<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Possible to select gateway based on URL ?]]></title><description><![CDATA[<p dir="auto">I have two internet connections at my home, one being provided by my employer (on campus internet @ 1 Gbps), and a secondary connection for which I pay (200 Mbps).</p>
<p dir="auto">The campus internet blocks access to some of the websites, and even some file downloads (like ISOs) are blocked. YouTube and other sites work absolutely fine.</p>
<p dir="auto">I was wondering if there's a way to direct traffic through a specific gateway based on the URL ?</p>
]]></description><link>https://forum.netgate.com/topic/156788/possible-to-select-gateway-based-on-url</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 10:05:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/156788.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 12 Sep 2020 09:21:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Mon, 14 Sep 2020 15:15:42 GMT]]></title><description><![CDATA[<p dir="auto">Updated setup :</p>
<p dir="auto">Router 1 (College Campus) : 10.1.0.1/16<br />
Router 2 (ISP Router) : 10.1.0.4/16<br />
Both Routers connected to each other. Hence R1, R2, pfSense WAN on same layer 2 network.</p>
<p dir="auto"><strong>pfSense :</strong><br />
WAN 1 : 10.1.0.2/<strong>30</strong>    Gateway : 10.1.0.1 (<strong>Default Route</strong>)<br />
WAN 2 : 10.1.0.5/<strong>30</strong>    Gateway : 10.1.0.4<br />
LAN 1 : 192.168.1.1/24</p>
<p dir="auto">Firewall Rules for LAN :<br />
Alias containing FQDN of all websites :<br />
<img src="/assets/uploads/files/1600095665365-6b96fa66-776e-4ff8-bbe7-aedc38148776-image.png" alt="6b96fa66-776e-4ff8-bbe7-aedc38148776-image.png" class=" img-fluid img-markdown" /><br />
LAN Firewall Rules :<br />
<img src="/assets/uploads/files/1600096055812-3afd9723-cda6-4f17-aa55-6f24bb65fd59-image.png" alt="3afd9723-cda6-4f17-aa55-6f24bb65fd59-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Traceroute Diagnostics :<br />
<img src="/assets/uploads/files/1600096085366-8e909d0a-e047-4a0a-b12c-790c0c05c888-image.png" alt="8e909d0a-e047-4a0a-b12c-790c0c05c888-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Results :<br />
<img src="/assets/uploads/files/1600096133589-e5319961-1ec7-4e52-aa9a-b74a76de46e9-image.png" alt="e5319961-1ec7-4e52-aa9a-b74a76de46e9-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Test (if BlockedWebsites firewall rule is disabled)<br />
<img src="/assets/uploads/files/1600096191420-b0c5d34f-029d-4947-a6a8-1741f6e7d4af-image.png" alt="b0c5d34f-029d-4947-a6a8-1741f6e7d4af-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">So yes, I believe that Sophos ( the firewall which my campus uses) blocks access to the TLD name, hence blocking any chance of redirect. So I guess I was partly right in saying that Sophos can't really block CDNs since many websites originate from the very same CDN.</p>
<p dir="auto">Also, I still can't understand properly what causes so much trouble if both the gateways are on the same subnet.</p>
]]></description><link>https://forum.netgate.com/post/934601</link><guid isPermaLink="true">https://forum.netgate.com/post/934601</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Mon, 14 Sep 2020 15:15:42 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Mon, 14 Sep 2020 14:40:12 GMT]]></title><description><![CDATA[<p dir="auto">Well yeah you kind of need a working 2nd gateway to be able to policy route through it ;)</p>
]]></description><link>https://forum.netgate.com/post/934594</link><guid isPermaLink="true">https://forum.netgate.com/post/934594</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 14 Sep 2020 14:40:12 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Mon, 14 Sep 2020 14:35:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934580">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Why did you start another thread?</p>
</blockquote>
<p dir="auto">Because I though topics are different, the other thread is just asking for URL based routing (not necessarily about gateways on same subnet).</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934580">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Where client only uses 1 gateway..<br />
There is a VM hooked behind pfSense, through which I am doing all the tests. Hence all traffic is infact flowing through pfSense (the only gateway on the VM).</p>
</blockquote>
<p dir="auto">I guess the whole issue is because both my gateways are on the same subnet. I'll try moving them to separate subnets, see if things work.</p>
]]></description><link>https://forum.netgate.com/post/934592</link><guid isPermaLink="true">https://forum.netgate.com/post/934592</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Mon, 14 Sep 2020 14:35:44 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Mon, 14 Sep 2020 13:44:13 GMT]]></title><description><![CDATA[<p dir="auto">Why did you start another thread?</p>
<p dir="auto">And your whole setup is BORKED, from reading that other thread.. If you want to policy route than you need to have both wan connections routed through pfsense..  Where client only uses 1 gateway..</p>
]]></description><link>https://forum.netgate.com/post/934580</link><guid isPermaLink="true">https://forum.netgate.com/post/934580</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 14 Sep 2020 13:44:13 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 12:59:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934368">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">again.. msn.com doesn't do anything but redirect you to a different IP.. So that is not going to work..</p>
</blockquote>
<p dir="auto">I believe that my campus internet is blocking access to msn.com also, since I can successfully ping www.msn.com but not msn.com. Also, since a lot of content is hosted through (microsoft) CDN (bing works), I believe that the block is at the first level only, preventing msn.com from loading up, hence no redirects, and the page fails to loads up.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934368">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">because your policy route is for tcp only.</p>
</blockquote>
<p dir="auto">Tried with all protocols, still no success.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934368">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Did you validate your table shows the IPs?</p>
</blockquote>
<p dir="auto">I'll post updates once I'm back home.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934368">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Have you validated your gateway even works - route all your traffic through it</p>
</blockquote>
<p dir="auto">Yes. My secondary gateway works (no blocks) if I set it up as the sole gateway on pfSense.</p>
<p dir="auto">However, if I setup my secondary gateway by going under System &gt; Routing, and then create a firewall rule for this second gateway, even then this rule doesn't apply and all my traffic gets routed through the first gateway regardless of any firewall rules.</p>
<p dir="auto"><img src="/assets/uploads/files/1600001949151-a60e2038-1f5e-47f6-bec5-8d92162d05f7-image.png" alt="a60e2038-1f5e-47f6-bec5-8d92162d05f7-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dr_tech">@<bdi>dr_tech</bdi></a> said in <a href="/post/934344">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Gateways :<br />
<img src="/assets/uploads/files/1600001711928-69b9e8c6-bf53-418a-bcac-6112e322dd5f-image.png" alt="69b9e8c6-bf53-418a-bcac-6112e322dd5f-image.png" class=" img-fluid img-markdown" /></p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/934391</link><guid isPermaLink="true">https://forum.netgate.com/post/934391</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Sun, 13 Sep 2020 12:59:12 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 12:18:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dr_tech">@<bdi>dr_tech</bdi></a> said in <a href="/post/934366">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">I tried pinging msn.com</p>
</blockquote>
<p dir="auto">again.. msn.com doesn't do anything but redirect you to a different IP.. So that is not going to work..</p>
<pre><code>curl msn.com
&lt;head&gt;&lt;title&gt;Document Moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This document may be found &lt;a HREF="http://www.msn.com/"&gt;here&lt;/a&gt;&lt;/body&gt;
</code></pre>
<p dir="auto">Which is a different IP.</p>
<pre><code>$ dig msn.com +short
13.82.28.61

$ dig www.msn.com +short
www-msn-com.a-0003.a-msedge.net.
a-0003.a-msedge.net.
204.79.197.203
</code></pre>
<p dir="auto">And your ping wouldn't ever go through that policy route, because your policy route is for tcp only.</p>
<p dir="auto">Did you validate your table shows the IPs?</p>
<p dir="auto">example<br />
<img src="/assets/uploads/files/1599999348338-tables.png" alt="tables.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Have you validated your gateway even works - route all your traffic through it.. Do a traceroute showing your path that will be taken.. Via the IP your trying to hit, etc.</p>
]]></description><link>https://forum.netgate.com/post/934368</link><guid isPermaLink="true">https://forum.netgate.com/post/934368</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 13 Sep 2020 12:18:00 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 12:07:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934358">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">IPv6</p>
</blockquote>
<p dir="auto">No, I don't have IPv6 on any of my gateways.</p>
<p dir="auto">Also, as far as DOH is concerned, I tried pinging msn.com, x1337x.ws, and other similar blocked sites directly through Windows Ping utility, and the resolved IP is the same as what pfSense DNS lookup shows.</p>
]]></description><link>https://forum.netgate.com/post/934366</link><guid isPermaLink="true">https://forum.netgate.com/post/934366</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Sun, 13 Sep 2020 12:07:15 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 11:33:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dr_tech">@<bdi>dr_tech</bdi></a> said in <a href="/post/934357">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">(hoping that the resolved DNS IP gets refreshed once every while)</p>
</blockquote>
<p dir="auto">They do, by default every 5 minutes.</p>
<p dir="auto">I would suggest you actually validate the table you created contains the IPs you expect to be using, and what your client is using to get there.</p>
<p dir="auto">Also with browsers using their own dns via doh, you can run into a whole different problem were they resolve something different than pfsense did.</p>
<p dir="auto">For such aliases to work for firewall rules, you need to make sure your client is actually resolving via pfsense, so you more likely to have the client trying to go to the IP that pfsense has for the www.domain.tld it resolved, etc.</p>
<p dir="auto">Another issue - are you even using IPv4 to get there, many sites these days have IPv6, your x1337x.ws example</p>
<pre><code>104.31.68.27	A
172.67.218.132	A
104.31.69.27	A
2606:4700:3034::681f:441b	AAAA
2606:4700:3030::ac43:da84	AAAA
2606:4700:3030::681f:451b	AAAA
</code></pre>
<p dir="auto">So did you client try and use IPv6 to get there, if so then it wouldn't be forced out your gateway because its only a IPv4 rule, etc.</p>
]]></description><link>https://forum.netgate.com/post/934358</link><guid isPermaLink="true">https://forum.netgate.com/post/934358</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 13 Sep 2020 11:33:16 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 11:22:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934350">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">Hosted off CDN.. that IPs will change all the time, etc. And the IPs are different..</p>
</blockquote>
<p dir="auto">Yes, that is why I thought of using DNS names instead of explicit IP addresses in the first place (hoping that the resolved DNS IP gets refreshed once every while), providing a better firewall rule than just using a static IP.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/934350">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">For starters which is is x133x or x1337x ??</p>
</blockquote>
<p dir="auto">I'm sorry, it's x1337x.ws. It was a typo that I corrected soon afterwards. Still it doesn't work.</p>
]]></description><link>https://forum.netgate.com/post/934357</link><guid isPermaLink="true">https://forum.netgate.com/post/934357</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Sun, 13 Sep 2020 11:22:33 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 10:16:15 GMT]]></title><description><![CDATA[<p dir="auto">For starters which is is x133x or x1337x ??</p>
<p dir="auto">You have alias that is different then what you put in the browser</p>
<p dir="auto">Do a simple traceroute to show you which path your taking</p>
<p dir="auto">Your msn is going to be difficult because you put in msn.com but that redirects to www.msn.com</p>
<p dir="auto">which is a cname anyway.</p>
<pre><code>;; ANSWER SECTION:
www.msn.com.            21591   IN      CNAME   www-msn-com.a-0003.a-msedge.net.
www-msn-com.a-0003.a-msedge.net. 3591 IN CNAME  a-0003.a-msedge.net.
a-0003.a-msedge.net.    3591    IN      A       204.79.197.203
</code></pre>
<p dir="auto">Hosted off CDN.. that IPs will change all the time, etc. And the IPs are different..</p>
]]></description><link>https://forum.netgate.com/post/934350</link><guid isPermaLink="true">https://forum.netgate.com/post/934350</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 13 Sep 2020 10:16:15 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 09:25:53 GMT]]></title><description><![CDATA[<p dir="auto">Gateways :<br />
<img src="/assets/uploads/files/1599988891880-a8d99599-eef0-4e32-a31c-3722c553ea62-image.png" alt="a8d99599-eef0-4e32-a31c-3722c553ea62-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Firewall Alias :<br />
<img src="/assets/uploads/files/1599988972763-a3b00e28-8ce1-41e0-a4a4-ef7b149131fa-image.png" alt="a3b00e28-8ce1-41e0-a4a4-ef7b149131fa-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Firewall Rule For LAN :<br />
<img src="/assets/uploads/files/1599989145013-8a631dd3-8a75-4c65-8e3b-c59d766a0970-image.png" alt="8a631dd3-8a75-4c65-8e3b-c59d766a0970-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Test Results :<br />
<img src="/assets/uploads/files/1599989064754-8d89c563-860c-4c30-ac3e-e81f7464ce5b-image.png" alt="8d89c563-860c-4c30-ac3e-e81f7464ce5b-image.png" class=" img-fluid img-markdown" /> <img src="/assets/uploads/files/1599989102809-1647893d-8d4d-4c45-b574-59020a4a4772-image.png" alt="1647893d-8d4d-4c45-b574-59020a4a4772-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/934344</link><guid isPermaLink="true">https://forum.netgate.com/post/934344</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Sun, 13 Sep 2020 09:25:53 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sun, 13 Sep 2020 08:47:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dr_tech">@<bdi>dr_tech</bdi></a> said in <a href="/post/934225">Possible to select gateway based on URL ?</a>:</p>
<blockquote>
<p dir="auto">x133x.ws,</p>
</blockquote>
<p dir="auto">Please show the firewall rule and gateway settings</p>
]]></description><link>https://forum.netgate.com/post/934338</link><guid isPermaLink="true">https://forum.netgate.com/post/934338</guid><dc:creator><![CDATA[viktor_g]]></dc:creator><pubDate>Sun, 13 Sep 2020 08:47:50 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sat, 12 Sep 2020 16:21:49 GMT]]></title><description><![CDATA[<p dir="auto">I have already tried setting up a firewall alias using the FQDN, x133x.ws, which happens to be a blocked site on the campus, to be routed through my paid internet connection.</p>
<p dir="auto">However, there's no change when I try to access the website, even a traceroute shows that the gateway being is used is that of the campus internet connection.</p>
]]></description><link>https://forum.netgate.com/post/934225</link><guid isPermaLink="true">https://forum.netgate.com/post/934225</guid><dc:creator><![CDATA[dr_tech]]></dc:creator><pubDate>Sat, 12 Sep 2020 16:21:49 GMT</pubDate></item><item><title><![CDATA[Reply to Possible to select gateway based on URL ? on Sat, 12 Sep 2020 12:47:18 GMT]]></title><description><![CDATA[<p dir="auto">it's possible to direct traffic to specific gateway based on the source/destination IP address or FQDN (limited, see https://docs.netgate.com/pfsense/en/latest/firewall/using-fqdns-in-aliases.html)</p>
<p dir="auto">see Policy Based Routing:<br />
https://docs.netgate.com/pfsense/en/latest/book/multiwan/policy-routing-configuration.html</p>
]]></description><link>https://forum.netgate.com/post/934168</link><guid isPermaLink="true">https://forum.netgate.com/post/934168</guid><dc:creator><![CDATA[viktor_g]]></dc:creator><pubDate>Sat, 12 Sep 2020 12:47:18 GMT</pubDate></item></channel></rss>