Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Multi-WAN, LTE Gateway problems

    Routing and Multi WAN
    3
    8
    39
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      brucehowells last edited by

      I recently adopted an LTE Gateway, which can't be switched into bridged mode (not sure if that's relevant for LTE, anyway, but...) and I've spent more time than I care to admit trying to get Multi-WAN to work with it.

      I have two WAN interfaces defined - WAN, which goes to Comcast and gets a public IPv4 address, and WWAN which goes to the LTE, getting a NAT IP - at the moment, I have it set to 172.16.0.0/24. My LAN is in 10.0.0.0/23.

      Creating the gateway group works well, but I can not seem to get failover or policy-based routing to work.

      Has someone written up a setup guide for this kind of scenario?

      DaddyGo 1 Reply Last reply Reply Quote 0
      • Rico
        Rico LAYER 8 Rebel Alliance last edited by

        Double NAT is not ideal but just works, I do this a lot with LTE too.
        Show your settings via Screenshot.

        -Rico

        B 1 Reply Last reply Reply Quote 0
        • B
          brucehowells @Rico last edited by

          @Rico It'll be later today. Just didn't want to gunk up the forum with a bunch of screenshots if the answer was "oh, yea, just go to this page in the pfSense book, you ninny." :)

          1 Reply Last reply Reply Quote 0
          • Rico
            Rico LAYER 8 Rebel Alliance last edited by Rico

            Oh well here we go. ;-)
            https://docs.netgate.com/pfsense/en/latest/routing/connectivity-troubleshooting.html
            https://docs.netgate.com/pfsense/en/latest/routing/troubleshooting-multi-wan.html

            -Rico

            1 Reply Last reply Reply Quote 0
            • DaddyGo
              DaddyGo @brucehowells last edited by

              @brucehowells said in Multi-WAN, LTE Gateway problems:

              reating the gateway group works well, but I can not seem to get failover or policy-based routing to work.

              we had problems with this for a long time and so we solved it....

              1. Special SIM card from the service provider (industrial non - NATd)
              2. Huawei B2338-168 4G LTE modem / router in IP pass mode

              https://www.4gltemall.com/blog/huawei-b2338-outdoor-lte-cpe/

              9f10435a-7947-489a-a88c-9167a45f9cd5-image.png

              WWAN on pfSense works perfectly after replacements ๐Ÿ˜‰

              B 1 Reply Last reply Reply Quote 0
              • B
                brucehowells @DaddyGo last edited by

                @DaddyGo Well, yea, but... :)

                DaddyGo 1 Reply Last reply Reply Quote 0
                • DaddyGo
                  DaddyGo @brucehowells last edited by DaddyGo

                  @brucehowells

                  dual-NAT on the secondary WAN connection is just a headache
                  does not work properly the VOIP (SIP), icecast stream, reverse proxy, etc

                  can I list more? ๐Ÿ–

                  +++edit:
                  https://www.verizon.com/support/knowledge-base-213106/
                  https://community.sophos.com/products/xg-firewall/f/hardware/94546/lte-modem-with-passthrough-of-external-ip-address
                  https://www.netgear.com/images/datasheet/mobile/LB1120.pdf

                  1 Reply Last reply Reply Quote 0
                  • B
                    brucehowells last edited by

                    I think I identified my problem, and figured I'd share with the community if anyone ever sees this breadcrumb again.

                    I was trying to use a gateway group so that I had fallback for PBR - "prefer WWAN, use WAN if you must" and that didn't quite seem to be working as expected; I'd get SYN-SENT on WWAN and active state on WAN.

                    Once I changed the PBR rule to use the gateway and not the gateway group (and, of course, tossed the states on WAN), traffic started flowing as desired.

                    Fun, fun, fun.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post

                    Products

                    • Platform Overview
                    • TNSR
                    • pfSense
                    • Appliances

                    Services

                    • Training
                    • Professional Services

                    Support

                    • Subscription Plans
                    • Contact Support
                    • Product Lifecycle
                    • Documentation

                    News

                    • Media Coverage
                    • Press
                    • Events

                    Resources

                    • Blog
                    • FAQ
                    • Find a Partner
                    • Resource Library
                    • Security Information

                    Company

                    • About Us
                    • Careers
                    • Partners
                    • Contact Us
                    • Legal
                    Our Mission

                    We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                    Subscribe to our Newsletter

                    Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                    © 2021 Rubicon Communications, LLC | Privacy Policy