<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[The problem with not working the gateway]]></title><description><![CDATA[<p dir="auto">Vip wan 10.10.10.1<br />
vip lan 192.168.1.254<br />
sync interface1 192.168.10.25<br />
lan pf1 ip   172.16.120.1<br />
lan pf2 172.16.120.3<br />
192.168.10.26 sync pf2<br />
172.16.120.2 server behind pf<br />
server behind pf gw??<br />
all /24</p>
<p dir="auto">The problem with not working the gateway in the cluster<br />
The firewalls are properly synchronized and the master and backup mode is correct<br />
But when  gateway does not pass the firewall servers as 10.10.10.1 I do not pass traffic</p>
<p dir="auto">server behind pf gw ??<br />
Thanks</p>
]]></description><link>https://forum.netgate.com/topic/144366/the-problem-with-not-working-the-gateway</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 18:04:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144366.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 22 Jun 2019 17:58:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to The problem with not working the gateway on Mon, 24 Jun 2019 13:23:46 GMT]]></title><description><![CDATA[<p dir="auto">Your saying stuff behind pfsense doesn't have internet.. Just at a loss to why your vip would be .6?  Whenever you setup a carp or hsrp or anything where there is a vip that is moved between 2 devices.. It is almost always in sequence with the actual physical IPs</p>
<p dir="auto">.1<br />
.2<br />
.3 would normally be the vip..</p>
<p dir="auto">.252<br />
.253<br />
.254 would be the vip</p>
<p dir="auto">etc..</p>
<p dir="auto">Where did you come up with .6????</p>
<p dir="auto">and .1 and 3 for your physical???</p>
<p dir="auto">So if your traffic comes in from some other path and not through the cluster, and your trying to use the cluster as your gateway for the webserver - then again NO shit its not going to work..</p>
<p dir="auto">What I would suggest you do is get 1 pfsense working... Then graduate to a HA setup..  If your going to use some other path to and from internet or other networks, then this path needs to be connected via a transit network off your pfsense box..</p>
<p dir="auto">Again I suggest you DRAW!!! your network so we are all clear how you have everything connected..</p>
<p dir="auto">You understand for port forwards to work you would need them to point to the wan carp VIP!!  this looks like you have your pf1 and 2 in line with each other?  Traffic hits your wan carp vip, and would be forwarded to your webserver IP.</p>
<blockquote>
<p dir="auto">dns load balancer &gt;&gt; pf1 - pf2 &gt;&gt; webservers</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/849952</link><guid isPermaLink="true">https://forum.netgate.com/post/849952</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 24 Jun 2019 13:23:46 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Mon, 24 Jun 2019 06:57:03 GMT]]></title><description><![CDATA[<p dir="auto">I will try explain better than before thanks for your answer I have a pfsense firewall that it was cluster and behind firewall  there are    some of web servers when I want use this cluster I use virtual IP pfsense such as web servers gateway and after those I don't have internet ping  and internet firewall if I use  gateway that I use before the cluster doesn't work because this is one of the firewalls<br />
Ip lan pfsense1 172.16.120.1<br />
Ip lan  pfsense2 172.16.120.3<br />
Virtual ip lan 172.16.120.6(if should have other range plz tell me )<br />
all rule s are sync and master and back up doesn't work properly  big problem is that web servers traffic don't sent out right now thanks<br />
For this I use  dns load balancer<br />
dns load balancer &gt;&gt; pf1 - pf2 &gt;&gt; webservers</p>
]]></description><link>https://forum.netgate.com/post/849898</link><guid isPermaLink="true">https://forum.netgate.com/post/849898</guid><dc:creator><![CDATA[Mnnn]]></dc:creator><pubDate>Mon, 24 Jun 2019 06:57:03 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sun, 23 Jun 2019 18:13:10 GMT]]></title><description><![CDATA[<p dir="auto">If the webserver is on your lan then its gateway would be the lan carp vip... If you have to ask such a question then you shouldn't be even touching this stuff..</p>
<p dir="auto">How would a devices gateway be an IP on a different network???</p>
<p dir="auto">Maybe you should ask your question in your native language section?</p>
<p dir="auto">Your wording doesn't make a lot of sense.  If you have a webserver on your lan.. How would your lan gateway IP be 192.168.1.254 if your lan for pfsense is 172.16.120..</p>
<p dir="auto">How about you draw a picture of how you have this setup!!  I gave you a link to how you would setup a carp... Are you asking about something on your wan or internet accessing your webserver via a port forward?</p>
]]></description><link>https://forum.netgate.com/post/849843</link><guid isPermaLink="true">https://forum.netgate.com/post/849843</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 23 Jun 2019 18:13:10 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 23:13:42 GMT]]></title><description><![CDATA[<p dir="auto">For example, would i have a web server<br />
ip gateway web server = virtual ip wan<br />
or<br />
Ip gateway webserver =  virtual ip lan<br />
Thanks</p>
]]></description><link>https://forum.netgate.com/post/849775</link><guid isPermaLink="true">https://forum.netgate.com/post/849775</guid><dc:creator><![CDATA[Mnnn]]></dc:creator><pubDate>Sat, 22 Jun 2019 23:13:42 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 22:54:04 GMT]]></title><description><![CDATA[<p dir="auto">Read what you wrote - how is someone suppose to understand that?</p>
<p dir="auto">I have been doing networking for since before there was networks ;)  And its gibberish!</p>
<p dir="auto">Are you asking what the clients should use for their gateway when you setup a HA pair in pfsense?<br />
https://docs.netgate.com/pfsense/en/latest/highavailability/configuring-high-availability.html</p>
<p dir="auto">They would use the carp vip... Normally this would be .3 where pf1 would be .1 and pf2 would be .2 in your ha pair. on the network of your lan... Seems you have some other machine trying to use what would normally be the one of the pf IPs..</p>
]]></description><link>https://forum.netgate.com/post/849772</link><guid isPermaLink="true">https://forum.netgate.com/post/849772</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 22 Jun 2019 22:54:04 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 21:13:54 GMT]]></title><description><![CDATA[<p dir="auto">I have multiple servers behind pfsense<br />
And pfsense cluster<br />
What kind of ip should I use for pfsense machine gates to get traffic from one another if one of the firewalls gets out?</p>
]]></description><link>https://forum.netgate.com/post/849767</link><guid isPermaLink="true">https://forum.netgate.com/post/849767</guid><dc:creator><![CDATA[Mnnn]]></dc:creator><pubDate>Sat, 22 Jun 2019 21:13:54 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 21:06:11 GMT]]></title><description><![CDATA[<p dir="auto">you wouldn't use a vip in a gateway.. A vip is just that a vip, Used to run multiple IPs on an interface, say for a port forward when you have more than one public IP, etc.</p>
<p dir="auto">Not sure what your trying to do.. Just that 10.10.10.1 is what pfsense blocker uses and could conflict with whatever you think your trying to accomplish.  which you have not stated.</p>
]]></description><link>https://forum.netgate.com/post/849766</link><guid isPermaLink="true">https://forum.netgate.com/post/849766</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 22 Jun 2019 21:06:11 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 21:03:47 GMT]]></title><description><![CDATA[<p dir="auto">When I change the virtual ip<br />
For example 172.16.1.100<br />
And put it as the gateway , way traffic will not go out again<br />
For Gateway Servers, do I use Virtual IP lan Address or Virtual IP wan Address?</p>
]]></description><link>https://forum.netgate.com/post/849765</link><guid isPermaLink="true">https://forum.netgate.com/post/849765</guid><dc:creator><![CDATA[Mnnn]]></dc:creator><pubDate>Sat, 22 Jun 2019 21:03:47 GMT</pubDate></item><item><title><![CDATA[Reply to The problem with not working the gateway on Sat, 22 Jun 2019 20:35:18 GMT]]></title><description><![CDATA[<p dir="auto">are you running pfblocker? that 10.10.10.1 vip is what pfbocker uses so that could be causing you some grief.</p>
]]></description><link>https://forum.netgate.com/post/849762</link><guid isPermaLink="true">https://forum.netgate.com/post/849762</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 22 Jun 2019 20:35:18 GMT</pubDate></item></channel></rss>