Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Load-Balancing Multi-WAN, Issues with Some Websites

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 4 Posters 724 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DanielK-CG
      last edited by

      We are having an issue connecting to a 401K bank site when on site that has the pfSense device. Our device has two ISP WANs coming in that are configured to load balance. When we switch a client to our Guest Wi-Fi that points to only one of the WAN ports via a certain subnet, we are able to connect to the 401K site without issue. I suspect that when we connect to the 401K site, it does not like packets being sent from both WAN connections because it shows multiple ISPs. Is there a way to have traffic specific to this 401K site, from a subnet that is being load-balanced between two WANs, be diverted only through one WAN port?

      G 1 Reply Last reply Reply Quote 0
      • G
        gswhite @DanielK-CG
        last edited by

        @danielk-cg Lots of https sites do not like packets being split when using multi-wan load balancing.

        You have two options,

        1. create a firewall rule for your device at the very top of the rulebase on the LAN side with the IP Address of the source to any destination but force the packets out of a specific interface. The specific interface will be under the advanced section.

        2. enable sticky packets under the advanced settings/miscellaneous

        G

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          https://www.netgate.com/resources/videos/multi-wan-on-pfsense-23.html

          -Rico

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Pretty much all websites prob have issues with this, anything that does any sort of session or login for sure would have issues with this especially from a security point of view where you would have a cookie coming from multiple IPs, etc. etc.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.