<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Failover and routing issue with multi (dual) WAN with multi (dual) LAN]]></title><description><![CDATA[<p dir="auto">Hi Everyone, I have been banging my head on this one for a few evenings and can't seem to figure out why my LAN1/2 can't talk to each other when I change gateway to anything but default.</p>
<p dir="auto">Here is the setup, tested with both 2.2.2 and 2.2.4 release</p>
<p dir="auto">2 X WAN<br />
2 X LAN<br />
LAN1 FW IP 10.0.1.3<br />
LAN2 FW IP 10.2.1.3</p>
<p dir="auto">LAN1 host IP 10.0.1.6<br />
LAN2 host IP 10.2.1.6</p>
<p dir="auto">Here are the Gateway Groups</p>
<p dir="auto">WAN1 and WAN2 in a Gateway Group call LB with both WAN set to tier 1 for load balance.<br />
WAN1 and WAN2 in a Gateway Group call 1over2 with WAN1 set to tier 1 and WAN2 set to tier 2 for WAN1 failover to WAN2<br />
WAN1 and WAN2 in a Gateway Group call 2over1 with WAN1 set to tier 2 and WAN2 set to tier 1 for WAN2 failover to WAN1</p>
<p dir="auto">SCENARIO 1</p>
<p dir="auto">When I set both LAN1 and LAN2 gateway to LB. Hosts on LAN1 and LAN2 are able to get internet, LB round robin seems to working<br />
LAN1 host 10.0.1.6 can ping FW LAN2 IP 10.2.1.3<br />
LAN2 host 10.2.1.6 can ping FW LAN1 IP 10.0.1.3</p>
<p dir="auto">but</p>
<p dir="auto">LAN1 host 10.0.1.6 can NOT ping LAN2 host 10.2.1.3 and vise versa, I don't see anything in firewall log showing blocked</p>
<p dir="auto">SCENARIO 2</p>
<p dir="auto">When I set both LAN1 and LAN2 gateway to 1over2. Hosts on LAN1 and LAN2 are able to get internet with WAN1 FW IP</p>
<p dir="auto">but same issue with scenario 1 LAN1/2 hosts not able to ping each other</p>
<p dir="auto">SCENARIO 3</p>
<p dir="auto">When I set both LAN1 and LAN2 gateway to 2over1. Hosts on LAN1 and LAN2 are able to get internet with WAN2 FW IP</p>
<p dir="auto">but same issue with scenario 1 LAN1/2 hosts not able to ping each other</p>
<p dir="auto">a few notes</p>
<p dir="auto">outbound NAT is set to auto<br />
when both LAN1 and LAN2 gateway are set to default, Hosts on LAN1 and LAN2 are able to get internet via WAN1 only, which is expected, there is no problem with LAN1/2 hosts talking to each other.<br />
I reset state tables after each test<br />
for both LAN1 and LAN2, there are no other FW rules other than the single rule of IPv4* LAN1(2) net, * port, * destination, * port, and Gateway set to each scenario.</p>
<p dir="auto">I am not good any visio, but I can attach some diagrams if it helps.</p>
<p dir="auto">thanks</p>
<p dir="auto">Robin</p>
]]></description><link>https://forum.netgate.com/topic/88695/failover-and-routing-issue-with-multi-dual-wan-with-multi-dual-lan</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 19:18:23 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/88695.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Sep 2015 18:05:07 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Failover and routing issue with multi (dual) WAN with multi (dual) LAN on Fri, 04 Sep 2015 18:18:44 GMT]]></title><description><![CDATA[<p dir="auto">awesome, Derelict</p>
<p dir="auto">thanks, looks like that's what I am missing. I just tested by creating a IP alias named LocalNetwork with values of 10.0.1.0/24 and 10.2.1.0/24.</p>
<p dir="auto">then add firewall rule of IPv4* LAN1(2) net, * port, LocalNetwork destination, * port, * Gateway to both LAN1 and LAN2</p>
<p dir="auto">insert that rule before the LB rule. and like magic, it's working correctly now.</p>
]]></description><link>https://forum.netgate.com/post/568693</link><guid isPermaLink="true">https://forum.netgate.com/post/568693</guid><dc:creator><![CDATA[robinxyz]]></dc:creator><pubDate>Fri, 04 Sep 2015 18:18:44 GMT</pubDate></item><item><title><![CDATA[Reply to Failover and routing issue with multi (dual) WAN with multi (dual) LAN on Fri, 04 Sep 2015 18:07:58 GMT]]></title><description><![CDATA[<p dir="auto">https://doc.pfsense.org/index.php/What_is_policy_routing</p>
<p dir="auto">And this is what you need to do:</p>
<p dir="auto">https://doc.pfsense.org/index.php/Bypassing_Policy_Routing</p>
]]></description><link>https://forum.netgate.com/post/568689</link><guid isPermaLink="true">https://forum.netgate.com/post/568689</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Fri, 04 Sep 2015 18:07:58 GMT</pubDate></item></channel></rss>