Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Gateway Groups

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    11 Posts 7 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thermionic
      last edited by

      Hi,

      I presume that with the new Gateway Groups, I add interfaces into a group, and then set the gateway for the traffic that I want to go over the group in the firewall rules.

      Do I need to set multiple gateways to "default" as well ?

      Cheers

      Arne

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        @thermionic:

        I presume that with the new Gateway Groups, I add interfaces into a group, and then set the gateway for the traffic that I want to go over the group in the firewall rules.

        Yes.

        @thermionic:

        Do I need to set multiple gateways to "default" as well ?

        No, only the one you want to be the default route. There can only be one default. Some changes related to that will be coming soon, for the time being check the one you consider your primary WAN.

        1 Reply Last reply Reply Quote 0
        • T
          thermionic
          last edited by

          Thanks!

          my follow on question…

          If Gateway groups are being used, do you "need" a default route ?

          Cheers

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            @thermionic:

            If Gateway groups are being used, do you "need" a default route ?

            Yes, you'll still want the firewall to be able to access the Internet, for NTP time sync, update checking, auto update, etc. It won't affect inside hosts if they all hit a rule with a gateway group, but does affect the firewall itself.

            1 Reply Last reply Reply Quote 0
            • L
              lotacus
              last edited by

              For fail-over, if wan1 fails, and later the link is re-established will all traffic move back to wan1 since it's gateway is set to "default"?

              1 Reply Last reply Reply Quote 0
              • D
                DennisBagley
                last edited by

                related question : if I have multi wan and the default route wan goes down does that stop pfsense being able to see the internet [ for its own purposes - e.g. update check etc… ] or will it fall back to the other defined gateways ???

                in the 'future changes' will it be possible to define a wan group as teh default route ??
                and will checking default on a gateway automatically uncheck default on the other gateways ???

                1 Reply Last reply Reply Quote 0
                • G
                  geeknik
                  last edited by

                  @DennisBagley:

                  related question : if I have multi wan and the default route wan goes down does that stop pfsense being able to see the internet [ for its own purposes - e.g. update check etc… ] or will it fall back to the other defined gateways ???

                  in the 'future changes' will it be possible to define a wan group as teh default route ??
                  and will checking default on a gateway automatically uncheck default on the other gateways ???

                  I don't have either WAN or WAN2 marked as default and pfSense sees the Internet just fine (checks for updates, syncs time, etc).

                  1 Reply Last reply Reply Quote 0
                  • L
                    lotacus
                    last edited by

                    I added two gateways in the gateway group and when one gateway went down, PFSense was still able to route traffic to the other gateway, so it seems that having seperate rules/groups for fail-over isn't necessary. At least under simple configurations.

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      I'm using 64 bit pfsense and am having difficulties.  Fail over seems to work just fine, however all traffic seems to go through only one of the two gateways (Which ever is set to default).  I have both gateways set for tier 1.  I have a rule set up to allow all traffic to go through the gateway group.  I even set up rules to try to force certain traffic to go through the inactive gateway.  It didn't seem to help.  Can anyone confirm working gateway load balancing?  Do I need to setup manual outbound NAT rules?

                      -V

                      1 Reply Last reply Reply Quote 0
                      • H
                        horsedragon
                        last edited by

                        Can Gateway-Group work fine with PBR in last snap-version?

                        1 Reply Last reply Reply Quote 0
                        • C
                          cmb
                          last edited by

                          People, please stop hijacking threads. Do not post things in a thread that aren't addressing the original purpose/question of the thread. Start a new thread.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.