Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    routing VLAN via second WAN

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 3 Posters 222 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hebein
      last edited by

      Hello,
      I would like some of my VLAN (not all) via my second WAN (to keep my networks physically separated).
      How can I configure this in VLAN settings?

      Regards,
      Gutnher

      1 Reply Last reply Reply Quote 0
      • JeGrJ Offline
        JeGr LAYER 8 Moderator
        last edited by

        You don't configure that in your VLAN settings. Just add an Alias, where you put the IPs or the subnet/range you want to route via WAN2 from your VLAN and create a firewall rule on that VLAN e.g. LAN2 (or however it es called) atop of others that permit access to any (e.g. Internet) but in this rule click on the "advanced" button at the bottom and select your WAN2 gateway there.

        0ed84f5b-b8b2-4ff3-a31a-326c9c4f1242-image.png

        Just as an example I created this on a Test VM. LAN is 172.22.222.0/24 and I "cut out" 172.22.222.64/26 (64 IPs) that will get routed via Gateway GW_WAN2 instead of GW_WAN (e.g. default ).
        It has to be atop the more generic rule below so it get's matched. Also watch out if you have multiple other VLANs you want to still access, then you'd need another rule on top that allows internal traffic to private IPs or those VLANs with Gateway "
        " - otherwise your internal traffic gets pushed out WAN2, too and dismissed at upstream.

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 2
        • RicoR Offline
          Rico LAYER 8 Rebel Alliance
          last edited by Rico

          Normally you'd Policy Route on Layer 3 (IP), not VLAN.

          EDIT: Too slow for JeGr. ☺

          -Rico

          1 Reply Last reply Reply Quote 1
          • H Offline
            hebein
            last edited by

            Thank you!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.