Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense 2.1 Floating rules for Multi Wan doesn't work.

    Scheduled Pinned Locked Moved Routing and Multi WAN
    86 Posts 35 Posters 49.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hyrol
      last edited by

      I problem in the floating for multi wan, after I upgraded to version 2.1, it does not work.
      ![04. Floating.png](/public/imported_attachments/1/04. Floating.png)
      ![04. Floating.png_thumb](/public/imported_attachments/1/04. Floating.png_thumb)

      1 Reply Last reply Reply Quote 0
      • K
        kathampy
        last edited by

        I'm not entirely sure but that rule looks fundamentally wrong in the first place. You've created a floating rule with direction Out on a WAN interface. This means by the time the rule fires, NAT has already occured and a gateway has already been chosen.

        Just create a normal Internet access rule on the LAN interface and set the gateway there. There is generally no need for floating rules for multi-WAN conditional gateway selection.

        You rule is just for HTTP, so simply create a new Internet access rule on the LAN interface above the existing one and set the destination port to HTTP.

        1 Reply Last reply Reply Quote 0
        • H
          hyrol
          last edited by

          previously no problems during pfSense 2.0.3, you can refer to this link.

          http://forum.pfsense.org/index.php/topic,60977.0.html

          1 Reply Last reply Reply Quote 0
          • K
            kathampy
            last edited by

            It doesn't matter. The floating rule seems overly complex and unnecessary when a simpler solution achieves the same thing.

            1 Reply Last reply Reply Quote 0
            • H
              hyrol
              last edited by

              Need floating rules for squid multi wan, have any idea without floating rules.

              1 Reply Last reply Reply Quote 0
              • K
                kathampy
                last edited by

                Are both your gateways on the same WAN interface or do you have 2 WAN interfaces each with their own gateway?

                Your rule specifies "WAN" so it's only going to fire after traffic has already been translated to "WAN"'s public IP address. There is no question of "WAN2" ever being used. If it worked before, it sounds like it was thanks to a bug that has now been fixed.

                Unless you can somehow make the OS itself use the "LoadBalancer" gateway I don't see how it could work. You should probably install Squid on a separate box and use a conditional gateway rule on that interface for incoming traffic from Squid.

                1 Reply Last reply Reply Quote 0
                • K
                  kathampy
                  last edited by

                  Try selecting both WAN and WAN2 in the floating rule. IMO it still shouldn't work since NAT has already taken place, but try your luck.

                  1 Reply Last reply Reply Quote 0
                  • C
                    cmb
                    last edited by

                    I don't see where that rule would have ever done anything since quick isn't checked, the default pass out rules will override it.

                    1 Reply Last reply Reply Quote 0
                    • H
                      hyrol
                      last edited by

                      My knowledge, squid works only in WAN, that's why i need Floating rules for multi wan work in squid.

                      1 Reply Last reply Reply Quote 0
                      • R
                        ruggero
                        last edited by

                        i have the same problem. In pfsense 2.03 i can use all my wan with squid. In pfsense 2.1 squid only use default wan.
                        In 2.03 i use directive tcp_outgoing_address 127.0.0.1 in squid and add a floating rule with quick flag on that pass the traffic from the default gateway to a gateway Group.

                        How can do the same in pfsense 2.1

                        thanks.

                        1 Reply Last reply Reply Quote 0
                        • E
                          Ekrem
                          last edited by

                          some problem…i cant fix it...much people wait fix that...in my country...

                          1 Reply Last reply Reply Quote 0
                          • H
                            hyrol
                            last edited by

                            maybe squid proxy not compatible for pfsense 2.1.

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              Not sure what's the "me too" stuff about. If you are creating the broken rule without "quick" checkbox, it will not ever apply, as noted by cmb.

                              1 Reply Last reply Reply Quote 0
                              • C
                                craibo
                                last edited by

                                Hi doktornotor, hyrol

                                I understand from the thread that the rule was working due to a "bug" prior to 2.1, however is there another way to get Squid to use a Multi WAN Loadbalancing gateway?
                                The rule may have been a bug but it was a great help!!

                                Kind Regards and thanks in advance

                                P.S hyrol thank you for your Squid with Load balancing solution it has worked brilliantly for me prior to upgrading.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  doktornotor Banned
                                  last edited by

                                  Which part of "you must tick the quick checkbox" for the rule to have any effect is unclear?

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    craibo
                                    last edited by

                                    That does not fix the problem of the load balancing. Does the same as if it wasn't checked…

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      miami71it
                                      last edited by

                                      scusa non capisco provo a postarti le cose che ho fatto

                                      alias : host(s) e poi sotto ho aggiunto www.speedtest.net
                                      ruels : Pass - LAN - IMCP - any - 192.168.0.15 - speedtest.net - GTWOPT1

                                      la regola l'ho messa anche in varie posizioni ma non va se vado su speedtest mi mostra l'ip della WAN e non della OPT1 e funziona se spendo la WAN mi va in failover e solo in quel caso va in OPT1

                                      ma la mia domanda era oltre a fare la regola su ruels devo fare qualcosa su out/nat ecc ecc?

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        doktornotor Banned
                                        last edited by

                                        Uh, English please!

                                        1 Reply Last reply Reply Quote 0
                                        • H
                                          hyrol
                                          last edited by

                                          I have been using another method "Use sticky connections", but not Load Balacing i want, it is just temporary use.

                                          ![Use sticky connections.png](/public/imported_attachments/1/Use sticky connections.png)
                                          ![Use sticky connections.png_thumb](/public/imported_attachments/1/Use sticky connections.png_thumb)

                                          1 Reply Last reply Reply Quote 0
                                          • technicalT
                                            technical
                                            last edited by

                                            i stuck that problem to 2.1

                                            squid - (wpad configured) - loadbalance not working.

                                            Necati Selim GÜNER
                                            IT Technician

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.