Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Force client to use 2nd gateway

    Routing and Multi WAN
    4
    11
    806
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      CvH
      last edited by CvH

      Hello, I try to force a client to use the second gateway instead of the default one.
      As far I can tell the firewall rule (choosed the 2nd gateway at adavanced settings) is okay and it should work but it doesn't.

      vlan12 (gateway 2) and vlan13 (gateway default) are just the wan vlans, vlan 30 is my vlan for all the clients
      10.24.96.25 is my client (asterisk server) that should use the 2nd gateway

      538093f1-0fbf-48ee-bcf4-402c83fcb9ef-grafik.png

      no firewall rules at floating and nothing at vlan12 (besides the 2 default one), 2nd gateway is working well (if I use it as default)

      any idea if this is correct at all btw if so how I can debug that problem ?

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @CvH
        last edited by NogBadTheBad

        Rules are read top -> down.

        Move the rule up.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 1
        • C
          CvH
          last edited by

          tried that and I can see that the packets are routed through that rule BUT they still using the wrong gateway (cleared states just to be sure)

          if I change the default getaway it works instantly

          not sure if I miss here something fundamentally

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Post how it is configured when you think it should be working but isn't.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • C
              CvH
              last edited by

              sorry for the delay, here the pics (gateway2 = fritz gateway, i renamed it ...)
              d3877235-0830-453b-94c3-7e68d07ba858-grafik.png

              here the complete rule

              a1d69555-c48e-4ebb-94a7-66f77cf15667-grafik.png

              Currently it shows 0B at the states tab but that is because I had it disabled, after some minutes it shows traffic.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                You do know that you have to kill all states when you make a routing change like that. existing traffic will continue to flow over any existing states.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                C 1 Reply Last reply Reply Quote 0
                • C
                  CvH @Derelict
                  last edited by

                  @Derelict yes I did this, even if I use * as source everything is still routed to the default gateway.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Except it won't be.

                    Please post the contents of /tmp/rules.debug to me in a chat and explicitly and specifically state what you think should be routed where that doesn't do what you think it should.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • C
                      CvH
                      last edited by

                      I do it as soon as possible, tx !

                      C 1 Reply Last reply Reply Quote 0
                      • G
                        gokallit
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • C
                          CvH @CvH
                          last edited by

                          @CvH said in Force client to use 2nd gateway:

                          I do it as soon as possible, tx !

                          as soon as possible was today 🙈 and it worked
                          tx a lot !

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.