Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Floating Rule WAN1 OUT triggering for WAN2 traffic while WAN1 is down

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 750 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      kathampy
      last edited by

      WAN1 is the default gateway.
      Default Gateway Switching is disabled.
      Skip Rules When Gateway Is Down is disabled.

      LAN Rule: WAN2 Traffic
      Destination Port: <ports>Gateway: WAN2
      Tag: SKIP_DEFAULT
      Action: Pass

      LAN Rule: Default Traffic
      Destination: Any
      Action: Pass

      Floating Rule: Skip Default
      Interface: WAN1
      Direction: OUT
      Tagged: SKIP_DEFAULT
      Action: Reject

      I want the "WAN2 Traffic" rule to use only WAN2 and the traffic should be rejected if WAN2 is down. This works fine. If WAN2 is down and WAN1 is up, pfSense recreates the "WAN 2 Traffic" rule with the default gateway (WAN1) and the floating rule blocks the traffic on WAN1.

      However if WAN1 is down and WAN2 is up, the floating rule still triggers and rejects the traffic even though it is set only on interface WAN1. The firewall logs show that the floating rule interface was WAN2! Why is the floating rule suddenly matching WAN2 traffic when WAN1 is down? I worked around it by adding "Source Address: WAN1_Address" to the floating rule, but this should not be required.

      Also, if both WAN1 and WAN2 are up, it works fine as the rule is not triggered for WAN2 traffic.</ports>

      1 Reply Last reply Reply Quote 0
      • C Offline
        cmb
        last edited by

        Have 'quick' set on the floating rule? It'll need to be.

        1 Reply Last reply Reply Quote 0
        • K Offline
          kathampy
          last edited by

          Yes "Quick" is set. Even if it isn't, why would it trigger for an interface not even selected in the rule?

          It's falsely triggering for WAN2 only when WAN1 is selected and WAN1 is down. As an experiment, it does not trigger if I select LAN as the interface and WAN1 is down.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.