26.7 Default Gateway no longer switching.

Started by niei, July 19, 2026, 03:44:07 PM

Previous topic - Next topic
Hi Everyone,

After upgrading my secondary firewall to 26.7 I noticed that the default gateway switching no longer works automatically.
I have two gateways configured, the WAN Router and the HA Interface IP of the Primary Firewall. The Idea is as long as the WAN Router is reachable (so, as long as the firewall has the virtual ip of the wan interface) it uses that as the default gateway. But as soon as the WAN Router is no longer reachable it should use the HA IP of the Primary Firewall (which in turn then has the virutal ip to talk to the WAN Router) as the default gateway and so access the Internet over the HA Link.

To explain; This whole setup is to only use one IP Address in the WAN Network, so that when I finally get fiber Internet and can scrap my Provider Router, I can use only singluar IP and don't have to buy a whole /29 Subnet or somthing like that.

However, after the upgrade of my secondary Firewall I noticed that it couldn't check for updates. I switched to mirror and still, no connectivity. So I tried pinging 8.8.8.8 and behold: Doesn't work.

I checked to Routing table (routing-table.png) and I see that it still has the IP Address of the WAN Router (192.168.1.1) as the default Gateway. Even though the Gateway Configuration Page (gw-conf.png) states correctly that the WAN Router is down and that the HA IP of the primary Firewall should be the active default gateway. And yes, I checked, the HA IP Gateway is a default gateway candidate (ha_ip-conf.png) and default gateway switching is enabled in the system settings (system-settings.png).

The only way it switches to the HA IP as the default gateway is when I manually disable the WAN Router in the Gateway configuration. Even then, It doesn't switch back to the WAN Router when the secondary firewall gets the Virtual IP and I have to now manually disable the HA IP Gateway.

And yes, I rebooted the secondary firewall manually after the update to see if that would fix the issue. It didnt.

What gives?

FYI, on my Primary Firewall, running 26.1.11_6, the behaivour is as expected. So I think it must have something todo with the 26.7 Update.
- NIEI
Redundant Sophos XG210

i have the same issues ince upgrading to 26.7

Updating to 26.7.1 didn't fix the issue for me.

Same situation here since 26.7 and 26.7.1 also didn't fix it for me either.

I have a very similar setup as niei and I also triple checked all my gateways configs. Nothing changed since 26.7, the configs remained as they should be and worked well before 26.7.

When I fail over, I end up with a bad default gateway and no internet access. As if the default gateway isn't being configured anymore when the WAN comes back up after HA failover and you end up with an UP WAN link but without the default gateway pointing to it in the routing table so no internet access.

For now, the only workaround I found to fix this without playing manually with the routing table is: I have to manually (after a failover) go in System, Gateways, Configuration and (without changing anything) I simply click Apply and the routing table updates and the default gateway is corrected. If I don't do this, it will not fix itself.

This isn't super easy to explain, sorry, but this is a major issue.


the Patch 26.7.1_1 fixed the issue for me, thank you!

Note that due to 26.7.1(_1) not rebooting you need to restart the "Gateway Watcher" service to apply the fix.  It also has to be _1 specifically. .1 doesn't have the fix.


Cheers,
Franco