Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    different clients go through different gateways

    Scheduled Pinned Locked Moved Routing and Multi WAN
    14 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      heliop100
      last edited by

      Hi

      I want that different clients go through different gateways, servers through WAN1 and workstations through WAN2. I setup LAN rules based on IPs but all servers and stations goes every time through default gateway.

      Any clue?

      Thanks.

      V T 2 Replies Last reply Reply Quote 0
      • V
        viragomann @heliop100
        last edited by

        @heliop100
        Ensure that both gateways is shown up as online in Status > Gateways.

        Probably one doesn't reply to ping and is treated as offline. In this case, either change the monitoring IP in the gateway settings to another public one, which does respond, or disable gateway monitoring if you don't need it for failover certain traffic.

        H 1 Reply Last reply Reply Quote 0
        • T
          The Party of Hell No @heliop100
          last edited by

          @heliop100
          did you get this to work?

          H 1 Reply Last reply Reply Quote 0
          • H
            heliop100 @viragomann
            last edited by

            @viragomann said in different clients go through different gateways:

            @heliop100
            Ensure that both gateways is shown up as online in Status > Gateways.

            Probably one doesn't reply to ping and is treated as offline. In this case, either change the monitoring IP in the gateway settings to another public one, which does respond, or disable gateway monitoring if you don't need it for failover certain traffic.

            Hi, both are online and working fine.

            V 1 Reply Last reply Reply Quote 0
            • H
              heliop100 @The Party of Hell No
              last edited by

              @The-Party-of-Hell-No said in different clients go through different gateways:

              @heliop100
              did you get this to work?

              Not yet.

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @heliop100
                last edited by

                @heliop100
                So verify your filter rules. How did you set them up?

                H 1 Reply Last reply Reply Quote 0
                • H
                  heliop100 @viragomann
                  last edited by

                  @viragomann

                  The rules assign specific gateways for specific sources, but all connections only goes through default gateway .

                  Thanks

                  rules.jpg

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @heliop100
                    last edited by

                    @heliop100
                    So you say, all involved gateway are shown up as online in Status > Gateways, but the policy routing rules are not obeyed?

                    I'd expect, that all policy routing rules, which show hits here, directed the packets to the stated gateway though:
                    071b54b1-2bad-4111-999b-1fb8f595cdfb-grafik.png

                    But maybe you have rules added, which are overriding these? Could be floating rules or ones on an interface group.

                    To investigate enable the logging in all your pass rules, also you should state a description for reference. Then try your outbound connections and check in the filter log, which rule was passing the traffic.

                    Consider to flush the states before.

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      The Party of Hell No @viragomann
                      last edited by

                      @viragomann I assume in your rules you have clicked on advanced and chosen the gateway in the drop-down menu you want that rule to go out on?

                      H 1 Reply Last reply Reply Quote 0
                      • H
                        heliop100 @The Party of Hell No
                        last edited by

                        @The-Party-of-Hell-No said in different clients go through different gateways:

                        @viragomann I assume in your rules you have clicked on advanced and chosen the gateway in the drop-down menu you want that rule to go out on?

                        yes

                        H 1 Reply Last reply Reply Quote 0
                        • H
                          heliop100 @heliop100
                          last edited by

                          @heliop100

                          @viragomann said in different clients go through different gateways:

                          To investigate enable the logging in all your pass rules, also you should state a description for reference. Then try your outbound connections and check in the filter log, which rule was passing the traffic.

                          I do that and was a handy tip

                          I made some changes on rules, from TCP to ANY and check some IPs that are on more than one ALIAS.

                          Checking the gateway using tracert 8.8.8.8 still going allays through pfsense default gateway.

                          But, checking using https://www.showmyip.com/ the gateway on the rules seems correct

                          Thanks.

                          T 1 Reply Last reply Reply Quote 0
                          • T
                            The Party of Hell No @heliop100
                            last edited by

                            @heliop100 So have you created NAT outbound rules allowing the LAN segments to go out the different gateways?

                            H 1 Reply Last reply Reply Quote 0
                            • H
                              heliop100 @The Party of Hell No
                              last edited by

                              @The-Party-of-Hell-No

                              No outbound NAT, only LAN rules.

                              rules.jpg

                              T 1 Reply Last reply Reply Quote 0
                              • T
                                The Party of Hell No @heliop100
                                last edited by

                                @heliop100 I think you have to give permission - route - to the LAN segment to go out each of the gateways. This is done under firewall, NAT, Outbound. Usually it is recommended before adding rules to select manual then save. Then start adding rules for routing.
                                Untitled.jpg

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.