Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Two Multi WAN firewall rules give different results

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 4 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      heper
      last edited by

      perhaps you should supply more info….

      like what is the exact error you are getting?
      what are your dns servers set at ?

      are you having a dns issue or is this actually a different issue ?

      1 Reply Last reply Reply Quote 0
      • A Offline
        alltime
        last edited by

        @heper:

        perhaps you should supply more info….

        like what is the exact error you are getting?
        what are your dns servers set at ?

        are you having a dns issue or is this actually a different issue ?

        Apologies, I could have supplied better information:

        8.8.8.8 using WAN1 as the gateway
        8.8.8.4 using WAN2 as the gateway

        There are no errors, however, I just noticed that when the second rule is set, we cannot ping external or internal IP's. So there must be a firewall rule blocking something. Our captive portal is set, however, even signed-in users experience the same issue.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          Google's second DNS server IP address is 8.8.4.4 not 8.8.8.4.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • A Offline
            alltime
            last edited by

            @Derelict:

            Google's second DNS server IP address is 8.8.4.4 not 8.8.8.4.

            Derelict, sorry that was a typo on my part. We are using:

            8.8.8.8
            8.8.4.4
            
            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              All your NAT rules in place for both WANs?

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • A Offline
                alltime
                last edited by

                @Derelict:

                All your NAT rules in place for both WANs?

                At this time, Automatic outbound NAT rule generation is selected within Outbound NAT. There is nothing in 1:1 or NPT. We do have port forwards, but you can see below that nothing is out of ordinary (as far as I know).

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  If you change the default gateway to the other WAN without changing the rule does it work?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    alltime
                    last edited by

                    @Derelict:

                    If you change the default gateway to the other WAN without changing the rule does it work?

                    Same results, we cannot ping anything internally/externally. I even tried modifying the first rule, by just adding the gateway portion in advanced settings but received the same results. The second that the rule is modified to include the gateways, the rule somehow stops all traffic. Btw, I really appreciate your help here because I quickly ran out of ideas.

                    Note: I can manually switch gateways and the internet continues to work on each connection as it should, so I know both connections are active.

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      I don't understand how manually switching gateways and changing the default route are two different things.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • A Offline
                        alltime
                        last edited by

                        What I meant is that going to Routing, if I make either connection the default gateway, traffic flows through  whichever as it should. My point was that both connections are definitely working so there is something strange going on.

                        1 Reply Last reply Reply Quote 0
                        • A Offline
                          alltime
                          last edited by

                          @Derelict:

                          I don't understand how manually switching gateways and changing the default route are two different things.

                          I would very curious to know if anyone running 2.2.4 is experiencing this issue. Fail-over works flawlessly, however, WAN load balancing is the issue where I force traffic through the Gateway Groups using firewall rules. I'm convinced that this feature simply does not work anywhere. This has worked in the past with 2.0, I remember. The comments of the following blog post kind of confirms it for me http://terraltech.com/multi-wan-load-balancing-with-pfsense/

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            cmb
                            last edited by

                            @UNet:

                            I'm convinced that this feature simply does not work anywhere. This has worked in the past with 2.0, I remember. The comments of the following blog post kind of confirms it for me http://terraltech.com/multi-wan-load-balancing-with-pfsense/

                            Of course it still works. The comments on that post no doubt from Squid users, where it's not hitting those rules at all.

                            You need to negate policy routing for LAN to LAN connectivity to work.
                            https://doc.pfsense.org/index.php/Bypassing_Policy_Routing

                            I'm guessing you're breaking your DNS maybe, if it's on one of the other internal subnets. Troubleshoot the issue, what works and what doesn't? IP connectivity to the Internet (ping 8.8.8.8/8.8.4.4/4.2.2.2)? DNS resolution work?

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.