Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    default gateway override route ?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @rynstack
      last edited by

      @rynstack said in default gateway override route ?:

      we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

      You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

      R 1 Reply Last reply Reply Quote 0
      • R
        rynstack @viragomann
        last edited by

        @viragomann said in default gateway override route ?:

        @rynstack said in default gateway override route ?:

        we have a single default gateway route but now have set up an alternate 2nd wan/lan for "DMZ" segmented type networks

        You got a 2nd WAN connection with a different gateway and you want to route the upstream traffic of the DMZ out to this new WAN?

        yes, that is correct @viragomann

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @rynstack
          last edited by

          @rynstack this would be a policy route, via firewall rule you can push traffic out any specific gateway you want.

          https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          R 1 Reply Last reply Reply Quote 1
          • R
            rynstack @johnpoz
            last edited by rynstack

            @johnpoz thanks for the note and ref, I did play with that option before when troubleshooting early on, but was still having some problems with it, though I'd like to try it again some more [it was allowing traffic out when viewing logs, but getting stuck beyond the virtual child interface out to the public for some reason]. granted I did make changes while testing afterwards, still came to the same problem I'm having now, but there may be additional config needed for that to work properly in our setup.
            so technically, policy routing should resolve this issue and no adjustment would be needed to the system default route settings?

            One downside I found after trying that and some other things during testing, is a gateway listed in the routing table is stuck with the gateway IP I want to use pointing at a wrong MAC address [alternate virtual interface] - so now i cannot seem to fix it or use that IP as a gateway now. the gateway is marked as down, though its up on the correct physical interface, even after removing and re-adding from the the system gateway list. concerned some stale config is conflicting with getting this to work properly since the beginning. any advice on how to manually remove the problem gateway from the routing table without affecting other networks or the entire running system is welcome! thanks in advance.
            edit=uploaded image example
            5082e5ed-5c51-466c-a366-2cad35043663-image.png

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @rynstack
              last edited by

              @rynstack
              Did you accidentally assign the same subnet to different interfaces by any chance?
              Check out Status > Interfaces.

              R 1 Reply Last reply Reply Quote 0
              • R
                rynstack @viragomann
                last edited by

                @viragomann thanks for the check - here's what I can see currently, this virtual interface for 10.86.151.1 still has the problematic gateway assigned to it, but in the interface config its not set. I checked subnets of all interfaces and they are all unique, but the problem gateway IP is listed for 2 interfaces. bug?
                0f0ed89d-2453-4526-9c2e-d0d2007894e1-image.png e88ab6f1-789b-48d6-903b-fd692af28630-image.png b7fec519-7175-4eb4-8309-168ec89aeff5-image.png

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @rynstack
                  last edited by

                  @rynstack
                  Strange. Chiefly as the gateway is outside of the subnet.

                  What shows System > Routing > Gateways?

                  R 1 Reply Last reply Reply Quote 0
                  • R
                    rynstack @viragomann
                    last edited by rynstack

                    @viragomann basic default route and the problem GW, which I have removed, re-added, disabled, enabled twice but no change.
                    513a03bf-3677-4253-99a7-2cc0369d1360-image.png
                    ed9b32db-c57c-4d77-abd3-938ede59a378-image.png

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      rynstack @rynstack
                      last edited by rynstack

                      i just "re-saved" the interface [10.86.151.1] again with no change / no gateway and it fixed itself! 27f9ebe7-f82a-45c3-9f33-44960775f876-image.png e145081c-993d-456f-92bc-5f983d9f4994-image.png4a1824a3-8356-425d-accf-86d3b4d1fe55-image.png be6083aa-2d46-4f3f-b9ec-75580aa87493-image.png

                      1 Reply Last reply Reply Quote 0
                      • R
                        rynstack
                        last edited by

                        thanks so much for the help @viragomann and @johnpoz , I seem to have a working route out now with FW rules using policy route!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.