<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Group gateway confused]]></title><description><![CDATA[<p dir="auto">Hi,<br />
I have 2 WAN, WAN1 and WAN2, WAN1 gateway is 172.17.0.254 and WAN2 gateway is 172.16.0.254</p>
<p dir="auto">I created a group, "GWalt", as WAN1 (Tier1) and WAN2(Tier2).  I assigned an IP of a client to "GWalt" in firewall rule and turned<br />
on the log.</p>
<p dir="auto">What I noticed is the log show its going through "GWalt" and gateway IP is 172.17.0.254, that is correct.</p>
<p dir="auto">But when I tried on the same client, I do "tracert yahoo" it shows "172.16.0.254", kind of funny which path it follows?</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/72560/group-gateway-confused</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 00:20:29 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/72560.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 Aug 2014 08:47:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Group gateway confused on Mon, 25 Aug 2014 12:46:10 GMT]]></title><description><![CDATA[<p dir="auto">Got It !</p>
<p dir="auto">Tiers 1 is 172.17.0.254<br />
Tiers 2 is 172.16.0.254<br />
And your PF default's GW is your Tiers 2 (172.16.0.254).</p>
<p dir="auto">In your rule, you specify the kind on trafic that should be filtered : in your case "TCP" only. So it won't apply to any ICMP traffic (a trace route uses ICMP). But it will for HTTP trafic though.</p>
<p dir="auto">So, because you don't specify ICMP kind of trafic, your default routing policy aplly : Go through the default PF's GW.</p>
<p dir="auto">Here is your answer.</p>
]]></description><link>https://forum.netgate.com/post/479417</link><guid isPermaLink="true">https://forum.netgate.com/post/479417</guid><dc:creator><![CDATA[AIMS-Informatique]]></dc:creator><pubDate>Mon, 25 Aug 2014 12:46:10 GMT</pubDate></item><item><title><![CDATA[Reply to Group gateway confused on Sat, 23 Aug 2014 07:37:24 GMT]]></title><description><![CDATA[<p dir="auto">1.  yes it is right on top - see attached file<br />
2.  yes they r all online - see attached ping return<br />
3.  routing default set to 172.16.0.254 - see attached GW config<br />
4.  yes, I do have a DHCP setup but specific client with fixed IP under static IP mapping in LAN<br />
    yes, gateway is 192.168.1.1, see attached file<br />
5.  No, no other route…blank</p>
<p dir="auto">I have chanced some of the naming, WAN1=&gt;WAN, WAN2=&gt;WAN1 and "GWalt" =&gt; "GrpGWStaff"<br />
but the IP remain unchanged.</p>
<p dir="auto">I also attached a traceroute and log from the System Log.</p>
<p dir="auto">![Screen Shot 08-23-14 at 03.28 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.28 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.28 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.28 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 03.19 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.19 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.19 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.19 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 03.13 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.13 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.13 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.13 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 03.11 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.11 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.11 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.11 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 03.04 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.04 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.04 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.04 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 03.03 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.03 PM.PNG)<br />
![Screen Shot 08-23-14 at 03.03 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 03.03 PM.PNG_thumb)<br />
![Screen Shot 08-23-14 at 02.37 PM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 02.37 PM.PNG)<br />
![Screen Shot 08-23-14 at 02.37 PM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-23-14 at 02.37 PM.PNG_thumb)</p>
]]></description><link>https://forum.netgate.com/post/479144</link><guid isPermaLink="true">https://forum.netgate.com/post/479144</guid><dc:creator><![CDATA[tanniit]]></dc:creator><pubDate>Sat, 23 Aug 2014 07:37:24 GMT</pubDate></item><item><title><![CDATA[Reply to Group gateway confused on Fri, 22 Aug 2014 09:28:19 GMT]]></title><description><![CDATA[<p dir="auto">1 - check you're specific client firewall rule position in the list : should be first.<br />
2 - Are all you're GW members "Online" : Status-&gt;Gateways ? Are the RTT and Loss parameters OK ?<br />
3 - Which GW in "Routing" section, is set as default ? can you send us the configuration of you're GW and GW Groups ?<br />
4 - What is you're client DHCP (or static) configuration ? The DNS and GW should be 192.168.1.1 (you're pf's LAN Adress).<br />
5 - You should'nt have any Route configured in you're PF.</p>
<p dir="auto">If you try consecutives tracert from client do you see the trafic going through WAN1 and then WAN2 ? or only WAN</p>
]]></description><link>https://forum.netgate.com/post/478938</link><guid isPermaLink="true">https://forum.netgate.com/post/478938</guid><dc:creator><![CDATA[AIMS-Informatique]]></dc:creator><pubDate>Fri, 22 Aug 2014 09:28:19 GMT</pubDate></item><item><title><![CDATA[Reply to Group gateway confused on Fri, 22 Aug 2014 03:24:37 GMT]]></title><description><![CDATA[<p dir="auto">Yes I can ping from from client.<br />
May be the attached network diagram helps.</p>
<p dir="auto">![Screen Shot 08-15-14 at 07.29 AM.PNG](/public/<em>imported_attachments</em>/1/Screen Shot 08-15-14 at 07.29 AM.PNG)<br />
![Screen Shot 08-15-14 at 07.29 AM.PNG_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 08-15-14 at 07.29 AM.PNG_thumb)</p>
]]></description><link>https://forum.netgate.com/post/478903</link><guid isPermaLink="true">https://forum.netgate.com/post/478903</guid><dc:creator><![CDATA[tanniit]]></dc:creator><pubDate>Fri, 22 Aug 2014 03:24:37 GMT</pubDate></item><item><title><![CDATA[Reply to Group gateway confused on Thu, 21 Aug 2014 14:43:19 GMT]]></title><description><![CDATA[<p dir="auto">Weird you're using private IP range for WAN purpose… NATed-NAT on WAN is tricky!</p>
<p dir="auto">Here are the defined RFC PRIVATE IP ranges :<br />
10.0.0.0        -  10.255.255.255  (10/8 prefix)<br />
172.16.0.0      -  172.31.255.255  (172.16/12 prefix)<br />
192.168.0.0    -  192.168.255.255 (192.168/16 prefix)</p>
<p dir="auto">But you're problem is not here...</p>
<p dir="auto">What's the GW monitor adresses ?<br />
Does your gateways responds to IMCP requests ?<br />
Is you're rule on the top of the list (should be) ?</p>
]]></description><link>https://forum.netgate.com/post/478788</link><guid isPermaLink="true">https://forum.netgate.com/post/478788</guid><dc:creator><![CDATA[AIMS-Informatique]]></dc:creator><pubDate>Thu, 21 Aug 2014 14:43:19 GMT</pubDate></item></channel></rss>