Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Gateway policy routing

    Scheduled Pinned Locked Moved Routing and Multi WAN
    7 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      slv
      last edited by

      Hi

      I've got setup 1 LAN and 3 WANs.

      WAN 1 is my default gateway.
      WAN2 and WAN3 are in multiWan setup.

      Source based routing is working fine, but i would go one step further and set rules based on gateway.

      My pfSense machine has primary IP 192.168.1.1 and 2 virtual IP's 192.168.1.2 192.168.1.3
      If client set default gateway to 192.168.1.2 routing should go via WAN2, and if set gateway to 192.168.1.3 via WAN3

      Is it possible to do this?
      Maybe other ideas how to redirect traffic changing setup on workstations?

      Best regards
      Slv

      1 Reply Last reply Reply Quote 0
      • H Offline
        heper
        last edited by

        Why?

        1 Reply Last reply Reply Quote 0
        • S Offline
          slv
          last edited by

          Some workstations are configured to use multiWan connection only due to generate heavy traffic, but in some cases (firewall rules on the other end) they need to route by specific (not random) gateway.
          One WAN2 is static IP, WAN3 is dynamic IP and it is much easier to change gateway on workstations than on router due to high frequency of changes.

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            There's no way for different routing dependent on the incoming address. But it could be done by source addresses.
            So just segment your LAN in subnets and add policy routing rules to fit your needs. After, you have control over the routing by changing the clients IP. That won't be a bigger undertaking than changing the gateway.

            1 Reply Last reply Reply Quote 0
            • S Offline
              slv
              last edited by

              I was thinking about that, but all workstations must be in the same network…

              In other hand I can add another class to each workstation… i't should work.

              Thanks for an idea!

              1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann
                last edited by

                I meant the segmentation only for rule handling. The whole LAN should stay a broadcast domain, of course.

                So e.g. if your LAN is 192.168.1.0/24
                You can route traffic from source
                192.168.1.192/27 to WAN2
                192.168.1.224/27 to WAN3

                1 Reply Last reply Reply Quote 0
                • S Offline
                  slv
                  last edited by

                  This type of rules I've used to route traffic via MultiWan because this is default behavior for this subnet.

                  Now I added 2 virtual IP: 192.168.10.1/24 and 192.168.11.1
                  Firewall rules are set to route via specific WAN according to source network and this i working fine.

                  Thanks for an idea.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.