Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual wan cluster setup.

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 1 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      flamy
      last edited by

      Hello all, I'm trying to configure pfsense to act as a redundant firewall on a redundant link, so I have two servers if one goes out of commission the other takes over, and also I've got two separated links to the Internet, so if one link fails both servers switch to the other one. Everything is seen better on the graph attached(diagram.png), right now ignore DMZ I haven't configured it yet.

      First I configure cluster failover, according to this - ftp://reflection.ncsa.uiuc.edu/pub/pfSense/tutorials/carp/carp-cluster-new.htm  except I add additional NAT rule for secondary WAN link(net_mapping.png), create static routes for DNS servers. Everything works at that point. Then I  configure load balancing service from Services -> Load balancing. Then I need to change outgoing Lan gateway from the default to load balancer, as soon as do that, virtual ip on the local network, that is used for cluster failover stops working, neither does web interface work on that address. I tried not changing Lan gateway, but without it failover doesn't work.  May be someone ran into situation like this before.

      Any help appreciated.

      1 Reply Last reply Reply Quote 0
      • F
        flamy
        last edited by

        Diagram. I couldn't attach it to the original post.

        nat_mapping.png
        diagram_1.png
        diagram_1.png_thumb
        nat_mapping.png_thumb

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.