Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Two Pfsense each with Seprate Internet routing each other

    Scheduled Pinned Locked Moved Routing and Multi WAN
    39 Posts 2 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      "(the wan is down on pf2 [192.168.10.0/24])"

      well that would be a problem now wouldn't it.. How would it work if the wan is down??  That has nothing to do with the transit or connectivity between the pfsenses, etc.

      Why do you have 2 transits?

      What sort of wan do you have that it doesn't show an interface assigned to it for speed and duplex, etc.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • I
        irs
        last edited by

        The wan is down since morning on site 2 (pf2) but the site 1 has the internet (pf1) wan is working

        1 Reply Last reply Reply Quote 0
        • I
          irs
          last edited by

          @johnpoz:

          "(the wan is down on pf2 [192.168.10.0/24])"

          well that would be a problem now wouldn't it.. How would it work if the wan is down??  That has nothing to do with the transit or connectivity between the pfsenses, etc.

          Why do you have 2 transits?

          What sort of wan do you have that it doesn't show an interface assigned to it for speed and duplex, etc.

          i made another Transit just to see if i have made something wrong.

          1 Reply Last reply Reply Quote 0
          • I
            irs
            last edited by

            if one wan on any pf goes down wouldn't it takes over to other pf wan which is up through transit?

            1 Reply Last reply Reply Quote 0
            • I
              irs
              last edited by

              what should I do?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Yeah if you set it up like that.. But yours doesn't seem down - it was pending, and looks like you removed the interface from it or something?

                And why do you have 2 transits?  How did you configure your failover?  You should simulate it being down by blocking ping at pfsense gateway, that is how I did it.  Or mark the gateway down.  But you should validate that your can talk to each others networks and go out your local wan before trying to test the failover, etc.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • I
                  irs
                  last edited by

                  i have changed the transit now only one transit

                  1 Reply Last reply Reply Quote 0
                  • I
                    irs
                    last edited by

                    it is showing up online now

                    ![pf2 dashboard update.PNG](/public/imported_attachments/1/pf2 dashboard update.PNG)
                    ![pf2 dashboard update.PNG_thumb](/public/imported_attachments/1/pf2 dashboard update.PNG_thumb)

                    1 Reply Last reply Reply Quote 0
                    • I
                      irs
                      last edited by

                      pf1 internet is working fine, still can not figure out what mistake i made?

                      ![ping 2.PNG](/public/imported_attachments/1/ping 2.PNG)
                      ![ping 2.PNG_thumb](/public/imported_attachments/1/ping 2.PNG_thumb)
                      ping.PNG
                      ping.PNG_thumb

                      1 Reply Last reply Reply Quote 0
                      • I
                        irs
                        last edited by

                        can you explain from where the gateway 192.168.9.253 and 192.168.2.253 comes from

                        you have used in your snapshot
                        System > Routing > Gateway

                        Thx

                        1 Reply Last reply Reply Quote 0
                        • I
                          irs
                          last edited by

                          I tried again but same no luck, completely from scratch.

                          Both firewall communicate each other but can not access Internet.

                          I created transit on both firewall

                          Created LAN on each of them

                          Gateway, Static route and gateway group failover on each pfsense

                          Firewall LAN allowed

                          firewall Transit interface allowed

                          but unlucky to get the internet

                          please help me to find the problem?
                          Thx

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            "can you explain from where the gateway 192.168.9.253 and 192.168.2.253 comes from"

                            As I told you already - those were my wan_dhcp gateways in the downstream pf1 and 2 I setup.. That is just my internet in my setup to mimic yours.  Here is a drawing..

                            "Both firewall communicate each other but can not access Internet."

                            Who can not access internet, can your 2 networks talk to each other? 192.168.0 and 192.168.10?  Did you mess with outbound nat?  When you create your downstream route it should automatic create your outbound nat for you.

                            Your going to have to post your setup if you want me to spot what your doing wrong.  How is it showing online when shows NO interface or connection just "NONE"  How does your wan have a 0.0ms response time??

                            setupsimyoursetup.png
                            setupsimyoursetup.png_thumb

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.