Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Sticky connections - Multi WAN

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      fusionp
      last edited by

      Just a couple quick questions on this.

      1. Do I have to restart pfsense after enabling this for it to take affect?
      2. what would be the recommended time to keep states?

      This morning I enabled it with a 5 second timeout, and I had a user still unable to login to her banking website….

      Do I need to set the time higher? Do I need to reboot pfsense before it takes affect?

      thanks

      1 Reply Last reply Reply Quote 0
      • H Offline
        heper
        last edited by

        https will always have issue when loadbalancing.

        a)create a gateway group: failover_https (different tiers)
        b)create a PASS rule on lan, (on top), with dest-port: https, gateway: failover_https

        1 Reply Last reply Reply Quote 0
        • F Offline
          fusionp
          last edited by

          Thanks Heper….once again!  :)

          1 Reply Last reply Reply Quote 0
          • M Offline
            markn62
            last edited by

            I'm not sure what you accomplished Heper?  Are you saying pass all https traffic Wan 1 or 2, not balanced? If not, different tier relative to what, the load balance tier 1?  I have the same issue.  I first plopped a Lan pass rule putting all https on Wan2 just above the loadbalance catchall (Wan1+2) at the bottom. Problem is Netflix is on https so the balance becomes very imbalanced.

            Another issue is dynamic "per ip" rate limiting. I limit, on the loadbalance rule, with values just below the aggregate of Wan1+2 both having an equal provision. However, load balance is never equal and gets more unbalanced when sticky connections are applied so the modem buffer gets hit on occasion increasing latency during high load.  I can't figure out a way to apply separate limiters on each Wan and still load balance both Wan's.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.