Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot get failover WAN to work

    Scheduled Pinned Locked Moved Routing and Multi WAN
    10 Posts 4 Posters 940 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dwr953topfsense
      last edited by dwr953topfsense

      I cannot get WAN failover to work.... I think its just better to post some screenshots.

      WAN1: ISP router in bridge mode
      WAN2: D-Link 4G router with DMZ host pointing to interface set as WAN2 on pfSense

      587fd4a0-cdc1-4a08-97d9-3ad6eac76b3c-image.png

      22e7fc9f-82ce-42fd-9782-78e83098d3c9-image.png

      OK, so bad news: I used to be able to ping thru WAN2 but I cant anymore...Which is really odd. Rebooted the D-Link but still nothing. Let me continue with the pfsense config...

      382bebe4-fc83-4972-a456-34b13c111709-image.png

      I tried changing the default gateway but id did nothing.

      d3bf7e24-e0fc-4bf3-b5e9-7639d0c7dcfa-image.png

      6f549ff5-03ae-4108-800a-f2c3a25a6c1a-image.png

      daaa168c-6947-460e-81fe-ced3734563b9-image.png

      4e28ab93-a330-4a4d-986b-212962c35976-image.png

      197701d2-3c21-4f1b-82dc-afb16038de0a-image.png

      Here are some things about the D-Link:

      6f2d7e56-380c-45db-bb75-fa621eba4b24-image.png

      6de09e26-e363-4aac-aeea-1cf698120e2d-image.png

      I think thats all the information....If you need anymore, please ask.

      Thank you

      1 Reply Last reply Reply Quote 0
      • D
        d83
        last edited by

        Make sure on your lan firewall rule the Gateway is in your case is set to "GWGROUP". It is found in the advanced options under Gateway.

        D 1 Reply Last reply Reply Quote 0
        • D
          dwr953topfsense @d83
          last edited by

          @d83 said in Cannot get failover WAN to work:

          Make sure on your lan firewall rule the Gateway is in your case is set to "GWGROUP". It is found in the advanced options under Gateway.

          I dont quite understand what you mean....

          ef9bf120-dcea-431c-8ff0-27c08c26c957-image.png

          The gateway on my rules is set to * so it affects all of it. I included the rule you said but I dont think it means much.

          1 Reply Last reply Reply Quote 0
          • D
            d83
            last edited by

            So on that rule the Protocol should be IPv4 * (any). You can lock down whatever you need after you get everything up and running. Additionally, OPT1 should have the same rule.

            I don't know if you have checked this video out but this will get you there.

            https://www.youtube.com/watch?v=svZ6PKqGdtg&feature=youtu.be

            D 1 Reply Last reply Reply Quote 0
            • chpalmerC
              chpalmer
              last edited by chpalmer

              Why are your interface address and gateway address the same? The gateway address needs to be the address of the Dlink router. Hopefully that is not 192.168.254.1

              And Im pretty certain that you should have more than a /30 on that network..

              Triggering snowflakes one by one..
              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

              D 1 Reply Last reply Reply Quote 0
              • D
                dwr953topfsense @chpalmer
                last edited by

                @chpalmer said in Cannot get failover WAN to work:

                Why are your interface address and gateway address the same? The gateway address needs to be the address of the Dlink router. Hopefully that is not 192.168.254.1

                And Im pretty certain that you should have more than a /30 on that network..

                Yup. That was it :) Gateway is suppose to be the D-Link

                Noticed it just a few minutes ago.

                Thank you

                That being said....The failover IS working but the "Failback" isnt....

                If I disconnect WAN1, it falls back to WAN2. Perfect.

                But If is reconnecte WAN1, it stays on WAN2. It doesnt go back to WAN1

                Why?

                1 Reply Last reply Reply Quote 0
                • D
                  dwr953topfsense
                  last edited by

                  More progress.....

                  Failover is working but "Failback" still isnt....

                  There is also something strange I noticed, on Windows clients....

                  If it fails back to WAN2, it creates a persistent route on the Windows client. When WAN1 comes up, that persistent route stays so it still attempts to go thru there, when that route shouldn't exist anymore.

                  1 Reply Last reply Reply Quote 0
                  • D
                    dwr953topfsense @d83
                    last edited by

                    @d83 said in Cannot get failover WAN to work:

                    I don't know if you have checked this video out but this will get you there.

                    https://www.youtube.com/watch?v=svZ6PKqGdtg&feature=youtu.be

                    I didnt but a hour and 13 minute video seems very excessive (plus it might be out of date for something that takes 15-30 minutes)

                    https://www.youtube.com/watch?v=O0e13_q-ImY

                    6 minutes

                    https://www.youtube.com/watch?v=tKChXh8rbPw

                    7 minutes

                    https://www.youtube.com/watch?v=o-c89CVKBC4

                    Hell, if you want to push it, 40 minutes...

                    O 1 Reply Last reply Reply Quote 0
                    • O
                      Orbettino @dwr953topfsense
                      last edited by

                      @dwr953topfsense Hello, have you made any progress? I've the exact same problem here on my setup. Failover works but fallback isn't.

                      D 1 Reply Last reply Reply Quote 0
                      • D
                        dwr953topfsense @Orbettino
                        last edited by

                        @Orbettino said in Cannot get failover WAN to work:

                        @dwr953topfsense Hello, have you made any progress? I've the exact same problem here on my setup. Failover works but fallback isn't.

                        Yes, I did. All works OK now.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.