Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Question about Multi WAN in and NAT

    NAT
    2
    2
    352
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AYSMAN last edited by

      Hi guys,

      I hope someone can help me with this. Currently I'm hosting a website on my server that is behind my pfsense system. I have already configured the NAT for my Static WAN which is currently working perfectly. I'm planning to subscribe for another Static WAN IP from another ISP. My question is, is there a way to automatically forward traffic from my 1st WAN (incase its down) to my second WAN;

      1 Reply Last reply Reply Quote 0
      • D
        DJBenson last edited by

        I have an identical setup apart from WAN2 is a dynamic IP. If you wanted to ensure at least one route IN to your network, you would (I presume) need to use some form of load-balancing outside of your network (i.e. on the internet) or a DNS provider who will try IP's in a round-robin method if one of them is down. There is nothing you can do inside of your network as if WAN1 is down, pfSense has no control of traffic coming from the outside to it.

        If you mean NATting internal to external, if you add both the gateways to a gateway group, the default behaviour is to load-balance outgoing traffic, so the internet will see traffic coming from two different IP's - this is how I have my system set up - it works fine mostly (i.e. I effectively doubled my download speeds when using multithreaded download clients) BUT it can wreak havoc if a website (such as an online bank) has security measures in place which detect a change in IP address. To get around this, I am "whitelisting" certain sites which I know don't like the multi WAN setup and using a firewall alias to tunnel that traffic over WAN1 (my primary connection if you will).

        1 Reply Last reply Reply Quote 0
        • First post
          Last post