• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Web GUI

Scheduled Pinned Locked Moved Routing and Multi WAN
41 Posts 4 Posters 4.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    Ilya.V
    last edited by Ilya.V Jun 1, 2020, 10:05 AM Jun 1, 2020, 9:50 AM

    Good afternoon!
    There is a server with Pfsense, two providers are connected to it. Both gateways are added to Multiwan. In the System>Advanced menu, I changed the protocol to https and changed the port. The problem is that from the Internet I can’t connect to WEB GUI only on Wan1, but not on Wan2. Other ports are forwarded without problems. The firewall turned on / off - no difference. Tell me, please, where is the error?
    Всем добрый день!
    Стоит шлюз на Пфсенс, подключены 2 провайдера, но до веб морды могу достучаться только через Wan1. Подскажите, куда копать?

    1 Reply Last reply Reply Quote 0
    • D
      DaddyGo
      last edited by Jun 1, 2020, 10:12 AM

      What kind of multi-WAN configuration is this?
      Failover or loadbalance?

      https://docs.netgate.com/pfsense/en/latest/routing/multi-wan.html

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      1 Reply Last reply Reply Quote 0
      • I
        Ilya.V
        last edited by Jun 1, 2020, 10:15 AM

        Loadbalance.
        1.png

        1 Reply Last reply Reply Quote 0
        • D
          DaddyGo
          last edited by DaddyGo Jun 1, 2020, 10:42 AM Jun 1, 2020, 10:24 AM

          correct configuration at first glance:

          Are other services available from outside, on both WAN IPs?

          I will be honest, we have 3 multi-WAN configured pfSnese, but we handle it remotely with OpenVPN.
          https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/openvpn-remote-access-server.html
          Not via https, so this them interests me too.

          i don't know if pfSense pairs the dashboard (web), for example, specifically for WAN1 in load balancer mode and primarily (that wouldn't make sense ☺ )

          this question also::

          7f9272b6-e6b7-4f2a-b2a4-3239dfa76f16-image.png

          Cats bury it so they can't see it!
          (You know what I mean if you have a cat)

          1 Reply Last reply Reply Quote 0
          • I
            Ilya.V
            last edited by Jun 1, 2020, 10:29 AM

            @DaddyGo said in Web GUI:

            this question also::

            Everything else works fine, on both ip, only WebGUI does not open. Some time ago, everything worked, a breakdown was discovered today. There is also a second Pfsense, it all worked somehow by accident, without my intervention.

            1 Reply Last reply Reply Quote 0
            • D
              DaddyGo
              last edited by Jun 1, 2020, 10:35 AM

              Please unplug the WAN 1 ethernet connector (if you can do this now depends on your environment) and see how this round-robin works

              so,
              " When two gateways are on the same tier, they will load balance. This means that on a per-connection basis, connections are routed over each WAN in a round-robin manner. If any gateway on the same tier goes down, it is removed from use and the other gateways on the tier continue to operate normally."

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              1 Reply Last reply Reply Quote 0
              • I
                Ilya.V
                last edited by Ilya.V Jun 1, 2020, 10:43 AM Jun 1, 2020, 10:42 AM

                Thanks, but that doesn’t explain why I cannot open WebGUI on both Wan1 and Wan2 at the same time.

                1 Reply Last reply Reply Quote 0
                • D
                  DaddyGo
                  last edited by Jun 1, 2020, 10:44 AM

                  there were certificat issues yesterday, maybe this will affect something at https, as it affected more everything ???

                  , you use DDNS?

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • I
                    Ilya.V
                    last edited by Ilya.V Jun 1, 2020, 10:49 AM Jun 1, 2020, 10:48 AM

                    @DaddyGo said in Web GUI:

                    there were certificat issues yesterday, maybe this will affect something at https, as it affected more everything ???

                    No, we don’t use dnds. By http does not work either, I have no idea what to do.

                    1 Reply Last reply Reply Quote 0
                    • D
                      DaddyGo
                      last edited by Jun 1, 2020, 11:01 AM

                      true, we never use pfSense with this - https, so because of this:
                      https://www.netgate.com/blog/securely-managing-web-administered-devices.html

                      but it is very interesting why what has worked so far is not now...

                      what to see in the firewall log, when you want to connect from outside on WAN2?
                      it must be a trace of this

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 0
                      • I
                        Ilya.V
                        last edited by Jun 1, 2020, 11:05 AM

                        @DaddyGo said in Web GUI:

                        in the firewall log

                        Not a line about Wan2 in firewall log

                        1 Reply Last reply Reply Quote 0
                        • D
                          DaddyGo
                          last edited by Jun 1, 2020, 11:15 AM

                          so you don’t even get to the firewall with the request that’s a fact..

                          okay, meanwhile your ISP who is on the WAN2 interface is not volatile in its port filtering rules?
                          it is suspected that it is exactly the beginning of the month..

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          • I
                            Ilya.V
                            last edited by Jun 1, 2020, 12:56 PM

                            @DaddyGo said in Web GUI:

                            so you don’t even get to the firewall with the request that’s a fact..
                            okay, meanwhile your ISP who is on the WAN2 interface is not volatile in its port filtering rules?
                            it is suspected that it is exactly the beginning of the month..

                            I was informed that one of the providers fell off yesterday. On the second ip it was no longer possible to enter. After a working day I'll try to restart, maybe it will help
                            Thanks for the help)

                            1 Reply Last reply Reply Quote 0
                            • D
                              DaddyGo
                              last edited by Jun 1, 2020, 12:58 PM

                              you welcome

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              I 1 Reply Last reply Jun 1, 2020, 3:05 PM Reply Quote 0
                              • I
                                Ilya.V @DaddyGo
                                last edited by Jun 1, 2020, 3:05 PM

                                @DaddyGo No it didn't help

                                1 Reply Last reply Reply Quote 0
                                • D
                                  DaddyGo
                                  last edited by Jun 1, 2020, 3:39 PM

                                  the fact is that if you don't see an entry in the firewall log about the attempt, it's not pfSense that is causing the error

                                  the package / request / etc. does not reach the pfSense

                                  it is not possible for pfSense to cancel the connection attempt, ergo the process is interrupted somewhere before it

                                  @Илья I was informed that one of the providers fell off yesterday.
                                  so this ISP thing is definitely the source of your problem

                                  Cats bury it so they can't see it!
                                  (You know what I mean if you have a cat)

                                  1 Reply Last reply Reply Quote 0
                                  • I
                                    Ilya.V
                                    last edited by Jun 2, 2020, 6:11 AM

                                    Even when I turn off the firewall, packets do not fly by. Moreover, the port is pushed inside with this ip, that is, the address is available. For some reason, there is no access only to the GUI

                                    1 Reply Last reply Reply Quote 0
                                    • I
                                      Ilya.V
                                      last edited by Ilya.V Jun 2, 2020, 6:26 AM Jun 2, 2020, 6:14 AM

                                      It is periodically unavailable even from LAN
                                      After reboot, I turn off / on the firewall, and from the LAN I can access the GUI through the second address. But it’s impossible to get through from the Internet.
                                      LOL) I can redirect packets from a “non-working” ip to the LAN address of the gateway, and then everything works.

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        DaddyGo
                                        last edited by Jun 2, 2020, 6:54 PM

                                        What IPs do you use on WANs?
                                        Are these ISP public (fixed) IPs?

                                        Can you send a log snippet of dpinger?

                                        9a6581f9-44f6-4f3a-84de-d612ab4ac6b3-image.png

                                        Cats bury it so they can't see it!
                                        (You know what I mean if you have a cat)

                                        1 Reply Last reply Reply Quote 0
                                        • I
                                          Ilya.V
                                          last edited by Jun 3, 2020, 8:09 AM

                                          Send text or picture?

                                          1 Reply Last reply Reply Quote 0
                                          20 out of 41
                                          • First post
                                            20/41
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received