OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • High availability »
  • 2 OPNsenses same WAN network Broadcast Flood
« previous next »
  • Print
Pages: 1 [2] 3

Author Topic: 2 OPNsenses same WAN network Broadcast Flood  (Read 3976 times)

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #15 on: May 28, 2024, 02:34:13 pm »
...you had me at "MDNS"....
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #16 on: May 28, 2024, 03:07:44 pm »
You have a Multi WAN Setup?
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #17 on: May 28, 2024, 03:11:57 pm »
Is there the possibility that a Firewal rule relay DHCP or DNS traffic to the WAN interface?

EDIT:

Hope this was the solution for me. Testing at the moment ....

EDIT 2:
Sadly not the solution :(. Have a floating rule which allows dhcp,dns,ntp .... to "this firewall" for all local networks. Deactivated the rule, but broadcast flood coming in ...
« Last Edit: May 28, 2024, 04:06:04 pm by aeschma »
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #18 on: June 03, 2024, 09:02:18 am »
@aeschma

Yes, I actually do have 2 WAN connections for failover. But those also have their own interfaces.

No firewall rules that should relay this traffic.
The other WAN does not have this problem.
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #19 on: June 03, 2024, 01:38:08 pm »
Same Setup here ....

But I can't use my second WAN for HA. Second WAN is DHCP only. So second WAN is configured on both OPNsenses but only plugged into one Sense.... on the other is the interface offline.

Your ISP is also Vodafone? If so, do you think it could be an Vodafone issue?
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #20 on: June 03, 2024, 03:47:37 pm »
Yes, my second ISP is Vodafone.
The main WAN is Telekom, no problems there.

Actually it came to my mind, there is a firewall rule that could be the culprit... Because I'm using load-balancing, there's a firewall rule that splits traffic to both WAN interfaces.
I will be on-site on Saturday and will check whether this causes the problem. (Although, if it is... Then it should be on both WAN interfaces, right?)

Do you use load-balancing or just failover?
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #21 on: June 03, 2024, 04:25:40 pm »
Yes, I use Load Balancing too.

That's why I asked, but if it was due to Load Balancing, both connections would have to be affected.

I remember a forum post where someone successfully runs HA with Vodafone Cable. So there must exist an solution ....
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #22 on: June 04, 2024, 12:05:04 pm »
How did you configure multi WAN? Firewall rule with redirect gateway?
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #23 on: June 05, 2024, 07:37:37 am »
Yes. I have an RFC1918 Alias, which I use to route the public traffic to a Gateway-Group.
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #24 on: June 05, 2024, 09:05:18 am »
So 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, right?

Try to add 224.0.0.0/24, 239.255.0.0/16, 239.192.0.0/14 to the alias.
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #25 on: June 05, 2024, 09:32:04 am »
Ok, I will try it. I can't try it until the weekend because I won't be back before then. I will write you.
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #26 on: June 10, 2024, 11:14:57 am »
I tried it last weekend and it seems like the problem is solved for me.

Kinda feel stupid now, because it should have been obvious from the start to exclude ALL subnets from this firewall rule, that don't belong on a WAN network...
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #27 on: June 10, 2024, 03:25:18 pm »
Good to hear it's working for you. Sadly dosen't work for me :(

Here is my alias and firewall rule.
Logged

HenrikHenkel

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #28 on: June 14, 2024, 02:21:15 pm »
Hi. Sorry for the late response.

The firewall rule and alias look exactly like mine...

Might sound stupid, but did you synchronize the changes to your second firewall?
Logged

aeschma

  • Jr. Member
  • **
  • Posts: 65
  • Karma: 1
    • View Profile
Re: 2 OPNsenses same WAN network Broadcast Flood
« Reply #29 on: June 14, 2024, 03:13:04 pm »
Yes, both Firewalls are synchonized. I even restarted the firewalls afterwards.
Logged

  • Print
Pages: 1 [2] 3
« previous next »
  • OPNsense Forum »
  • English Forums »
  • High availability »
  • 2 OPNsenses same WAN network Broadcast Flood
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2