OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Multi WAN
« previous next »
  • Print
Pages: [1]

Author Topic: Multi WAN  (Read 5569 times)

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Multi WAN
« on: October 25, 2017, 12:15:55 pm »
Dear All,
i have posted many times about multi WAN and no one have ever helped me.
i have configured the Multi WAN as following https://docs.opnsense.org/manual/how-tos/multiwan.html
internet does works, every time when the WAN1 or WAN2 down goes we have to reboot the firewall in order it will swap the Gateways.
Can someone please advise here why is this happening and what I am missing in the configurations ?
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN never works
« Reply #1 on: October 25, 2017, 12:16:10 pm »
Extra Notices,
what I have noticed is we have a Group NICS Productions with VLAN10-11-12-13 and the LAN 192.168.1.1 where the VLANS are nested.
would this be the issue with Multi WAN ?
Can someone now please provide advice ?
« Last Edit: October 25, 2017, 12:52:51 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6302
  • Karma: 434
    • View Profile
Re: Multi WAN
« Reply #2 on: October 25, 2017, 12:52:20 pm »
Please provide:

- Number of WAN uplinks
- Type of WAN uplinks (pppoe, static, dhcp)
- Gateway monitoring active on WAN?
- Gateway switching enabled/disabled
- Sticky connections enabled/disabled
- LAN setup (Vlan, LAGG, Trunk, plain interface)
- Tiering and GW Groups
- LAN access to GUI possible or why reboot required
- system.log when switchover occurs
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #3 on: October 25, 2017, 01:04:34 pm »
Quote from: mimugmail on October 25, 2017, 12:52:20 pm
Please provide:

- Number of WAN uplinks
- Type of WAN uplinks (pppoe, static, dhcp)
- Gateway monitoring active on WAN?
- Gateway switching enabled/disabled
- Sticky connections enabled/disabled
- LAN setup (Vlan, LAGG, Trunk, plain interface)
- Tiering and GW Groups
- LAN access to GUI possible or why reboot required
- system.log when switchover occurs

Dear mimugmail.
please kindely see the below for your answers.

- Number of WAN uplinks.   2 UP WAN
- Type of WAN uplinks (pppoe, static, dhcp) STATICS
- Gateway monitoring active on WAN?  yes on both WANS I have, if you mean with active I have entire 8.8.8.8 on the monitor ip
- Gateway switching enabled/disabled , where can find this option ?
- Sticky connections enabled/disabled, yes sticky connection is enabled under firewall, settings ,advanced
- LAN setup (Vlan, LAGG, Trunk, plain interface). yes we have LAN and VLAN 10.12.13.14 are on a production.
- Tiering and GW Groups. yes I have a group WAN , trigger level " Member Down "
- LAN access to GUI possible or why reboot required, I can access the LAN and everything and even I can ping 8.8.8.8 and not www.google.com however the dns rule is already applied on the LAN side. I don't know why reboot is required too, is the only options to get the internet back
- system.log when switchover occurs, on the log it doesn't shows anything about the gateways or swathing, the only think I can see is the log in successfully to the admin which is the last time I logged in using the web interface

a big thank you for your support
« Last Edit: October 25, 2017, 08:06:26 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #4 on: October 25, 2017, 06:40:44 pm »
 In system, settings, general:
Prefer IPv4 over IPv6=checked
Gateway switching =unchecked


I hope someone can help with this issue, I never got Multi WAN working.
« Last Edit: October 25, 2017, 07:55:17 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6302
  • Karma: 434
    • View Profile
Re: Multi WAN
« Reply #5 on: October 26, 2017, 09:47:50 am »
Firewall - Settings - Advanced

There's gw switching (please enable) and Sticky connections (please enable).

Have you gw monitoring for both gateways 8.8.8.8 or each gateway a different IP?

Do you use as DNS server the IPs you monitor?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #6 on: October 26, 2017, 04:13:23 pm »
Quote from: mimugmail on October 26, 2017, 09:47:50 am
Firewall - Settings - Advanced

There's gw switching (please enable) and Sticky connections (please enable).

Have you gw monitoring for both gateways 8.8.8.8 or each gateway a different IP?

Do you use as DNS server the IPs you monitor?
Thank you for your answer,
both WAN has different Monitoring IP. one uses 8.8.8.8 and other 8.8.4.4
yes both IP has own DNS server, or you do mean something else ?
see below screenshots how they are not.
thank you for your continue support.

« Last Edit: October 26, 2017, 04:18:42 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

mimugmail

  • Hero Member
  • *****
  • Posts: 6302
  • Karma: 434
    • View Profile
Re: Multi WAN
« Reply #7 on: October 26, 2017, 05:05:21 pm »
Ok, and with this setup when one interface/WAN goes down you can ping external IP addresses but no dns resolution. Only way to fix this is reboot, correct?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #8 on: October 26, 2017, 08:07:37 pm »
Quote from: mimugmail on October 26, 2017, 05:05:21 pm
Ok, and with this setup when one interface/WAN goes down you can ping external IP addresses but no dns resolution. Only way to fix this is reboot, correct?
correct Sir,
its the only reason to get internet back online.
when we use on the any to any rules the gateway group, the internet does not works.
it works only when we use any to any with default gateway on the LAN rule to get the internet working.

Can you please explain why ?

« Last Edit: October 27, 2017, 09:01:31 am by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #9 on: October 27, 2017, 09:23:57 am »
i noticed when we use on the LAN the WANgroup as default gateway the internet does not works in the VLANS
it does works only when we have to use the any to any with default gateway. see screenshots.
thank you so much
« Last Edit: October 27, 2017, 09:33:28 am by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

NilsS

  • Full Member
  • ***
  • Posts: 174
  • Karma: 18
    • View Profile
Re: Multi WAN
« Reply #10 on: October 27, 2017, 09:48:11 am »
why dont you use your DNS Servers as Monitoring IPs, are they also still pingable beside the 8.8.x.x

I see you use the local DNS Resolver/Forwarder ... any more infos on that? unbound?
is Systen -> Settings -> General:  Do not use the DNS Forwarder/Resolver as a DNS server for the firewall  set?

Is the name resolution not working on the LAN/VLANs or also not working on OPNsense itself?

Does reseting states (Firewall -> Diagnostics -> States Reset) work? instead of reboot
Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Multi WAN
« Reply #11 on: October 27, 2017, 10:07:00 am »
Quote from: NilsS on October 27, 2017, 09:48:11 am
why dont you use your DNS Servers as Monitoring IPs, are they also still pingable beside the 8.8.x.x

I see you use the local DNS Resolver/Forwarder ... any more infos on that? unbound?
is Systen -> Settings -> General:  Do not use the DNS Forwarder/Resolver as a DNS server for the firewall  set?

Is the name resolution not working on the LAN/VLANs or also not working on OPNsense itself?

Does reseting states (Firewall -> Diagnostics -> States Reset) work? instead of reboot
Dear Niels,
Do you mean use our ISP DNS servers instead of using google DNS?
Systen -> Settings -> General:  Do not use the DNS Forwarder/Resolver as a DNS server for the firewall is not selected ( seee screenshot), do i have to enable this options ?
on the Pfsense i can resolve google.com i can ping google.com but the computers not.

internaly we have a active directory which is using the firewall ip of the vlans and lan 10.10.10.1/10.10.20.1/10.10.30.1/192.168.1.1 as forwared

thank you
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Multi WAN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2