FRR - OSPF / Default gateway



  • Hi,

    I have setup 4 pfSense with FRR. 2 in Mainoffice and two in a brunch office.
    They are both ha setups.

    They have a lwl line and a wlan backup. I use frr with ospf to switch routing if one line goes down.
    Internet will be delivered from mainoffice.

    Now when I put both frr ospf setups so announce them as default gw I get in the main brunch the following routing table:

    ============ OSPF external routing table ===========
    N E2 0.0.0.0/0 [10/10] tag: 0
    via 10.10.65.1, lagg0.65
    via 10.10.65.2, lagg0.65

    10.10.65.2 is the secondary pfsense in ha. So it can not do nat until it gets master. Is there a way to add a wight on the second entry?



  • In the ospf interfaces, there is a metric parameter, which defines the cost for each interface. Maybe this helps.



  • Hi,

    I have set it and used it. Works perfect for the routes that are exchanged but not for the default getway.
    What it makes even worse. Some pakages go over one firewall of the cluster but back the other way. So the tcp session is not in the state table and get droped. :(



  • If the whole config is only one branch location, i would avoid ospf. Just setup a gateway group with failover to wlan on each site. If you are using openvpn site to site tunnel you can define both public ips for the tunnel target and the gateway group as main interface. The failover would be faster as with ospf and the routing problem, which is a problem with the carp configuration.

    Much better : if your provider router can take the wlan failover, with the bgp routing, you even don´t see the failover. My provider does it that way and this works perfectly.


 

© Copyright 2002 - 2018 Rubicon Communications, LLC | Privacy Policy