Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Failover apparently not working

    Scheduled Pinned Locked Moved Routing and Multi WAN
    5 Posts 3 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pablot
      last edited by

      Hi,

      I have installed a failover and load balance pfSense firewall with two WAN interfaces and one LAN.

      Everything seems to be working quite well, but when I take offline one of the WAN interfaces, although I can still access internet, the firewall rule of the failover group does not seems to get any traffic, and the load balance one seems to be receiving all the traffic.

      So in other words, I have one loadbalance rule and two failover rules, but in every situation apparently only the loadbalance rule is working as it increments its counters no matter wich wan interface is online or if both are online, so I'm not sure if the failover is really working or just the loadbalance rule is getting all the traffic through just one interface.

      1 Reply Last reply Reply Quote 0
      • L
        logan23
        last edited by

        Same here, the "take wan offline" is a good test that shows that failover doesn't correctly work.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          [qupte]
          So in other words, I have one loadbalance rule and two failover rules, but in every situation apparently only the loadbalance rule is working as it increments its counters no matter wich wan interface is online or if both are online, so I'm not sure if the failover is really working or just the loadbalance rule is getting all the traffic through just one interface.

          It works fine.

          If the loadbalance rule matches the traffic the failover rule will never be hit.

          You will need to post more information instead of just claiming it is broken.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • P
            pablot
            last edited by

            @Derelict:

            [qupte]
            So in other words, I have one loadbalance rule and two failover rules, but in every situation apparently only the loadbalance rule is working as it increments its counters no matter wich wan interface is online or if both are online, so I'm not sure if the failover is really working or just the loadbalance rule is getting all the traffic through just one interface.

            It works fine.

            If the loadbalance rule matches the traffic the failover rule will never be hit.

            You will need to post more information instead of just claiming it is broken.

            Sorry, I do not even suggest that anything is broken, I'm just saying that "apparently" it's not working for me, so I'm asking for someone more experienced to tell me if it's working as it should or I have something wrong.

            I'm attaching my configurations so anyone can take a look if they want.

            In the firewall rules you can see that only the first rule is being hit, as is the only that have traffic (I take offline both wans alternately and the other rules never got traffic)

            gateways.png
            gateways.png_thumb
            wangroup.png
            wangroup.png_thumb
            wangroupfibertel.png
            wangroupfibertel.png_thumb
            wangrouparnet.png
            wangrouparnet.png_thumb
            firewallrules.png
            firewallrules.png_thumb

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              The only thing that will be effective there is WANGroup. It will match all traffic. The other rules will never be hit. As is evidenced by the traffic counters on them.

              If you want different behavior, delete the other two rules.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.