Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Dual WAN failover, can't access 99% of the websites. Need help

    Scheduled Pinned Locked Moved Routing and Multi WAN
    12 Posts 3 Posters 1.2k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pfrickrollP Offline
      pfrickroll
      last edited by pfrickroll

      all rules are automatic, i didn't set up any. I also disabled DNS forwarder
      0_1551724414057_3.PNG

      A 1 Reply Last reply Reply Quote 0
      • A Offline
        Alex Atkin UK @pfrickroll
        last edited by Alex Atkin UK

        @pfrickroll How are you handling DNS then? Hard coding on every client or using resolver?

        If you use DNS Resolver make sure both WAN interfaces are selected for Outgoing Network Interfaces. It probably has ALL selected as default which is usually fine, depending on if you have any other interfaces that might not be appropriate (I have VPNs for example I don't want DNS going over).

        pfrickrollP 1 Reply Last reply Reply Quote 0
        • pfrickrollP Offline
          pfrickroll @Alex Atkin UK
          last edited by

          @alex-atkin-uk said in Dual WAN failover, can't access 99% of the websites. Need help:

          @pfrickroll How are you handling DNS then? Hard coding on every client or using resolver?

          If you use DNS Resolver make sure both WAN interfaces are selected for Outgoing Network Interfaces. It probably has ALL selected as default which is usually fine, depending on if you have any other interfaces that might not be appropriate (I have VPNs for example I don't want DNS going over).

          By hard coding, do you mean this?
          0_1551735056173_1.PNG

          Here is my LAN rules, i do have DUALWAN group set up and its in LAN rules as well
          0_1551735096664_2.PNG

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            Alex Atkin UK @pfrickroll
            last edited by

            @pfrickroll Ah I see, that doesn't stop the rest of the LAN using DNS Forwarder, only pfSense itself. Did you actually want to do that or disable the DNS Forwarder entirely? (not sure why you would do either tbh)

            For starters I'd keep it simple, keep Disable DNS Forwarder ticked, untick DNS Server Override and only have 8.8.8.8 and 8.8.4.4 in the DNS Servers list, so we know only a single reliable provider is being used.

            I got a telling off by Netgate before for mixing DNS providers as it causes inconsistency in DNS lookup results. It usually works fine, but its not recommended.

            pfrickrollP 2 Replies Last reply Reply Quote 1
            • pfrickrollP Offline
              pfrickroll @Alex Atkin UK
              last edited by

              @alex-atkin-uk So, i left only both Google DNS IPS and still samething. I then enabled DNS forwarder and still nothing. I am not profy yet, when I enable DNS forwarder in services do i have to tick any other options there?

              1 Reply Last reply Reply Quote 0
              • pfrickrollP Offline
                pfrickroll
                last edited by

                Also in system > routing should I leave monitor ip blank that will reflect the my comcast/verizon gateways or put there 8.8.8.8 for first gateway and 8.8.4.4 for 2nd?

                1 Reply Last reply Reply Quote 0
                • pfrickrollP Offline
                  pfrickroll @Alex Atkin UK
                  last edited by

                  @alex-atkin-uk So, I enabled DNS forwarder without selecting anything else in the options and then I put monitor IPs for Comcast 8.8.8.8 and for Verizon 8.8.4.4 and everything began working as intended.
                  I also appreciate your time responding to my post and helping me out.

                  1 Reply Last reply Reply Quote 0
                  • GrimsonG Offline
                    Grimson Banned
                    last edited by

                    Read this: https://docs.netgate.com/pfsense/en/latest/book/routing/gateway-settings.html#monitor-ip very carefully and then think about what you are currently doing.

                    pfrickrollP 2 Replies Last reply Reply Quote 1
                    • pfrickrollP Offline
                      pfrickroll @Grimson
                      last edited by

                      @grimson said in Dual WAN failover, can't access 99% of the websites. Need help:

                      Read this: https://docs.netgate.com/pfsense/en/latest/book/routing/gateway-settings.html#monitor-ip very carefully and then think about what you are currently doing.

                      You mean as of if I am doing something completely wrong and careless?

                      1 Reply Last reply Reply Quote 0
                      • pfrickrollP Offline
                        pfrickroll @Grimson
                        last edited by

                        @grimson Ok, I see it now. Lots of things makes sense, thank you.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.