Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi Wan sending packets through ungrouped gateway

    Scheduled Pinned Locked Moved Routing and Multi WAN
    3 Posts 3 Posters 910 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bruhahaa
      last edited by

      Hello,

      I am having an issue setting up failover for a client. They have 2 different ISPs coming into the building, and I have both of the interfaces set in a group, with one on tier 1, and another on tier 2. We also have a gateway that is located on the lan that is used to direct traffic through a vpn tunnel, but is only meant to be used with one website so static routes have been set on pfsense.

      To explain better:
      -WAN1-ISP1
      -WAN2-ISP2
      -LANGW-lan only gateway for specific site

      PFSense is the only router in place, directly connected to everything. When WAN1 goes down, instead of failing over to WAN2, PFSense sets LANGW as the primary route for all traffic, causing everything to fail. LANGW isn't part of any failover groups. The router has been reset multiple times with the same affect.

      Also if I manually set WAN2 as the default route, it works, and all traffic flows, so it isn't an issue with WAN2 not responding.

      Attached are the images of my setup.  If anyone could help me that would be amazing.

      System-Gateway.jpg
      System-Gateway.jpg_thumb
      System-GatewayGroups.jpg
      System-GatewayGroups.jpg_thumb
      System-GatewayGroups-Edit.jpg
      System-GatewayGroups-Edit.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • T Offline
        timthetortoise
        last edited by

        Ensure that your LAN to WAN firewall rules set your failover group as the gateway, otherwise it will not get used at all.

        1 Reply Last reply Reply Quote 0
        • P Offline
          phil.davis
          last edited by

          And it sounds like you have default gateway switching enabled, that would be why default traffic is failing over to some other gateway, in this instance the gateway on LAN. The LANGW should just be a gateway, it should not also be selected as the gateway for the LAN interface (on Interffaces->LAN). If the LAN interface config has a gateway specified, then the system will consider that a possible general way out to "the internet" and may use it when default gateway switching is enabled.

          As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
          If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.