<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Firewall-Cluster &#x2F; Active-Active &#x2F; Link Aggregation… Questions]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">we plan to replace our current Firewall / VPN by PFSense with OpenVPN. We want to install 2 servers as a cluster. But I've many questions.</p>
<p dir="auto">Is it possible to run the two firewall nodes in active-active mode or only in active-passive (failover)?<br />
If active-active is possible: Is it possible to Load-Balance connection over both firewalls (not multi-wan-loadbalancing)?</p>
<p dir="auto">FreeBSD supports Link Aggregation. In WebGUI I can't setup LAGs. On Shell I can do this. Is it possible to use LAGs? Is LAG-support<br />
in WebUI planned?</p>
<p dir="auto">We've many (20) VLans e.g. Mgmt, DMZ, Server, Backup, User-Lan1-x. Is it possible to Setup an separate Management-IP, so that I can only configure<br />
from Mgmt-VLan? Do I need Vlans or can I also use one LAN (Firewall-Transfer-Network) and setup all rules on this interface?</p>
<p dir="auto">Greetings<br />
Thomas</p>
]]></description><link>https://forum.netgate.com/topic/8636/firewall-cluster-active-active-link-aggregation-questions</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 10:51:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/8636.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Apr 2008 16:20:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Firewall-Cluster &#x2F; Active-Active &#x2F; Link Aggregation… Questions on Mon, 28 Apr 2008 17:06:02 GMT]]></title><description><![CDATA[<p dir="auto">Details to my last question:</p>
<p dir="auto">Firewall LAN-Interface: 10.10.254.254<br />
Layer-3-Switch forwards all traffic to extern to firwall-lan-interface (10.10.254.254)</p>
<p dir="auto">Sample:<br />
VLAN 1  10.0.0.0 ==&gt; 10.10.254.254<br />
VLAN 2  10.0.1.0 ==&gt; 10.10.254.254<br />
VLAN 2  10.0.2.0 ==&gt; 10.10.254.254<br />
…</p>
<p dir="auto">Do I need Setup separate Vlans or can I use Aliases instead?</p>
]]></description><link>https://forum.netgate.com/post/172346</link><guid isPermaLink="true">https://forum.netgate.com/post/172346</guid><dc:creator><![CDATA[KoalaTNR]]></dc:creator><pubDate>Mon, 28 Apr 2008 17:06:02 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall-Cluster &#x2F; Active-Active &#x2F; Link Aggregation… Questions on Mon, 28 Apr 2008 19:53:39 GMT]]></title><description><![CDATA[<p dir="auto">Active-active is not availlable as far as i know.</p>
<p dir="auto">If you cannot do something in the GUI then it's not supported.<br />
Since you can do it from the shell it's "possible" to do it.<br />
But you're on your own.</p>
<p dir="auto">If you want to restrict access to the webgui:<br />
Just create your rules so they are that only certain IP's / Interfaces have access to the webgui.</p>
<p dir="auto">something along the lines of:<br />
allow<br />
source: LAN-subnet<br />
destination: "! LAN-interface" (NOT the LAN-interface)</p>
<p dir="auto">At the bottom of all rules is an invisible block everything.<br />
So with this rule you would still allow access to everywhere (internet) except the LAN-interface addess.</p>
<p dir="auto">Use the Alias system if you have more complex destinations.</p>
<p dir="auto">You also might want to disable the "anti-lockout option" under advanced since without that pfSense would still allow access to the webgui even you dont have a rule that explicitely allows it.<br />
Just be aware that if you disable this option and you dont have a rule that allows access to the webgui you're locked out :)</p>
<p dir="auto">If you have multiple VLAN's you can configure them under interfaces –&gt; assign --&gt; VLANs.<br />
Each VLAN appears as seperate "Interface" in pfSense.</p>
<p dir="auto">I dont understand what you mean with your last question.<br />
Maybe a diagramm would help.</p>
]]></description><link>https://forum.netgate.com/post/172344</link><guid isPermaLink="true">https://forum.netgate.com/post/172344</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Mon, 28 Apr 2008 19:53:39 GMT</pubDate></item></channel></rss>