Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Issue with Dual-WAN failover prevention

    Routing and Multi WAN
    2
    5
    329
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NineEyes last edited by

      I need to run my SG-3100 Dual-WAN without failover. I'd take failover if failback worked but I digress... I read that failover can occur unless you check "Do not create rules when gateway is down" in System/Advanced/Miscellaneous. I experimented with this option and discovered when the ISP on port OPT1 is disconnected, none of the nodes on VLANs using OPT1 as a gateway can ping the SG-3100, or accesses its WebUI. These nodes have proper IP addresses. The nodes on VLANs using port WAN as a gateway do not experience this SG-3100 access issue during this time.

      Is this expected? Is it correct behavior?

      1 Reply Last reply Reply Quote 0
      • Rico
        Rico LAYER 8 Rebel Alliance last edited by

        I'm using the SG-3100 for some Sites with Dual WAN Failover and some with 3-WAN or even 4-WAN Failover and Failback works as expected.
        What exactly is not working for you?

        -Rico

        2x Netgate XG-7100 | 11x Netgate SG-5100 | 6x Netgate SG-3100 | 2x Netgate SG-1100

        N 1 Reply Last reply Reply Quote 0
        • N
          NineEyes @Rico last edited by

          Sorry. When I disconnect the cable to OPT1 (connected to the modem of my second ISP), none of the VLANs gatewayed to OPT1 can access pfSense.

          1 Reply Last reply Reply Quote 0
          • Rico
            Rico LAYER 8 Rebel Alliance last edited by

            Do you Policy Route?
            You need to bypass policy routing for other local interfaces. Make a Rule above your policy routing Rule to hit your local networks.
            See https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html (Bypassing Policy Routing)

            -Rico

            2x Netgate XG-7100 | 11x Netgate SG-5100 | 6x Netgate SG-3100 | 2x Netgate SG-1100

            N 1 Reply Last reply Reply Quote 0
            • N
              NineEyes @Rico last edited by

              I do. I needed to add an early rule that passes traffic destined for This Firewall. With that, all is good.

              Thank you.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post