<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dual WAN and dropped packets]]></title><description><![CDATA[<p dir="auto"><strong>1.2-RC1  Embedded on WRAP</strong></p>
<p dir="auto">I have 2xWAN 2xLAN and 2XDMZ</p>
<p dir="auto">2xISPs BT (PPPoE) and Virgin (DHCP)</p>
<p dir="auto">I added static routes for each ISPs DNS and I'm not doing load balancing or failover</p>
<p dir="auto">LAN1 works over BT and LAN2 works over Virgin. Everything is ok outbound.</p>
<p dir="auto">I put an OpenVPN server on DMZ and created port forward NAT and fw rule</p>
<p dir="auto">As a test I put a laptop on LAN1 and connect ovpn client to the public IP address of WAN2</p>
<p dir="auto">Client–-&gt;PF(sis3)---&gt;BT-WAN1(sis1)---&gt;Internet---&gt;Virgin-WAN2(sis2)---&gt;DMZ(sis4)---&gt;OVPN</p>
<p dir="auto">with tcpdump I see the packet arrive at the ovpn server and it responds. It then seems to get silently dropped by the fw. There's nothing in the filter log and tcpdump doesn't see it leaving any of the other interfaces.</p>
<p dir="auto">I tried the DMZ i/f with and without a gateway, doesn't make any difference. I also opened up ssh on the ovpn server as additional test but I get the same result. I had the same setup working when I had a single ISP.</p>
<p dir="auto">tcpdump from ssh</p>
<p dir="auto">vpn# tcpdump -i lnc1<br />
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode<br />
listening on lnc1, link-type EN10MB (Ethernet), capture size 96 bytes<br />
23:00:32.097891 IP &lt;virginip&gt;.56919 &gt; 192.168.4.150.ssh: S 2981099879:2981099879(0) win 8192 &lt;mss 1452,nop,wscale="" 8,nop,nop,sackok=""&gt;23:00:32.098084 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535 &lt;mss 1460,nop,wscale="" 1,sackok,eol=""&gt;23:00:35.067268 IP &lt;virginip&gt;.56919 &gt; 192.168.4.150.ssh: S 2981099879:2981099879(0) win 8192 &lt;mss 1452,nop,wscale="" 8,nop,nop,sackok=""&gt;23:00:35.067345 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535 &lt;mss 1460,nop,wscale="" 1,sackok,eol=""&gt;23:00:38.066337 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535 &lt;mss 1460,nop,wscale="" 1,sackok,eol=""&gt;23:00:41.050725 IP &lt;virginip&gt;.56919 &gt; 192.168.4.150.ssh: S 2981099879:2981099879(0) win 8192 &lt;mss 1452,nop,nop,sackok=""&gt;23:00:41.050797 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535 &lt;mss 1460,nop,wscale="" 1,sackok,eol=""&gt;23:00:47.048828 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535 &lt;mss 1460,nop,wscale="" 1,sackok,eol=""&gt;23:00:59.044931 IP 192.168.4.150.ssh &gt; &lt;virginip&gt;.56919: S 4160585790:4160585790(0) ack 2981099880 win 65535&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;&lt;/mss&gt;&lt;/virginip&gt;</p>
]]></description><link>https://forum.netgate.com/topic/5343/dual-wan-and-dropped-packets</link><generator>RSS for Node</generator><lastBuildDate>Tue, 21 Apr 2026 23:01:28 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/5343.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 30 Jul 2007 23:42:39 GMT</pubDate><ttl>60</ttl></channel></rss>