put the others two rules permitting traffic for every WAN just in case.

          But do you see something wrong here that could be the cause for the slow speed?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            No, not obviously. Your faster WAN (TelWAN?) is set to to tier1 in the gateway group so all your traffic should be going via that.

            What happens if you set the gateway to TelWAN directly, rather than via the group?

            The only thing that you have slightly unusual is your DNS arrangement. I'm just wondering if DNS requests are being routed incorrectly and there is some timeout you have to wait for.

            Incidentally have you tested the failover function? Usually you have ensure you have DNS servers set for each WAN connection in pfSense, or DNS servers that can be reached on each WAN. However since you are using only external DNS this may not be a problem for you. Are you using pfSense for DHCP?

            Steve

            1 Reply Last reply Reply Quote 0
            • A
              argie01
              last edited by

              the faster WAN is VODWAN. TELWAN is a backup WAN.
              When I did a test with every WAN individually the speed was OK.

              I tested the failover unconnecting the wire from one WAN, and the speed still was a little slower. I could browse internet, but the speed was really poor.

              I have internal DNS (LAN) servers setup just in TELWAN. I wasn't able to find a way to assign internal DNS to VODWAN. In fact, the only way I found to setup internal DNS to TELWAN was using CLI.
              But both DNS could be used on both WAN, without problem.

              I'm not using pfSense as DHCP server. I just have enabled DNS Forwarder on PFS, but I don't know if this is necessary on my network.

              FWr4.jpg
              FWr4.jpg_thumb
              FWr5.jpg
              FWr5.jpg_thumb

              1 Reply Last reply Reply Quote 0
              • A
                argie01
                last edited by

                Hi,

                any help, please?

                thank you!

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Why do you have a gateway on LAN? Just for monitoring?

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • A
                    argie01
                    last edited by

                    No, that gateway is the main switch, and it also works as a router between VLANs.

                    1 Reply Last reply Reply Quote 0
                    • A
                      argie01
                      last edited by

                      eooo :)

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        I have no answers I'm afraid.  :(

                        So you have VLANs but you're not using pfSense with them directly?
                        I'm still not sure why you need a gateway on LAN.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.