Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2 gateways with the same wan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    32 Posts 5 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Alucardko
      last edited by

      hi to all, I have my pfsense with 2 Network cards (LAN and WAN), but I have 2 gateways in my ISP network then I configured that in pfsense, my question is, ¿I can configure 2 ip ranges each one with one gateway? example 192.168.2.10 to 192.168.2.100 with gateway1, and 192.168.2.101 to 192.168.2.200 eith gateway2, I know this can be donde with 3 networks cards (2 Wan (each with one gateway) and 1 LAN), but i must do only with 2 cards, somebody can help me?

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        What is the point of what you're doing?  You typically use multi-WAN for load-balancing or failover.  Having one NIC to one ISP, even if that ISP has multiple gateways, accomplishes neither.

        1 Reply Last reply Reply Quote 0
        • A Offline
          Alucardko
          last edited by

          @KOM:

          What is the point of what you're doing?  You typically use multi-WAN for load-balancing or failover.  Having one NIC to one ISP, even if that ISP has multiple gateways, accomplishes neither.

          Becasue one gateway gave me 100mbps (It's the one I use by default), and the another only gave me 3mbps but I want use this only when the other gateway doens work, only for the most important machines

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            Do you have a second account with your ISP and you have two connections, not just two gateways?

            I don't have a multi-WAN config, but you can go to System - Routing and add additional gateways.  You can create gateway groups that will handle failover.  Finally, you use firewall rules to control which gateway traffic goes to.  Just be careful to not end up with an asymmetrical routing problem.

            1 Reply Last reply Reply Quote 0
            • A Offline
              Alucardko
              last edited by

              @KOM:

              Do you have a second account with your ISP and you have two connections, not just two gateways?

              I don't have a multi-WAN config, but you can go to System - Routing and add additional gateways.  You can create gateway groups that will handle failover.  Finally, you use firewall rules to control which gateway traffic goes to.  Just be careful to not end up with an asymmetrical routing problem.

              I explain you, is only one subnet, if a put gateway1 in a machine that machine will have a internet conection fo 100mbps, if I put the gateway2 that machine only will have 3mbps, the only change is the gateway, the subnet is alwaays the same, I already have the gateways in Routing, I have in default the gateway with 100mbps, but I dont know exactly how make the rules for do the range of each gateway, u can give a example? I had thought it could be done in System\Routing\Static Routes but I think this is only for one IP not for a range

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                but I dont know exactly how make the rules for do the range of each gateway

                Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

                1 Reply Last reply Reply Quote 0
                • C Offline
                  climbatize92
                  last edited by

                  @KOM:

                  but I dont know exactly how make the rules for do the range of each gateway

                  Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

                  hello there,

                  I have almost same isssue than topic starter… Except I want to use 2nd gateway for specific subnet (actually for DMZ).
                  So I use default gateway for LAN interface, and in firewall rule for DMZ interface I put in advanced options to use my 2nd gateway of wan, but when I go on internet, my traffic still outbound from 1st default gateway, as servers from LAN does.

                  I have AUTOMATICLY NAT option. Should I change it?

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    Alucardko
                    last edited by

                    @KOM:

                    but I dont know exactly how make the rules for do the range of each gateway

                    Under a firewall rule's Advanced options, you will see a Gateway picklist that lets you select which gateway that rule's traffic goes out on.  Create aliases for your two groups and then use that aliases as the Source in your LAN rules.

                    I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

                    1 Reply Last reply Reply Quote 0
                    • KOMK Offline
                      KOM
                      last edited by

                      I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

                      What do you mean by routing gateway vs upstream gateway?  All gateways are upstream.

                      I have AUTOMATICLY NAT option. Should I change it?

                      No idea.  Start your own thread and post screenshots of your DMZ rules and multi-WAN config if you want someone to help you.

                      1 Reply Last reply Reply Quote 0
                      • A Offline
                        Alucardko
                        last edited by

                        @KOM:

                        I think this rule affect the routing gateway , I need affect the upstream gateway (The one in the WAN configuration)

                        What do you mean by routing gateway vs upstream gateway?  All gateways are upstream.

                        I dont think so,I will try to explain you with this diagram

                        1 Reply Last reply Reply Quote 0
                        • KOMK Offline
                          KOM
                          last edited by

                          I'm sorry but your network diagram is even more confusing to me.  Why do you have 4 routers and 4 PCs?  What are all these things connected to?

                          1 Reply Last reply Reply Quote 0
                          • D Offline
                            doktornotor Banned
                            last edited by

                            1 Reply Last reply Reply Quote 0
                            • KOMK Offline
                              KOM
                              last edited by

                              Tell me about it.  It's starting to make my head hurt.

                              1 Reply Last reply Reply Quote 0
                              • A Offline
                                Alucardko
                                last edited by

                                @KOM:

                                Tell me about it.  It's starting to make my head hurt.

                                is the same pfsense with 4 different configurations, and the pc with the result of that configurations

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ Offline
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  WTF does upstream gateway 2, routing gateway 1 mean???

                                  Its gibberish…

                                  When they asked you to draw, they meant how your connected to what gateway 1 and gateway 2 is..

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    Alucardko
                                    last edited by

                                    @johnpoz:

                                    WTF does upstream gateway 2, routing gateway 1 mean???

                                    Its gibberish…

                                    When they asked you to draw, they meant how your connected to what gateway 1 and gateway 2 is..

                                    my ISP provide me 2 gateways, in my pfsense I have 2 network cards (WAN and LAN), I have the 2 gateways configured in pfsense, my diagram only show what happen  with that 4 configurations (exchanging the gateways between upstream default and routing gate way), I only have one pc  in the pfsense LAN for see the results

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ Offline
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      And what is the point of giving you 2 gateways on the same connection?

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                                      1 Reply Last reply Reply Quote 0
                                      • A Offline
                                        Alucardko
                                        last edited by

                                        @johnpoz:

                                        And what is the point of giving you 2 gateways on the same connection?

                                        I explain it, in the third post

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ Offline
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          that doesn't explain the POINT of it.. You only have 1 connection???  If the connection is down then both gateways would not be reachable!!  So does their gateway 1 go down while you still have a connection??  WTF???

                                          And while on this second gateway you only get 3mbps from a 100mbps connection..  that is not really a failover or backup ;)

                                          So they gave you this 2nd gateway and said use this is a backup?  Because our primary router goes down??

                                          I see zero point to this sort of setup..  Point to the gateway that gives you 100mbps and call it a day..  If your internet goes down - try changing over to the other.. Does that work??  If so call the the ISP and say WTF!!!

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                                          1 Reply Last reply Reply Quote 0
                                          • A Offline
                                            Alucardko
                                            last edited by

                                            1. You are Wrong, I Dont know how is the ISP configuration but sometimes the 100mbps is down, then I can change the most important pc to another network (only changing the gateway)

                                            2.  I dont want failover, I know 3mbps is not enough for a network, is only for a few machines

                                            3. Yes

                                            4. Yes that Work, my ISP provide me from a fortinet, I cant see anything of that configuration and obvious I cant change anything of that

                                            Then you can help me, with the configuration that I want?

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.