Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Two pfSense serving same LAN

    Routing and Multi WAN
    4
    8
    963
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      misurex last edited by

      Hello,

      I have the following :

      DMZ
                                                                        |
                                                                        |
                                                              +–------------+
                          www                            |  Proxy      |      ...40.x
                              |                              +--------------+
                              |                                          |
                    +-------------+                  +---------------+
                    |                  |                    |                    |
                    |  pfSense1 |                    | pfSense2    |
                    |                  |                    |                    |
                    +--------------+                  +---------------+
        Gateway        \                                        /
                      ...30.x  \                                    /    ...30.x
                                    \                                  /
                                      \  +----------------+  /
                                        | App Server  |  /
                                          +----------------+

      From the DMZ I can ping the App Server (for now pfSense2 is full open to both ends), but I cannot ping from the LAN side, as expected, the only gateway of the ...30.x address is on the pfSense1 side.

      Please help me to resolve my problem, I don't know what to do to route the ...40.x requests to the pfSense2.
      Thank you.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned last edited by

        Is this some most broken network design contest going on now, or what? Cannot even see what's WAN where. Why on earth are you multihoming the App Server, instead of letting router route things?

        1 Reply Last reply Reply Quote 0
        • M
          misurex last edited by

          Because the App Server is in the same subnet (GREEN) with the rest of my computers (desktops, laptops, NAS, etc).
          Ok, here's the whole design:

          WWW
                                                            |
                                                            |
                                                    RED  |
                                +–-----------------------------------------+
                                |                                                      |
                                |                pfSense1                      |
                                |                                                      |
                                +------------------------------------------+
                    GREEN    |          | BLUE                  | ORANGE
                                    |          |                          |
                      (LAN)    |            wireless            |
                                    |                                      |
                                    |                                      |
                                    |                                      |
                                    |                                      |      DMZ
                                    |                                      |
                                    |                                      |
                                    |                                      |
                                    |                                      |           
                                    |                                      |
                                    |                                      |
                                    |                              +--------------+
                                    |                            |  Proxy      |      ...40.x
                                    |                            +--------------+
                                    |                                      |
                                    |                            +---------------+
                                    |                            |                    |
                                    |                            | pfSense2    |
                                    |                            |                    |
                                                                +---------------+
                                    \                                        /
                          ...30.x  \                                    /    ...30.x
                                        \                                  /
                                          \  +----------------+  /
                                            | App Server  |  /
                                              +----------------+

          and the rest of the LAN subnet

          Thank you.

          1 Reply Last reply Reply Quote 0
          • KOM
            KOM last edited by

            You can't ping appserver on LAN from some other client on the same LAN segment?  If so, pfSense is not involved in that issue?  And like dok said, I also fail to see why you're multi-homing the appserver.  I don't understand why you even have the second router.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned last edited by

              @misurex:

              Ok, here's the whole design:

              Well that's even worse than what I thought. Huh…

              1 Reply Last reply Reply Quote 0
              • M
                misurex last edited by

                I cannot ping from LAN (App Server) to PROXY (because the default gateway is on …30.x side (pfSense1), pfSense2 do not have a gateway).

                I have two branches because:

                • GREEN is used to make the Updates of anything in the LAN ( Servers, Desktops)
                • DMZ is used only to serve to WWW the sites/apps from the Servers

                Thank you.

                1 Reply Last reply Reply Quote 0
                • M
                  misurex last edited by

                  OK, I figure it out, it's not a pfSense problem, I need to play with the server routing table, to indicate what to do if a request come from the .40.x side.

                  Thank you.

                  1 Reply Last reply Reply Quote 0
                  • johnpoz
                    johnpoz LAYER 8 Global Moderator last edited by

                    "request come from the .40.x side."

                    So your source natting as well?  Putting a host in both your dmz and your lan via multihoming pretty much defeats the whole purpose of a "dmz"

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 23.01 | Lab VMs CE 2.6, 2.7

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post