Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How can i add firewall rules to not load balance traffic to these destinations

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 686 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hadiri
      last edited by

      Web site incompatibility with changing IP addresses in load balancing
      Some websites do not work properly if requests from the LAN are initiated from multiple public IP addresses. Hence load balancing is incompatible with these sites. Common examples are sites that maintain login sessions, most frequently online banking. This is most commonly observed with HTTPS sites so usually HTTPS should not be load balanced. Occasionally it is a problem with HTTP sites that maintain session, but this is rare.
      For sites that do not function with load balancing, add firewall rules to not load balance traffic to these destinations or protocols.
      how can i  add firewall rules to not load balance traffic to these destinations or protocols ????

      1 Reply Last reply Reply Quote 0
      • E
        earmani
        last edited by

        I nee help on that too, someone please …

        1 Reply Last reply Reply Quote 0
        • luckman212L
          luckman212 LAYER 8
          last edited by

          1. Go to Firewall > Aliases

          2. Create an "IP" alias which will contain the sites you need to disable the Loadbalancing for (e.g. banking sites etc)

          3. Add sites to it, can be IP or FQDN

          4. Save + Apply

          5. Now go to FW Rules > LAN

          6. Create a new LAN > any rule with "Destination" set to the name of the alias that you created in Step 2.  (N.B. make sure the rule is above your "default" LAN->any rule)

          7. Click Advanced and set your gateway to whatever you want (WAN1, Default, WAN2 etc… anything except the name of your LB group)

          8. Save + Apply

          9. Profit  ;)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.