Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule for route via VPN doesn't switch to default gateway if VPN is down

    Scheduled Pinned Locked Moved Firewalling
    1 Posts 1 Posters 109 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jabacrack
      last edited by

      I think I have very standard setup - openvpn to my own server, gateway for this connection and rule that forward requests via vpn for list of sites specified in alias list. Version of pfsense - 2.4.5-RELEASE-p1 (amd64)
      What I do:

      1. Stop my openvpn server and reboot my router: status of openvpn client is down and openvpn gateway is pending. Now if I try to traceroute site from alias list connection go via default gateway and all good
      2. I start my openvpn server, client succefully connect to server, gateway is up and request to sites go via vpn
      3. Now I again stop my openvpn server, after some time openvpn gateway go down and I cannot access sites from my list anymore. But how I understand from documentation in this case in all rules that use gateway that go down it replaced by default one. And all request should go via it. And this what I want to achieve. Also I try to set checkbox "Do not create rules when gateway is down". Because my route via vpn rule is first? after disabling traffic should go via default one. But this doesn't work either. If I manually disable route via vpn rule all start work fine.

      So I want to route some traffic via vpn if it available and via default gateway if vpn down. Please help me to do this.

      My rules
      df310359-fc82-4f52-856a-2f6960fae673-image.png

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.