Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi WAN and VLAN traffic

    Scheduled Pinned Locked Moved Routing and Multi WAN
    6 Posts 3 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      itamania
      last edited by

      Hi all,
      I have 5 VLANs setup in the office.
      I also have 2 WANs.
      When I configured WAN failover with Gateway Groups and added firewall rules to the VLAN to route traffic to the new group, my failover setup works, but I can no longer access machines on the other VLANs.

      Anyone can tip me how to accomplish this?
      TIA

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        In normal this are two different things. The VLANs are a two ending solution, starting at the switch and then
        ending at the LAN port of your pfSense, thats it. And then the second part is the WAN set up where this
        VLANs should be not in the game.

        Set up your LAN part and then your WAN part and don´t mix them together.

        1 Reply Last reply Reply Quote 0
        • I
          itamania
          last edited by

          Thanks Frank for your reply.
          I assume my VLANs are configured correctly.
          I have Three NIC on the pfsense machine (WAN1,WAN2, LAN), and I have the VLANs configured on the Cisco switch with matching VLANS interfaces added to pfsense, I can see the VLAN taggings in the packet logs etc.

          As soon as I route the traffic to WAN groups as oppose to specific WAN my ping test are failing.

          1 Reply Last reply Reply Quote 0
          • ?
            Guest
            last edited by

            I assume my VLANs are configured correctly.

            Ok, from the router to the switch tagged ports and 3 VLANs added should be not really the problem
            but if pfSense is routing then between the VLANs are their any firewall rules and/or restrictions?

            I have Three NIC on the pfsense machine (WAN1,WAN2, LAN), and I have the VLANs configured on the Cisco switch with matching VLANS interfaces added to pfsense, I can see the VLAN taggings in the packet logs etc.

            As soon as I route the traffic to WAN groups as oppose to specific WAN my ping test are failing.

            multi-wan [dual] and policy based routing with failover would be perhaps interesting you how to do it right.
            Load balancing and fail over with dual WAN.

            1 Reply Last reply Reply Quote 0
            • I
              itamania
              last edited by

              Thanks once again Frank.
              I ended up adding a specific firewall rule permitting traffic from VLAN-x to VLAN-x and moved it above the Failover Gatway Group rule.
              worked sweet.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                https://doc.pfsense.org/index.php/Bypassing_Policy_Routing

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.