• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HA Cluster Config Question

Scheduled Pinned Locked Moved HA/CARP/VIPs
2 Posts 2 Posters 865 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    net_admin
    last edited by May 2, 2017, 8:59 PM

    I am currently setting up a HA Cluster with two WAN Connections.  I was reviewing what I have setup currently and documentation from The pfSense book and the following jumped out at me:

    27.4.3 Firewall Configuration
    With Multi-WAN a firewall rule must be in place to pass traffic to local networks using the default gateway. Otherwise,
    when traffic attempts to reach the CARP address or from LAN to DMZ it will instead go out a WAN connection.
    A rule must be added at the top of the firewall rules for all internal interfaces which will direct traffic for all local
    networks to the default gateway. The important part is the gateway needs to be default for this rule and not one of the
    failover or load balance gateway groups. The destination for this rule would be the local LAN network, or an alias
    containing any locally reachable networks.

    I'm not quite following what the above paragraph means…  Does anyone know of any configuration examples I could look at to apply the documentation to practice?

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by May 5, 2017, 3:10 PM

      On your LAN side, if you have, say, a LAN and DMZ, you need rules to pass from LAN to DMZ without a gateway set. Under that, you can have a rule from LAN to any with a gateway set for whatever Multi-WAN scenario you setup (LB, failover, etc).

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received