• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Manage failover modem in Multi-WAN setup

Scheduled Pinned Locked Moved Routing and Multi WAN
3 Posts 2 Posters 204 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    marcg
    last edited by marcg Aug 19, 2024, 12:25 AM Aug 19, 2024, 12:02 AM

    I'm planning to add a secondary LTE WAN as backup for a primary fiber WAN in failover mode via a Gateway Group. pfSense will be behind the LTE modem/router on a dedicated subnet, say 192.168.90.1 for the LTE modem router and 192.168.90.2 for pfSense.

    While the primary connection is active, will I be able to access the management interface on the LTE modem/router from the pfSense's LAN-side networks (possibly with a static route for 192.168.90.1/24 pointing at the LTE WAN interface, so that traffic to 192.168.90.1 always routes through that interface, and assuming appropriate firewall rules)? Put differently, can any traffic be routed through the failover WAN interface while the primary is active?

    Thx.

    V 1 Reply Last reply Aug 19, 2024, 11:30 AM Reply Quote 0
    • V
      viragomann @marcg
      last edited by Aug 19, 2024, 11:30 AM

      @marcg said in Manage failover modem in Multi-WAN setup:

      While the primary connection is active, will I be able to access the management interface on the LTE modem/router from the pfSense's LAN-side networks

      Yes, this will be possible without any special settings.
      All it needs is that pfSense is the default gateway on your LAN device, what might be given anyway.

      The only thing to consider is if you create policy routing rules pointing to the other gateway, to exclude this destination. But this point applies also to other local subnets in general, which you have to exlude from the rule.

      can any traffic be routed through the failover WAN interface while the primary is active?

      You can do this with Policy Routing rules.
      But keep in mind, that policy routing force all matching traffic to the stated gateway. This means, if such rule matches a traffic, which is destined to local devices, access will fail.
      So you have either configure the rule in a way, so that it doesn't match (e.g. RFC 1918 alias for the destination with 'invert match' checked), or you put pass rule for allowing access to local destinations above of it.

      M 1 Reply Last reply Aug 19, 2024, 4:48 PM Reply Quote 1
      • M
        marcg @viragomann
        last edited by Aug 19, 2024, 4:48 PM

        @viragomann thank you ... greatly appreciated!

        The initial configuration will be basic. Simple failover and no policy routing.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received