WAN Failover using 2 Gateways on the same subnet
-
@viragomann
from Load Balancing
" If a gateway that is part of a load balancing group fails, the interface is marked as down and removed from all groups until it recovers"
Yes this is the answer, thank you.In any case, I don't understand why the entire interface is marked down if even just one of the gateways goes offline. I would have expected that only the offline gateway be excluded, and the traffic could still flow through the gateway that remains online.
-
@vsmaldino said in WAN Failover using 2 Gateways on the same subnet:
In any case, I don't understand why the entire interface is marked down if even just one of the gateways goes offline.
Probably a design decision we have to live with.
-
@vsmaldino
Yeah, load balancing gateways are somehow special in pfSense. In contrast to a failover gateway group, you also cannot use lb gw groups for policy routing.
There might be reasons for this. -
@viragomann From my tests it is not a question of groups or types of groups (LB, FO or LB+FO)
The real limitation is given by the close relationship between a gateway and the associated network interface. To define a gateway you must first of all indicate the network interface with which to use it. When the gateway goes down, its interface is marked as "down" regardless of whether there are other active gateways using it. From what I've seen from my testing, this happens even if you don't define any group.
The best load balance and fail over system I've seen so far is the one implemented by the late Zeroshell by Fulvio Ricciardi. -
@vsmaldino You can do it anyway, I have this running here:
-
@Bob-Dig The problem is what happens if any of your SS_* GWs go down? According to my tests, they should all go down because they supposedly all use the same network interface. This behavior is not acceptable in my network.
-
@vsmaldino said in WAN Failover using 2 Gateways on the same subnet:
The problem is what happens if any of your SS_* GWs go down?
There is no problem as long as there is no gateway set on the interface itself.
-
@Bob-Dig what do you mean with "there is no gateways set on the interface"?
When creating a gateway you need to define an interface for its use. From your screenshot I assume that all SS_* have the same interface, according to my tests, if only one of the SS_* goes down, that interface is marked as down.
Am I doing something wrong?
-
@vsmaldino said in WAN Failover using 2 Gateways on the same subnet:
what do you mean with "there is no gateways set on the interface"?
-
@Bob-Dig first of all, thank you for your patience.
Your screenshot refers to the IP configuration of the network interface, it doesn't set any upstream gateway, Ok.
But what about the config of the SS_* GWs? Can you send me a screenshot of a couple of them? I'm very curious to see which interface they use and if it is the same as I presumed. -
@vsmaldino said in WAN Failover using 2 Gateways on the same subnet:
But what about the config of the SS_* GWs? Can you send me a screenshot of a couple of them? I'm very curious to see which interface they use and if it is the same as I presumed.
It is the interface (192.168.111.1) I showed above.
If you have to NAT, you have to create the NAT-Rules manually. I don't because all the gateways are OpenWrt-VMs. -
@Bob-Dig
Tnx, another step over ;-)
VLAN111_OWRT_LAN is the interface of Ss_DeBe Gw.
I presume these:- Ss_AtVie, Ss_ChZur, ... have the same VLAN111_OWRT_LAN interface
- 192.168.111.1 is the IP address of VLAN111_OWRT_LAN
Is it right?
-
@vsmaldino correct.
-
@Bob-Dig
Tnx. It is a scenario very similar to that i tested with.These are my GWs, both on the same interface, NO Gateway Groups defined.
This is the status few seconds after shutting down only FibraITG:
In few tens of seconds both GWs are marked down, i think because both use the same interface (WAN).
As you stated on March 7, there is some deep design decision that put in close relationship the status of the gateways using the same interface.
-
@vsmaldino True. But also you have a gateway set on WAN.
My setup is also different that I don't use WAN for those VPN-Gateways on the same interface and none of those gateways is the default gateway.