Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi WAN with Other Back-End Firewalls

    Scheduled Pinned Locked Moved NAT
    1 Posts 1 Posters 365 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      skifire
      last edited by skifire

      Hi All,

      Full disclosure, this setup it a little outside of what I consider "normal" -- and it's new to me.

      We currently have a few networks running in our building (all for different people) but we all share an internet circuit. Long story short, the cable connection was becoming more and more unreliable so we brought in a second carrier with a fiber connection -- but we plan to keep both.

      Issue 1: We need something to manage Multi-WAN. Though I feel pretty confident that I can handle this part, It's important for the next part.

      While each tenant has their own firewall/network, we are all pulling a public IP of the carriers modem in bridge mode. For the most part this has been working (with the single WAN connection), with one exception -- we need QOS. Phones have been problematic as well as video calls.

      Issue 2: QOS / NATing - I'm less sure of my ability here. We need each of the back end firewalls to have a public IP address, but we need to control the traffic a little bit so that no one tenant can take everything

      My thought was to replace the current connections from each firewall (that go directly to the cable modem) and put a pfsense box there (pfsense 01 in the image). Then use that box to route the traffic down to the other firewalls.

      Course correction and advanced wisdom would be greatly appreciated.

      Here is how I would like to see this work...

      82a8efb4-bef8-4ad0-8cae-c0ae786c90f9-image.png

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.