• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

I need some help with PFsesne and dual WAN set-up

General pfSense Questions
2
18
1.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    enigma27
    last edited by Sep 11, 2020, 3:49 PM

    Ok I think I made some headway

    I randomly went into the routing page and noticed I had set both the defaults gateways from Automatic to the SKY gateway..

    I set that back to automatic and now steam and chrome download at full speed on the BT connection

    N 1 Reply Last reply Sep 11, 2020, 3:51 PM Reply Quote 0
    • N
      netblues @enigma27
      last edited by Sep 11, 2020, 3:51 PM

      @enigma27 No.
      When you create a rule, you are policy routing, and default gw is ignored.

      1 Reply Last reply Reply Quote 0
      • E
        enigma27
        last edited by Sep 11, 2020, 3:54 PM

        Does the firewall rule I set out above look correct for what I wanted to achieve?

        N 1 Reply Last reply Sep 11, 2020, 3:55 PM Reply Quote 0
        • N
          netblues @enigma27
          last edited by Sep 11, 2020, 3:55 PM

          @enigma27 Yes. Its fine.
          You need to clear states after such changes to take effect.

          1 Reply Last reply Reply Quote 0
          • E
            enigma27
            last edited by Sep 11, 2020, 4:22 PM

            OK all sorted now. thank you.

            1 Reply Last reply Reply Quote 0
            • E
              enigma27
              last edited by enigma27 Sep 12, 2020, 3:02 PM Sep 12, 2020, 3:00 PM

              this is not sorted and I cant work out why this is happening.

              Loaded my Pc up this morning.. firewall rule still running so that this PC goes through the BT gateway.. run a speed test and says im on BT and am getting the full speed...

              But downloading from steam and chrome on this PC and I am still using the sky connection and it taps out and SKYs max speed.

              Any idea why this is??

              I just downloaded something on another machine with the same firewall rule just pointing to its IP address and it downloaded on the BT connection at full speed.

              So why is steam and chrome deciding to ignore my routers firewall policy? i have cleared states.

              was working fine last night

              N 1 Reply Last reply Sep 12, 2020, 3:21 PM Reply Quote 0
              • N
                netblues @enigma27
                last edited by Sep 12, 2020, 3:21 PM

                @enigma27 post a screenshot of your firewall rules.

                1 Reply Last reply Reply Quote 0
                • E
                  enigma27
                  last edited by enigma27 Sep 12, 2020, 4:02 PM Sep 12, 2020, 4:02 PM

                  This is the simple rule i set-up to send traffic of the BT WAN for my main PC that although on whats my ip and speedtest both show my BT connection Steam and chrome are using the SKY connection to download... last night it was working fine

                  login-to-view
                  login-to-view
                  login-to-view

                  1 Reply Last reply Reply Quote 0
                  • E
                    enigma27
                    last edited by Sep 12, 2020, 4:21 PM

                    See this is strange.. I just restarted my PC and now steam is using the BT connection to download again.

                    1 Reply Last reply Reply Quote 0
                    • E
                      enigma27
                      last edited by enigma27 Sep 15, 2020, 11:31 AM Sep 15, 2020, 11:26 AM

                      Ok this is happening again.

                      Just tried to download a game from steam and its using the SKY WAN connection and ignoring the firewall rule above for my PC to use the BT WAN

                      But if i check my IP and do a speed test on the same PC it says i'm on the BT connection.

                      if i go into states and filter by my PC IP it shows no established connections through the SKY WAN

                      so confused

                      Restarting steam doesn't seem to make a difference.
                      doing an IPCONFIG /Renew on this PC makes no difference.

                      Here is a screenshot of my rules... are they in the right order?

                      login-to-view
                      login-to-view

                      N 1 Reply Last reply Sep 16, 2020, 4:46 AM Reply Quote 0
                      • N
                        netblues @enigma27
                        last edited by Sep 16, 2020, 4:46 AM

                        @enigma27 How about ipv6? I see a lot of traffic going out.
                        You can't policy route ipv6 the same way.
                        Try disabling ipv6 from your pc interface and see if it works as expected

                        1 Reply Last reply Reply Quote 1
                        • E
                          enigma27
                          last edited by Sep 16, 2020, 9:07 AM

                          OK so started a download on steam this morning and again it was using the slower sky connection.

                          So i paused steam and left it open... I then turned off IPV6 on both WAN connections and the DHCPv6 Server & RA to disabled and restarted the stem download and its back to using the BT connection.

                          So if steam uses IPV6 and the firewall rule only works on IPV4 protocol could that be the issue?

                          in the firewall rule says the following

                          Leave as 'default' to use the system routing table. Or choose a gateway to utilize policy based routing.
                          Gateway selection is not valid for "IPV4+IPV6" address family.

                          I did have IPV6 set-up for both WAN connections but the system default is the SKY connection. It seems you cant set-up a rule and designate a specific gateway that covers both IPV and IPV6 based on the note above.

                          N 1 Reply Last reply Sep 16, 2020, 9:13 AM Reply Quote 0
                          • N
                            netblues @enigma27
                            last edited by netblues Sep 16, 2020, 9:20 AM Sep 16, 2020, 9:13 AM

                            @enigma27 You can't policy route ipv6 the same way it is done in v4
                            Just because it can't be natted.

                            Keep ipv6 disabled.

                            p.s In theory you could have both ipv6 ranges assigned to your pc and then manipulate routing tables, but this has to be done at the workstation level

                            E 1 Reply Last reply Sep 16, 2020, 9:19 AM Reply Quote 0
                            • E
                              enigma27 @netblues
                              last edited by Sep 16, 2020, 9:19 AM

                              @netblues said in I need some help with PFsesne and dual WAN set-up:

                              @enigma27 You can't policy route ipv6 the same way it is done in v4
                              Just because it can't be natted.

                              Keep ipv6 disabled.

                              will this cause any issues in the future though? or are we still a long way off IPV6 becoming the norm?

                              Also just to be clear when i disable IPV6 do I disable the DHCPv6 Server & RA option?

                              N 1 Reply Last reply Sep 16, 2020, 9:21 AM Reply Quote 0
                              • N
                                netblues @enigma27
                                last edited by Sep 16, 2020, 9:21 AM

                                @enigma27 You can just disable it at your workstation.

                                You won't have any issues until you are either behind cgn or not assigned an ipv4 address

                                1 Reply Last reply Reply Quote 0
                                13 out of 18
                                • First post
                                  13/18
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.