<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Firewall rule match based on Virtual IP]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">The current setup had 2 WAN connections, with 2 WAN routers accessible on the same subnet. Each device was then manually configured which router to use.</p>
<p dir="auto">I've matched the setup and created a virtual IP matching the previous alternative router. I can use both the main and IP alias as a router, which works fine.</p>
<p dir="auto">I can also set up firewall rules based on IP address of the guest to route them from either main or alternative gateway.</p>
<p dir="auto">However, my question is - is there a way to match on which virtual IP the packet came in and then decide on which WAN it should go? I can only see a match on the interface, but both of the IPs are on the same interface so I am not allowed the distinction.</p>
]]></description><link>https://forum.netgate.com/topic/74164/firewall-rule-match-based-on-virtual-ip</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 14:14:26 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/74164.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 30 Sep 2014 10:35:02 GMT</pubDate><ttl>60</ttl></channel></rss>