• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple Gateways on same subnet

Scheduled Pinned Locked Moved Routing and Multi WAN
multi-wansubnetgatewayroutingfirewall
26 Posts 6 Posters 5.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dr_tech
    last edited by Sep 12, 2020, 5:10 PM

    My home setup is like :

    Campus Internet > Router 1 (10.1.0.1)
    Secondary ISP > Router 2 (10.1.0.2)

    I have setup a pfSense box with the WAN IP as 10.1.200.1 (static) and the gateway as 10.1.0.1, and then I added the second gateway (10.1.0.2) under System > Routing.

    6c5b3b86-a48a-49b3-b8e6-a6760063725a-image.png

    I have setup a firewall rule to use by default, the gateway 2 (secondary ISP) for all outgoing traffic, however all traffic is still going through the gateway 10.1.0.1.

    9a7d4d9a-df76-49f7-b1e1-0cfda0367b4b-image.png

    d3ccbb9a-d6c3-4fd6-9447-ccdc6fbef1bc-image.png

    159c4fb8-d0b4-407e-9872-f13166d91632-image.png

    What am I doing wrong ?

    (I cannot remove the two routers @ 10.1.0.1 & 10.1.0.2 since I live with roommates, and I don't want them to operate through my pfSense box).

    D 1 Reply Last reply Sep 12, 2020, 5:44 PM Reply Quote 0
    • D
      DaddyGo @dr_tech
      last edited by Sep 12, 2020, 5:44 PM

      @dr_tech said in Multiple Gateways on same subnet:

      box with the WAN IP as 10.1.200.1 (static) and the gateway as 10.1.0.1,

      Place the WAN static IP on the same network as the gateway.
      Name the WAN interfaces WAN1, WAN2, etc.
      (for better transparency)

      Alternatively, create a gateway group and the WANs put to failover (tiers)
      https://docs.netgate.com/pfsense/en/latest/routing/multi-wan.html

      btw:

      why are you using two WANs this is the question?
      load balancing or fault tolerance

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      D 1 Reply Last reply Sep 12, 2020, 6:18 PM Reply Quote 0
      • D
        dr_tech @DaddyGo
        last edited by Sep 12, 2020, 6:18 PM

        @DaddyGo said in Multiple Gateways on same subnet:

        Place the WAN static IP on the same network as the gateway

        The WAN static IP is on the same subnet as the other two routers, here is a flowchart to show the same in a better way :

        Picture1.png

        The reason for this setup is, that my campus provides a very high speed (1Gbps) connection, which is highly filtered (a lot of sites blocked), while my ISP offers unrestricted access to all sites, but the bandwidth is only 50Mbps. Hence, I am looking into load balancing first, then I'll setup up some firewall rules to use a specific gateway based on IP address.

        I need a 1Gbps connection since some files I download (DICOM images from CT scanners and X Ray machines) are sometimes as large as 2-4 gigs, and I sometimes need to download as many as 20 files a day.

        D 1 Reply Last reply Sep 12, 2020, 6:24 PM Reply Quote 0
        • D
          DaddyGo @dr_tech
          last edited by Sep 12, 2020, 6:24 PM

          @dr_tech

          ok I see...

          the gateway group will be your good friend, with a well-adjusted load distribution

          you use WAN interfaces with the same name, but their descriptions only are different, so the system use a lower IP address

          Cats bury it so they can't see it!
          (You know what I mean if you have a cat)

          D 1 Reply Last reply Sep 12, 2020, 6:35 PM Reply Quote 0
          • D
            dr_tech @DaddyGo
            last edited by Sep 12, 2020, 6:35 PM

            @DaddyGo said in Multiple Gateways on same subnet:

            you use WAN interfaces with the same name, but their descriptions only are different, so the system use a lower IP address

            Pardon ?

            Gateway groups are also not working in this case, as soon as my primary gateway goes down, I lose connectivity with the Internet.

            1 Reply Last reply Reply Quote 0
            • R
              Rico LAYER 8 Rebel Alliance
              last edited by Sep 12, 2020, 6:46 PM

              Your windows tracert not showing the pfSense LAN IP as first hop means you have something terribly wrong in your whole setup.

              -Rico

              D 1 Reply Last reply Sep 12, 2020, 6:49 PM Reply Quote 0
              • D
                dr_tech @Rico
                last edited by Sep 12, 2020, 6:49 PM

                @Rico said in Multiple Gateways on same subnet:

                Your windows tracert not showing the pfSense LAN IP as first hop means you have something terribly wrong in your whole setup.

                Oh yes, didn't notice that. I'll try setting up pfSense back from scratch and report back.

                D 1 Reply Last reply Sep 12, 2020, 7:21 PM Reply Quote 0
                • D
                  dr_tech
                  last edited by Sep 12, 2020, 7:10 PM

                  I re-did all my steps, installing a new pfSense instance, adding a WAN interface with static IP and gateway (10.1.0.1), did a traceroute, all traffic was being routed through the pfSense box :

                  10284131-bcde-4120-8996-c2d76d87257a-image.png

                  Added a second gateway under System > Routing :

                  33aac1c4-29b7-4414-b03b-2d25b03f6dad-image.png

                  Modified the default firewall rule to route all traffic through second gateway :
                  b3fcd643-6d38-4d22-8903-732bc0c20db2-image.png
                  Redid a traceroute :
                  7925ffc3-8b7a-466e-86c2-c263d47c235f-image.png
                  Everything just breaks apart, NAT stops working, pfSense starts acting sort of like a switch, even when my LAN IP is stil 192.168.1.2/24.

                  Please help

                  D 1 Reply Last reply Sep 12, 2020, 7:27 PM Reply Quote 0
                  • D
                    DaddyGo @dr_tech
                    last edited by Sep 12, 2020, 7:21 PM

                    @dr_tech said in Multiple Gateways on same subnet:

                    Oh yes, didn't notice that.

                    this is not entirely the case...
                    only ICMP question, listen....

                    0f8131cd-b72f-42f9-a94c-df990984c39f-image.png

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    1 Reply Last reply Reply Quote 0
                    • D
                      DaddyGo @dr_tech
                      last edited by Sep 12, 2020, 7:27 PM

                      @dr_tech said in Multiple Gateways on same subnet:

                      Everything just breaks apart, NAT stops working, pfSense starts acting sort of like a switch,

                      there may be serious configuration deficiencies ...
                      I suggest you try to install only one WAN interface first

                      and let us see that this behaves, because basically this is a dual-NAT configuration

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 0
                      • D
                        dr_tech
                        last edited by Sep 12, 2020, 7:31 PM

                        @DaddyGo said in Multiple Gateways on same subnet:

                        I suggest you try to install only one WAN interface first

                        I did that, and until that point it works fine. (Pleas refer to my previous post)

                        As soon as I add the second gateway, and set up the firewall rules to divert traffic through the second gateway, I stop seeing the first hop as the IP of pfSense.

                        @dr_tech said in Multiple Gateways on same subnet:

                        all traffic was being routed through the pfSense box :

                        c4782351-7291-4894-bc0f-db61cc6de2ff-image.png

                        (Only the first gateway - 10.1.0.1 Campus Network Installed)

                        D 1 Reply Last reply Sep 12, 2020, 7:35 PM Reply Quote 0
                        • D
                          DaddyGo @dr_tech
                          last edited by Sep 12, 2020, 7:35 PM

                          @dr_tech said in Multiple Gateways on same subnet:

                          Pleas refer to my previous post

                          try something please do this:

                          a1475b14-b1b4-4abf-90f8-39e284051576-image.png

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          • D
                            dr_tech
                            last edited by Sep 12, 2020, 7:36 PM

                            @DaddyGo said in Multiple Gateways on same subnet:

                            try something please do this:

                            I have already set it as automatic, the moment I added a second gateway.

                            D 1 Reply Last reply Sep 12, 2020, 7:38 PM Reply Quote 0
                            • D
                              DaddyGo @dr_tech
                              last edited by DaddyGo Sep 12, 2020, 7:38 PM Sep 12, 2020, 7:38 PM

                              @dr_tech

                              What is this.......LAN /16???

                              400f88c9-59a2-44fb-b8d4-4611a27a8a01-image.png

                              +++edit:
                              do you want to say / 24

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              1 Reply Last reply Reply Quote 0
                              • D
                                dr_tech
                                last edited by Sep 12, 2020, 7:41 PM

                                @DaddyGo said in Multiple Gateways on same subnet:

                                do you want to say / 24

                                No, I meant that the subnet for my LAN is 255.255.0.0, not the default /24 block. But regardless, even if I try the 24 block, I face the same issue.

                                D 1 Reply Last reply Sep 12, 2020, 7:44 PM Reply Quote 0
                                • D
                                  DaddyGo @dr_tech
                                  last edited by Sep 12, 2020, 7:44 PM

                                  @dr_tech

                                  Ohhh...OK

                                  if you think,..... I have a couple of lab pfSense units, I'll try to model your problem tomorrow...
                                  we have saturday night at 9pm and my wife is waiting with a bottle of wine...

                                  is this right for you?

                                  btw:
                                  what is a brief description of your hardware?

                                  Cats bury it so they can't see it!
                                  (You know what I mean if you have a cat)

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    dr_tech
                                    last edited by dr_tech Sep 12, 2020, 7:51 PM Sep 12, 2020, 7:50 PM

                                    @DaddyGo said in Multiple Gateways on same subnet:

                                    we have saturday night at 9pm

                                    Sure, Have a nice weekend !!

                                    My hardware :
                                    Router 1 (College Router) : Asus RT-AC53 (10.1.0.1)
                                    Router 2 (ISP Router): TP-Link Archer C1200 (10.1.0.2)

                                    pfSense: Running on VMWare ESXi (with an Intel i350-T4 passed through)
                                    Port 1 : Input from Asus RT-AC53
                                    Port 2 : Connected to a Switch (pfSense LAN 192.168.1.0/24)

                                    K 1 Reply Last reply Sep 14, 2020, 1:07 PM Reply Quote 0
                                    • K
                                      kkrazyken @dr_tech
                                      last edited by Sep 14, 2020, 1:07 PM

                                      @dr_tech Where is your connection from pfSense to the ISP router?

                                      D 1 Reply Last reply Sep 14, 2020, 1:26 PM Reply Quote 0
                                      • D
                                        dr_tech
                                        last edited by Sep 14, 2020, 1:24 PM

                                        This post is deleted!
                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dr_tech @kkrazyken
                                          last edited by Sep 14, 2020, 1:26 PM

                                          @kkrazyken
                                          Router 1 and Router 2 are connected to each other (DHCP turned off on router 2). This was so that I could just switch the gateway address on my phone/laptop to access blocked websites quickly, without changing the network.

                                          That is the reason why Router 1 is at 10.1.0.1/16 and Router 2 at 10.1.0.2/16.

                                          K 1 Reply Last reply Sep 14, 2020, 1:43 PM Reply Quote 0
                                          9 out of 26
                                          • First post
                                            9/26
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received