Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PBR with Multiple gateways on the same subnet/interface

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    7 Posts 4 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wishy
      last edited by

      Under 2.x thre is a new gateway screen, allowing gateways to be added, appearing in the Firewall rule gateways (PBR) selection.

      Test setup
      Default gateway 192.168.1.10
      Alternative gateway 192.168.1.11

      Seems after doing some testing, that while you can set this via the firewall rules it appears that the PBR doesn't actually take affect (Traffic continues along to 192.168.1.10)
      Under 1.3 you can't do this via the interface, and can do this by defining an additional interface

      I'm guessing the underlying code hasn't been changed / doesn't support this?

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        That works if they're both on the same interface.

        1 Reply Last reply Reply Quote 0
        • W
          wishy
          last edited by

          I could see it hitting the rule on the logs, but the traffic never showed up at the alternative gateway, it just carried on along the default route

          1 Reply Last reply Reply Quote 0
          • J
            jlepthien
            last edited by

            But isn't this kinda lame? If I have two internet connections and want to do PBR with two external interfaces then this won't work? Or do you mean that the subnets need to be different when using two interfaces?

            | apple fanboy | music lover | network and security specialist | in love with cisco systems |

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              When using two separate physical interfaces, the gateways must be different.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • J
                jlepthien
                last edited by

                Yeah, but isn't this just the 'normal' way?

                | apple fanboy | music lover | network and security specialist | in love with cisco systems |

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  If it's on two different interfaces you can't provide any assurance of where that ARP will end up being seen. It'll work with different gateways on two different interfaces that are on the same IP subnet, but may not use the interface you expect it to.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.