Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (Solve)FailOver not switching.

    Scheduled Pinned Locked Moved Routing and Multi WAN
    22 Posts 6 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • perikoP
      periko
      last edited by

      Thanks Asamat.

      For a scenario like a FailOver what is the recommendation to switch went a gw goes down?

      My case I need to enable "Flush all states when a gateway goes down.

      Thanks.

      Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
      www.bajaopensolutions.com
      https://www.facebook.com/BajaOpenSolutions
      Quieres aprender PfSense, visita mi canal de youtube:
      https://www.youtube.com/c/PedroMorenoBOS

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        If you need connectivity from the firewall itself then set the default gatway to the same failover gateway group as the clients are using.

        If you set Flush all states when a gateway goes down it will speed up the failover as nothing needs to timeout but it will also be disruptive. Connections between internal subnets and connections already using WAN2 will be killed and need to re-establish.

        Steve

        1 Reply Last reply Reply Quote 0
        • perikoP
          periko
          last edited by periko

          Thanks stephenw10.

          What I understand is, we have 2 possible paths for multiWAN, if I'm wrong let me know please.

          a) setup the FO or LB, once a GW goes down, wait until the session ends for the currents clients connected to the offline GW and after that they will try to reconnect, all other clients connected to the online GW will be NOT be affected.

          b) Setup the FO or LB, if a GW goes down force pfsense to flush all connections, this will affect all clients.

          Is correct?

          Thanks guys.

          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
          www.bajaopensolutions.com
          https://www.facebook.com/BajaOpenSolutions
          Quieres aprender PfSense, visita mi canal de youtube:
          https://www.youtube.com/c/PedroMorenoBOS

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Yes, that is correct.

            One important thing I omitted though is that if the main gateway is up and all clients are using it and then the failover gateway fails all states will still be flushed. Even if nothing is using that gateway. That means everything is interrupted unnecessarily.

            Steve

            1 Reply Last reply Reply Quote 0
            • perikoP
              periko
              last edited by

              Got it, I will test all this stuff.

              stephenw10, last thing, this will behavior is the same with a LoabBalance setup?

              Thanks again for your knowledge.

              Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
              www.bajaopensolutions.com
              https://www.facebook.com/BajaOpenSolutions
              Quieres aprender PfSense, visita mi canal de youtube:
              https://www.youtube.com/c/PedroMorenoBOS

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Yes the behaviour is the same for load-balanced gateways. In a load-balance config though it's usually not as bad because you expect to have some connections on both WANs.
                However that does mean that killing the states will always kill connections that didn't need to be.

                Steve

                1 Reply Last reply Reply Quote 1
                • perikoP
                  periko
                  last edited by

                  @periko said in FailOver not switching.:

                  stephenw10

                  I had finally test and see the behavior went a gw goes down.

                  With a LoadBalance or FailOver setup, no mater if the gw1 is up and u downloading something in gw1 and gw2 goes down.

                  Pfsense will flush states and affect even the session on online gw's.

                  There is no way to avoid this right?

                  I prefer to know this before going to production, thanks.

                  Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                  www.bajaopensolutions.com
                  https://www.facebook.com/BajaOpenSolutions
                  Quieres aprender PfSense, visita mi canal de youtube:
                  https://www.youtube.com/c/PedroMorenoBOS

                  1 Reply Last reply Reply Quote 0
                  • N
                    netblues
                    last edited by

                    @stephenw10 said in FailOver not switching.:

                    Flush all states when a gateway goes down i

                    dont use this setting. It is exactly what you are experiencing

                    perikoP 1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yes that's the expected behaviour if you have state flushing set.

                      That setting comes from a time when there was no alternative in pf. We are now looking at a better solution there, remove the states only for the gateway that went down. There's no ETA on that though.

                      Steve

                      perikoP P 2 Replies Last reply Reply Quote 0
                      • perikoP
                        periko @netblues
                        last edited by

                        @netblues , I forgot to disable this, yes u a right.

                        Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                        www.bajaopensolutions.com
                        https://www.facebook.com/BajaOpenSolutions
                        Quieres aprender PfSense, visita mi canal de youtube:
                        https://www.youtube.com/c/PedroMorenoBOS

                        1 Reply Last reply Reply Quote 0
                        • perikoP
                          periko @stephenw10
                          last edited by

                          @stephenw10 Looks like I got understand this part of pfsense, hope soon see this setting works, really will help.
                          Thanks all for your help.

                          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                          www.bajaopensolutions.com
                          https://www.facebook.com/BajaOpenSolutions
                          Quieres aprender PfSense, visita mi canal de youtube:
                          https://www.youtube.com/c/PedroMorenoBOS

                          1 Reply Last reply Reply Quote 0
                          • P pigbrother referenced this topic on
                          • P
                            patrick.pesegodinski @stephenw10
                            last edited by

                            @stephenw10 is the same configuration in 2.7.2 or is new change?

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Which configuration exactly?

                              P 1 Reply Last reply Reply Quote 0
                              • P
                                patrick.pesegodinski @stephenw10
                                last edited by

                                @stephenw10 Configuration "State Killing on Gateway Failure".

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  Nope in 2.7.2 you can choose to kill states only on the gateway that is down:
                                  https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#state-killing-on-gateway-failure

                                  P 1 Reply Last reply Reply Quote 0
                                  • P
                                    patrick.pesegodinski @stephenw10
                                    last edited by

                                    @stephenw10 This option "Kill states for all gateways which are down"?

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Yup

                                      J 1 Reply Last reply Reply Quote 1
                                      • J
                                        jamesn @stephenw10
                                        last edited by

                                        @stephenw10 Can you comment on the functionallity listed here: https://www.netgate.com/blog/netgate-to-enhance-gateway-recovery-in-pfsense-plus-version-24.03 will this be available in a CE release at any point? I have an expensive backup link and states don't reset on failback so I end up needing to take a manual action to reset them on 2.7.2

                                        Thanks for your help

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          No plans to add that to CE at this time.

                                          J 1 Reply Last reply Reply Quote 0
                                          • J
                                            jamesn @stephenw10
                                            last edited by

                                            @stephenw10 Thanks for confirming.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.