Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
« previous
next »
Print
Pages:
1
[
2
]
Author
Topic: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable (Read 5029 times)
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #15 on:
August 11, 2023, 04:38:13 pm »
Ok well that didn't take long. Had a real event occur minutes after I posted my previous reply.
Still not seeing a full fallback to Tier 1. See image below. This was taken a few minutes after Tier 1 came back online. Light green is WAN (Tier 1), Dark green is WAN2 (Tier 2).
I even tried forcing the WAN2 down and it still has traffic routed through it. See 2nd image.
Img 1.
Img 2.
«
Last Edit: August 11, 2023, 04:48:23 pm by axsdenied
»
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #16 on:
August 11, 2023, 05:05:08 pm »
Not sure where I got it my head that I needed to be on the development branch to apply patches but I caught my error. Everything above is and applies to the dev branch.
I've since reverted back to the community branch and have applied the patch to it and will continue to test.
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
franco
Administrator
Hero Member
Posts: 17660
Karma: 1611
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #17 on:
August 14, 2023, 01:26:37 pm »
> I've since reverted back to the community branch and have applied the patch to it and will continue to test.
So how's that test going?
Cheers,
Franco
Logged
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #18 on:
August 15, 2023, 06:04:34 am »
So far so good, but I haven't had a chance to simulate it. Will do this week!
Side question: Did you guys do any memory optimization as well? I've noticed overall usage, with my config, hovering around 2.5GB. In 23.1 series it would slowly ramp up to 5 to 6GB.
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
franco
Administrator
Hero Member
Posts: 17660
Karma: 1611
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #19 on:
August 15, 2023, 08:40:46 am »
Not that I'm aware of.
Cheers,
Franco
Logged
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #20 on:
August 20, 2023, 07:55:39 am »
Ok I went to simulate a test by marking the gateway as down but nothing shifted. I can physically unplug the primary WAN to test as well but thought I'd share this.
«
Last Edit: August 20, 2023, 08:00:50 am by axsdenied
»
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
franco
Administrator
Hero Member
Posts: 17660
Karma: 1611
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #21 on:
August 21, 2023, 01:28:37 pm »
"force_down" handling previously is a bit difficult to say given its niche value. Monitoring-induced downtimes already work and cable disconnects will work on 23.7.2.
I've added a commit to include force_down for testing as it would make sense to consolidate. If it works we can discuss adding it to 23.7.3.
https://github.com/opnsense/core/commit/7f1d8c66d3
Cheers,
Franco
Logged
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #22 on:
August 25, 2023, 05:12:43 pm »
Upgraded to 23.7.2 and tried simulating a fallback:
Everything fell back smoothly after WAN when down but after it came back up, existing sessions stayed with WAN2 and never went back to WAN.
Should I re-apply the patch and try again?
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
franco
Administrator
Hero Member
Posts: 17660
Karma: 1611
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #23 on:
August 25, 2023, 07:06:06 pm »
On 23.7.2 there is nothing to reapply.
Do you have sticky connections enabled?
Cheers,
Franco
Logged
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #24 on:
August 25, 2023, 11:43:08 pm »
Sticky connections is not enabled. Overtime, about an hour or 2 the connections did move over. Just not immediately.
Is it designed to wait for sessions to end or expire before moving?
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
franco
Administrator
Hero Member
Posts: 17660
Karma: 1611
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #25 on:
August 26, 2023, 08:43:57 pm »
Yep. Stateful tracking. You can try to experiment with rules that do not keep state (advanced rule settings). It might move over immediately, but it depends on the client liking that or not.
Cheers,
Franco
Logged
axsdenied
Full Member
Posts: 199
Karma: 9
Re: Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable
«
Reply #26 on:
August 26, 2023, 09:31:08 pm »
If that's by design, which makes logical sense for greatest session stability, then I had the wrong expectations.
Is there an option to force then back, much like connections are forced when WAN goes down for triggers? Most of the clients and apps I use respond well to being forced over with the exception of Discord and Hulu (when you have the TV package - they do a IP "home" check. It also seems to never release it's session, or at least that's the behavior it exhibits)
«
Last Edit: August 26, 2023, 09:37:52 pm by axsdenied
»
Logged
OPNsense 24.7.7 running on:
Dell Optiplex 3050
Intel I5-7600 @ 3.5Ghz (4 Cores)
Intel I350-T4 Nic
8G DDR4
256G SSD
Print
Pages:
1
[
2
]
« previous
next »
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Multi-Wan Setup Failback from Tier 2 to Tier 1 unreliable