OPNsense Forum

Archive => 19.1 Legacy Series => Topic started by: drivera on May 15, 2019, 12:25:58 am

Title: Firewall failover STILL not working
Post by: drivera on May 15, 2019, 12:25:58 am
Hi!  I've posted about this before (https://forum.opnsense.org/index.php?topic=11497.msg52045#msg52045).  The issue is still there: on a prolonged outage for the primary circuit (Cable), every so often the firewall's default gateway will simply get nulled out (i.e. set to "nothing") even though the secondary circuit (ADSL) is up and running.

The "workaround" is to log into the UI, open the ADSL gateway's configuration, save it (no changes!!), and then click on "Apply Changes". This causes the ADSL link to be selected as the default gateway.  But then again, a few minutes later, the same thing happens again (default gateway gets de-configured), and off we go again to the workaround...

Here are some configuration tidbits:


Basically, I have everything configured like the "textbooks" say I should have it, and yet I can't get it to work the way (I think) it should.  The problem seems to be with dpinger (or related processes), since if I change the VPN gateways to "Disable Gateway Monitoring" (i.e. assume they're always UP), then for some inexplicable reason they will be preferred ahead of the ADSL link as gateway, even though the ADSL link is in a higher tier within the same gateway group...!!!

Can someone please help me figure this out?

Thanks!
Title: Re: Firewall failover STILL not working
Post by: Antaris on June 04, 2019, 02:37:58 pm
I also have non-switching failover situation with 2 IPSs on fiber optic via media converters with public IP addresses.
The guide i used is:
https://wiki.opnsense.org/manual/how-tos/multiwan.html (https://wiki.opnsense.org/manual/how-tos/multiwan.html)
Title: Re: Firewall failover STILL not working
Post by: mimugmail on June 05, 2019, 07:05:39 am
Do you have default gw switching enabled on System : Settings : General?
Title: Re: Firewall failover STILL not working
Post by: Antaris on June 05, 2019, 12:15:11 pm
GW switching was not enabled. I now find this variable thanks to you. It's not mentioned in official guide.
Thanks a lot. Will check it on site.
Title: Re: Firewall failover STILL not working
Post by: mimugmail on June 05, 2019, 12:19:25 pm
You are very welcome to contribute this to the docs :)
https://github.com/opnsense/docs
Title: Re: Firewall failover STILL not working
Post by: Antaris on June 07, 2019, 07:14:58 am
The system started to switching gateways with the help of @mimugmail. But when the primary ISP goes up again, the router not switching to Tier1 until Tier2 is not failed (in my case Tier1 is ~1gbps, Tier2 is ~150mbps).
About editing the docs via github i will try, but i am new it github too.
Title: Re: Firewall failover STILL not working
Post by: drivera on January 19, 2020, 12:32:06 am
Do you have default gw switching enabled on System : Settings : General?

In my case, this setting has always been on, and I still have this issue. In fact, I just made another post about it providing a bit more info since this thread was sort of stale...
Title: Re: Firewall failover STILL not working
Post by: mimugmail on January 19, 2020, 07:02:50 am
Link?
Title: Re: Firewall failover STILL not working
Post by: Antaris on January 19, 2020, 07:43:41 pm
Link?
https://forum.opnsense.org/index.php?topic=15554.0 (https://forum.opnsense.org/index.php?topic=15554.0)