Professional Documents
Culture Documents
NETWORK DIAGRAM
1/ Configure two open DNS servers (Google DNS : 8.8.8.8 and L3 DNS : 4.2.2.2), with no gateway.
2/ Force theses DNS in the Proxy Server config. (may not required, but it might helps)
3/ Create and new floating rule to correctly failover DNS solving (**most important thing**)
Testing
Unplug WAN1 or WAN2 routers and test it:
https://PFSENSE_IP/diag_dns.php
STEP-BY-STEP HOWTO
1) Configure correctly your WAN1 and WAN2 interfaces (static IP or DHCP) and Gateways.
WAN1 example:
WAN2 example:
Example:
Some explanations:
- Provider for WAN1 uses 2 DNS servers. I configure the correct gateway to reach theses DNS
- Provider for WAN2 uses the gateway as DNS server (!). In this case, I didnt configure the gateway to reach the DNS.
Set-up a Floating rule with the following parameter (for HTTP proxy)
Explanations:
- The floating rules apply on multiple interfaces,
- Choose your WAN1 and WAN2 interfaces, and direction out
- Choose HTTP as destination port
- Specify the gateway with MULTIWAN (the most important thing!)
Result:
Set-up a Floating rule with the following parameter (for DNS resolving)
In NAT tab, you have to check Manual Outbound NAT rule generation
I assume that you have installed Squid package. In my case, I also installed SquidGuard (filter) and LightSquid (reports).
I also use a transparent proxy. I you choose to activate this option, you must change the port for pfSense Web GUI (HTTPS instead
of HTTP) in Advanced tab.
Then, you have to add a Custom Options on the bottom of the page:
tcp_outgoing_address 127.0.0.1;
6) Test it!
- Open your favorite Web Browser (Firefox) and go to http://myip.dk.
- Unplug the Tier 1 router and reload the page.