Multi-WAN Load balancing vs Failover vs both (Default Gateway, DNS resolver, LAN and OpenVPN setups)
-
Hi everyone,
I have two internet services from two different ISPs - one provides symmetric 1Gbps fiber service and another cable one with 1Gbps/60 Mbps. I am currently using a Netgate 6100 Max, several UniFi switches and APs.
Recently I have been reading about multi- WAN setups in pfSense, default gateway, LAN traffic and DNS resolver and I am trying to figure out if it would be appropriate for me to do the following:
-
Set up both a Load Balance Gateway group (each WAN with Tier 1) and another Failover one (fiber WAN gets Tier 1 and cable WAN2 gets Tier2). Would it make sense to use both or not? I kind of like having a higher throughput and frankly I am not super concerned about one internet service failing vs. the other as both services have been fairly reliable from what I have observed in the last 12 months or so. But that’s not to say that this will not happen in the future.
-
Choose the Load Balancing Gateway group as the default gateway. Although, I thought I read somewhere in the pfSense documentation that the Failover gateway group must be selected as the default gateway. Please correct me if I read that wrong.
-
DNS resolver - don’t plan to use the DNS forwarding mode and any other DNS providers, only the resolver mode and the DNS that pfSense provides. The multi-WAN documentation on this states that I should use the Failover group as the gateway for the resolver. Is this still ok to use even with a two gateway group setup (load balancing + failover)?
-
For LAN rules, can I use the Load Balancing group as the gateway to route traffic or do I need to use the failover one?
-
OpenVPN - I do plan to eventually set up NordVPN in my Netgate 6100. What would be the most appropriate gateway group to select here, load balancing or failover or both? I have a feeling that failover may be more appropriate but I could be wrong.
Appreciate your assistance and thoughts. Thank you in advance!!
Marin
-
-
Any thoughts on this?