Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule to make a website go through another wan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    12 Posts 3 Posters 860 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Online
      johnpoz LAYER 8 Global Moderator
      last edited by

      simple policy route can do that yeah.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

      1 Reply Last reply Reply Quote 0
      • B Offline
        bashar.saeed
        last edited by

        Hello @johnpoz

        Thank you for your reply.  Can you please elaborate how can i do that. Im still a newbe in pfsense.

        Thanks

        1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by

          Create a rule on your interface where clients sit that you want to go out a specific gateway.  Pick the specific gateway you want them to go out.

          Keep in mind rules are evaluated top down, first rule to trigger wins, no other rules are evaluated.

          See example attached - I currently do not have it enabled.  But when enabled this rule says hey if source is 192.168.9.100 and its ipv4 tcp only, and his destination is anything other than rfc1918 space (notice the !) then go out a vpn gateway I have setup.

          So notice my normal wan public IP, I then enable the rule - kill the states for that client.  Then do a refresh and you see my new public IP for that client is now my vpn connection.

          examplepolicyroute.png
          examplepolicyroute.png_thumb
          ruleenabled.png
          ruleenabled.png_thumb

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

          1 Reply Last reply Reply Quote 0
          • B Offline
            bashar.saeed
            last edited by

            Thank you for the clarification. If i want all users in my lan that are accessing www.cnn.com tp go to a specific gateway.  What should i put in the source and destination.

            1 Reply Last reply Reply Quote 0
            • johnpozJ Online
              johnpoz LAYER 8 Global Moderator
              last edited by

              Problem with www.cnn.com is hosted on CDN and IPs going to change all the time or could..  Fastly net.. But create a rule that where destinations you want to use your other wan is in an alias.. This should work.. But if for some reason if the client gets/has a different IP then pfsense has in the alias then it could go out your normal default wan.  But as long as your clients are using pfsense as their dns it should never happen.. But if you were pointing say clients to some other dns than what pfsense uses then sure that could happen.

              You can always see what IPs are in an alias via the diag menu, tables and pick your alias.  See attached example of my rfc1918 alias.

              diagtablecontents.png
              diagtablecontents.png_thumb

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

              1 Reply Last reply Reply Quote 0
              • B Offline
                bashar.saeed
                last edited by

                Cnn.com was a bad example. we have an online web application and i want all lan users accessing that webapp ( name or ip address) to be routed to the second wan and not their current wan.
                I suppose that would be easier that was you explained earlier as we dont change the ip address of the webapp usually.

                In that case should i put in my source address my webapp public ip address and estination is anything other than rfc1918 space?

                1 Reply Last reply Reply Quote 0
                • H Offline
                  heper
                  last edited by

                  no, the destination is the webapp ip

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    ^ correct, if you put in a rule like mine it would send ALL traffic not going to rfc1918 (ie internet) out that gateway.  If you know the IP address or address of the actual FQDN you want to send your clients out the specific wan.  Then use those specific IP(s) as your destination.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                    1 Reply Last reply Reply Quote 0
                    • B Offline
                      bashar.saeed
                      last edited by

                      Is that the correct way (see attached)

                      Capture.PNG
                      Capture.PNG_thumb
                      Capture2.PNG
                      Capture2.PNG_thumb
                      Capture3.PNG
                      Capture3.PNG_thumb

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        yup if the dest port is 8080, if they were going to just 80 or 443 they would not go there via that rule.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • B Offline
                          bashar.saeed
                          last edited by

                          Super. Thanks for your help.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.