<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Firewall Rules gateway settings ignored, when failover gateway group set as default gateway]]></title><description><![CDATA[<p dir="auto">Hi All,<br />
Sorry if this is a stupid question but I'm new to this and don't know if this is a bug or is working as per design as I could not found answer anywhere.</p>
<p dir="auto">So the scenario is multiple WANs:<br />
WAN1<br />
WAN2<br />
each of them have one GW, both configured as a failover group GW-GROUP. with WAN1 as preferred Tier1 and WAN2 as Tier2.<br />
To simplify it we have only one rule on LAN which is allow all/any.</p>
<p dir="auto">Scenarios:<br />
Default gateway is set to Automatic and LAN rule GW Default it uses only WAN1 GW which is normal.<br />
When you set Default gateway to GW-GROUP and LAN rule GW Default - it uses failover group which is logical as uses system default.<br />
When you set Default gateway to Automatic or GW1 or GW2 and LAN rule GW as GW-GROUP - it uses failover group which is fine and expected that is using the Rule GW setting.</p>
<p dir="auto">But when you set Default gateway to GW-GROUP , regardless of the settings on the LAN FW rule GW (GW1,GW2,Default) it still uses the failover group GW-GROUP, and I can't seems to make it use any of the specific GW for that traffic.</p>
<p dir="auto">Is this expected? As logically thinking and quoting the documentation which is, only not matched traffic should be using default gateway settings it should not behave like this and should use Rule GW settings.<br />
Or maybe I am interpreting this wrong and this is expected.<br />
I appreciate your opinion help.</p>
<p dir="auto">BTW this is on the latest 2.5.0 release</p>
]]></description><link>https://forum.netgate.com/topic/161337/firewall-rules-gateway-settings-ignored-when-failover-gateway-group-set-as-default-gateway</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 10:36:35 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/161337.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 24 Feb 2021 00:02:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Firewall Rules gateway settings ignored, when failover gateway group set as default gateway on Thu, 04 Mar 2021 22:40:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/alefe">@<bdi>alefe</bdi></a> thank you for your offer, but I don't want to waste to much of your time trying to schedule a remote session.<br />
Let me try explain what is the problem on home lab example:</p>
<p dir="auto">We have following gateways config with default gateway set to failover group preferring GW1<br />
<img src="/assets/uploads/files/1614895364891-be01e3f0-9d6c-49a0-ad07-52bd239ca1f6-image.png" alt="be01e3f0-9d6c-49a0-ad07-52bd239ca1f6-image.png" class=" img-fluid img-markdown" /><br />
<img src="/assets/uploads/files/1614895400296-d0ab0bb3-ffef-42af-bbd7-678094b0e21b-image.png" alt="d0ab0bb3-ffef-42af-bbd7-678094b0e21b-image.png" class=" img-fluid img-markdown" /><br />
And LAN rules are set to use only GW1 172.16.0.1/24 only, do not use failover.<br />
<img src="/assets/uploads/files/1614895990189-1d84f43e-ca38-4e1b-bc89-272b36ec45dd-image.png" alt="1d84f43e-ca38-4e1b-bc89-272b36ec45dd-image.png" class=" img-fluid img-markdown" /><br />
and when you have GW1 down<br />
<img src="/assets/uploads/files/1614896373622-40b81554-6f93-42b5-936b-a27aa3a2be3b-image.png" alt="40b81554-6f93-42b5-936b-a27aa3a2be3b-image.png" class=" img-fluid img-markdown" /><br />
FW makes a failover to WAN2 regardless of the rules setting to use only GW1<br />
<img src="/assets/uploads/files/1614896513050-7e980426-2fb3-4609-85a4-c77e96dd657c-image.png" alt="7e980426-2fb3-4609-85a4-c77e96dd657c-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Only if I set default GW to something different than GW group like automatic or ether GW<br />
<img src="/assets/uploads/files/1614896653818-10ea2306-6833-429b-b52e-65a91ea0a868-image.png" alt="10ea2306-6833-429b-b52e-65a91ea0a868-image.png" class=" img-fluid img-markdown" /><br />
Then the GW settings on FW rules are followed/respected:<br />
<img src="/assets/uploads/files/1614896992960-dd811aca-a9ee-412d-8d42-a70493c06ffe-image.png" alt="dd811aca-a9ee-412d-8d42-a70493c06ffe-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Hope I explained my query clearer now.<br />
And my question is: Is this is expected behaviour?</p>
<p dir="auto">Best regards,<br />
Piotr Marchewka</p>
]]></description><link>https://forum.netgate.com/post/970338</link><guid isPermaLink="true">https://forum.netgate.com/post/970338</guid><dc:creator><![CDATA[linkinpio]]></dc:creator><pubDate>Thu, 04 Mar 2021 22:40:43 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Rules gateway settings ignored, when failover gateway group set as default gateway on Thu, 25 Feb 2021 15:25:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/linkinpio">@<bdi>linkinpio</bdi></a> if you use the gw group all the rules used the defined group, however if in the rule point to the specific Gw the traffic will be forwarded to Gw specified in the rule exactly how you want it to work i don't speak english but could remotely try to help you with the settings</p>
]]></description><link>https://forum.netgate.com/post/967996</link><guid isPermaLink="true">https://forum.netgate.com/post/967996</guid><dc:creator><![CDATA[Alefe]]></dc:creator><pubDate>Thu, 25 Feb 2021 15:25:31 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Rules gateway settings ignored, when failover gateway group set as default gateway on Wed, 24 Feb 2021 21:18:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/alefe">@<bdi>alefe</bdi></a> said in <a href="/post/967694">Firewall Rules gateway settings ignored, when failover gateway group set as default gateway</a>:</p>
<blockquote>
<p dir="auto">this works yes tested in 2.5, I have this same environment mentioned in production</p>
</blockquote>
<p dir="auto">Hi alefe, thanks for replying, but I'm not sure if I get you right, so is this normal that it's behaving as expected, meaning if we set default gateway to gateway group all rules will use that gateway group?<br />
Or it's something wrong with my setup?</p>
]]></description><link>https://forum.netgate.com/post/967738</link><guid isPermaLink="true">https://forum.netgate.com/post/967738</guid><dc:creator><![CDATA[linkinpio]]></dc:creator><pubDate>Wed, 24 Feb 2021 21:18:20 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Rules gateway settings ignored, when failover gateway group set as default gateway on Wed, 24 Feb 2021 18:40:48 GMT]]></title><description><![CDATA[<p dir="auto">this works yes tested in 2.5, I have this same environment mentioned in production</p>
]]></description><link>https://forum.netgate.com/post/967694</link><guid isPermaLink="true">https://forum.netgate.com/post/967694</guid><dc:creator><![CDATA[Alefe]]></dc:creator><pubDate>Wed, 24 Feb 2021 18:40:48 GMT</pubDate></item></channel></rss>