Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2 gateways with the same wan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    32 Posts 5 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK Offline
      KOM
      last edited by

      but I dont know exactly how make the rules for do the range of each gateway

      Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

      1 Reply Last reply Reply Quote 0
      • C Offline
        climbatize92
        last edited by

        @KOM:

        but I dont know exactly how make the rules for do the range of each gateway

        Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

        hello there,

        I have almost same isssue than topic starter… Except I want to use 2nd gateway for specific subnet (actually for DMZ).
        So I use default gateway for LAN interface, and in firewall rule for DMZ interface I put in advanced options to use my 2nd gateway of wan, but when I go on internet, my traffic still outbound from 1st default gateway, as servers from LAN does.

        I have AUTOMATICLY NAT option. Should I change it?

        1 Reply Last reply Reply Quote 0
        • A Offline
          Alucardko
          last edited by

          @KOM:

          but I dont know exactly how make the rules for do the range of each gateway

          Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

          I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

            What do you mean by routing gateway vs upstream gateway?  All gateways are upstream.

            I have AUTOMATICLY NAT option. Should I change it?

            No idea.  Start your own thread and post screenshots of your DMZ rules and multi-WAN config if you want someone to help you.

            1 Reply Last reply Reply Quote 0
            • A Offline
              Alucardko
              last edited by

              @KOM:

              I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

              What do you mean by routing gateway vs upstream gateway?  All gateways are upstream.

              I dont think so,I will try to explain you with this diagram

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                I'm sorry but your network diagram is even more confusing to me.  Why do you have 4 routers and 4 PCs?  What are all these things connected to?

                1 Reply Last reply Reply Quote 0
                • D Offline
                  doktornotor Banned
                  last edited by

                  1 Reply Last reply Reply Quote 0
                  • KOMK Offline
                    KOM
                    last edited by

                    Tell me about it.  It's starting to make my head hurt.

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      Alucardko
                      last edited by

                      @KOM:

                      Tell me about it.  It's starting to make my head hurt.

                      is the same pfsense with 4 different configurations, and the pc with the result of that configurations

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        WTF does upstream gateway 2, routing gateway 1 mean???

                        Its gibberish…

                        When they asked you to draw, they meant how your connected to what gateway 1 and gateway 2 is..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        1 Reply Last reply Reply Quote 0
                        • A Offline
                          Alucardko
                          last edited by

                          @johnpoz:

                          WTF does upstream gateway 2, routing gateway 1 mean???

                          Its gibberish…

                          When they asked you to draw, they meant how your connected to what gateway 1 and gateway 2 is..

                          my ISP provide me 2 gateways, in my pfsense I have 2 network cards (WAN and LAN), I have the 2 gateways configured in pfsense, my diagram only show what happen  with that 4 configurations (exchanging the gateways between upstream default and routing gate way), I only have one pc  in the pfsense LAN for see the results

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            And what is the point of giving you 2 gateways on the same connection?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07 | Lab VMs 2.8, 25.07

                            1 Reply Last reply Reply Quote 0
                            • A Offline
                              Alucardko
                              last edited by

                              @johnpoz:

                              And what is the point of giving you 2 gateways on the same connection?

                              I explain it, in the third post

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ Offline
                                johnpoz LAYER 8 Global Moderator
                                last edited by

                                that doesn't explain the POINT of it.. You only have 1 connection???  If the connection is down then both gateways would not be reachable!!  So does their gateway 1 go down while you still have a connection??  WTF???

                                And while on this second gateway you only get 3mbps from a 100mbps connection..  that is not really a failover or backup ;)

                                So they gave you this 2nd gateway and said use this is a backup?  Because our primary router goes down??

                                I see zero point to this sort of setup..  Point to the gateway that gives you 100mbps and call it a day..  If your internet goes down - try changing over to the other.. Does that work??  If so call the the ISP and say WTF!!!

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 25.07 | Lab VMs 2.8, 25.07

                                1 Reply Last reply Reply Quote 0
                                • A Offline
                                  Alucardko
                                  last edited by

                                  1. You are Wrong, I Dont know how is the ISP configuration but sometimes the 100mbps is down, then I can change the most important pc to another network (only changing the gateway)

                                  2.  I dont want failover, I know 3mbps is not enough for a network, is only for a few machines

                                  3. Yes

                                  4. Yes that Work, my ISP provide me from a fortinet, I cant see anything of that configuration and obvious I cant change anything of that

                                  Then you can help me, with the configuration that I want?

                                  1 Reply Last reply Reply Quote 0
                                  • D Offline
                                    doktornotor Banned
                                    last edited by

                                    I should have purchased more popcorn…

                                    @Alucardko:

                                    1. You are Wrong, I Dont know how is the ISP configuration but sometimes the 100mbps is down, then I can change the most important pc to another network (only changing the gateway)

                                    Wonderful. So, perhaps the ISP could implement a failover on their own infrastructure, instead of suggesting their customers to configure similar WTFs?!

                                    1 Reply Last reply Reply Quote 0
                                    • KOMK Offline
                                      KOM
                                      last edited by

                                      I don't think what you are trying to do is possible without another NIC, and at this point I am stepping back.

                                      1 Reply Last reply Reply Quote 0
                                      • D Offline
                                        doktornotor Banned
                                        last edited by

                                        Well you could create 2 VLANs on your WAN and keep on messing with this nonsense, but I'd rather switch ISPs.

                                        1 Reply Last reply Reply Quote 0
                                        • A Offline
                                          Alucardko
                                          last edited by

                                          I ask to my ISP about how exactly work my service, I will try explain you MY isp have 2 contracts, with 2 companies (one 100mbps, another 3mbps), then they have connected the 2 services to a fortinet, then they make my subnet 192.168.17.xx that subnet have 2 gateways (100mbps and 3bmps) then I can use any of that services, only changing the gateways

                                          1 Reply Last reply Reply Quote 0
                                          • D Offline
                                            doktornotor Banned
                                            last edited by

                                            @Alucardko:

                                            have 2 contracts, with 2 companies (one 100mbps, another 3mbps), then they have connected the 2 services to a fortinet

                                            Good that we know now, after two days of asking you to produce a network scheme.  ::) ::) ::) Once you've asked both ISPs about how each of their services should be configured, got rid of the Fortinet and plugged both to pfSense box, you might even get a working pfSense multi-WAN setup.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.