Multi-WAN (pfSense 2.1.2): Can ping/tracert sites, but cannot browse web

  • Hi All,

    First, I'd like to say that pfSense is awesome!

    Anyway, I have a double DSL setup from different providers.

    It looks like this:

    DSL A –------|
                        | pfSense 2.1.2 Box --------| LAN
    DSL B -------

    DSL A (Default Gateway) =
    DSL B =
    LAN =

    When I try to make a host ( use DSL B as it's gateway (via LAN rule), the host cannot browse the web, but can ping and tracert sites successfully.
    Other applications (Steam, etc) don't work as well.

    DNS Forwarder is enabled, my hosts use pfSense LAN IP address as the DNS server, nslookup works, browsing works for the other hosts on DSL A.

    This has been bothering me for almost a week, and any insight would be greatly appreciated.

    Please see attached if they are of any help.

    ![Rules- LAN.png](/public/imported_attachments/1/Rules- LAN.png)
    ![Rules- LAN.png_thumb](/public/imported_attachments/1/Rules- LAN.png_thumb)
    ![Rules - Floating.png](/public/imported_attachments/1/Rules - Floating.png)
    ![Rules - Floating.png_thumb](/public/imported_attachments/1/Rules - Floating.png_thumb)
    ![Gateway - WAN1.png](/public/imported_attachments/1/Gateway - WAN1.png)
    ![Gateway - WAN1.png_thumb](/public/imported_attachments/1/Gateway - WAN1.png_thumb)
    ![Gateway - WAN2.png](/public/imported_attachments/1/Gateway - WAN2.png)
    ![Gateway - WAN2.png_thumb](/public/imported_attachments/1/Gateway - WAN2.png_thumb)

  • Update:

    I tried changing the Default Gateway to DSL B, and changing the host's gateway to DSL A, and the same thing happens: ping and tracert to websites are successful, but I can't browse the web.

    Any tiny nudge in the right direction would be great, TIA.

  • Are you using squid?

  • Hi Sir,

    No, I'm not, but I did.

    I removed all other packages after upgrading to 2.1.2 (squid3, squid guard, sarg, ntop), in an attempt to lower resource usage on the VM (VirtualBox).

    Thanks for your time. :)

  • Well.. It's working now, but I have no idea how…

    I just enabled logging on the Load Balance LAN rule, and removed the Streaming and Bulk download enqueue floating rules..

    Thanks timthetortoise for taking the time to reply.

    I'm still stumped though.. :-[

  • It'd make sense that those rules would take precedence and not give the result you wanted since they weren't set to use the correct gateway group.

