Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Specialty Builds > Servers

Reply
 
LinkBack Thread Tools
Old 09-06-09   #1 (permalink)
4.0ghz
 
superk's Avatar
 
intel nvidia

Join Date: Apr 2008
Posts: 3,582
Blog Entries: 5

Rep: 312 superk is a proven membersuperk is a proven membersuperk is a proven membersuperk is a proven member
Unique Rep: 233
Hardware Reviews: 2
Trader Rating: 44
Default pfSense firewall question.

I have a question regarding a firewall setup on pfSense.

I have a round robin type config in my firewall so far. This allows for me to have dual WAN connections, and thus, dual IP addresses.

Everything is running great so far. I noticed the failover connection works and overall my net speed is rougly 20 percent faster.

My problem now is that I have a specific website that uses session based AND ip based logins to its forum. Which means if I am browsing the site and my ip changes, its instant logout for me, regardless of session.

The only solution I can think of is to route all HTTP traffic over one WAN line, however that would completely defeat the purpose of my round robin for most intents and purposes.

So my question is how can I get a specific website on a specific WAN

here is how I *think* I should set it up as:
Quote:
Pass
Interface Lan
TCP (since its over port 80)
Source LAN Net
Destination Single Host or Alias (www.website.com)
Destination Port range 80:80
Gateway : default
State: Keep State
and I would place this rule ABOVE loadbalance in the firewall rules.


I have NO DMZ. I have one LAN net with wireless bridged to it. I have 2 WANs. Using 1.2.3-RC1.

Am I on the right track with this? I dont want to try it in case I bork my load balancing or somethign...
__________________
.: My Case Mods :.

Hades (Antec 900) * Antec 1200


.: My Case Rebirths :.

Agamemnon * Heracles


.: My Lego Cases :.

Lego PC v1 * Lego PC v3 * Lego Xbox

System: Apollo
CPU
Core i7 920 D0
Motherboard
Asus P6T
Memory
3x2GB OCZ Gold DDR3-1600
Graphics Card
Sapphire 4870X2
Hard Drive
2 x 500gb RAID 0, 2 x 1TB Caviar Black
Sound Card
Onboard
Power Supply
Cooler Master 850w 6 Rail
Case
Antec Twelve Hundred
CPU cooling
T.R.U.E. (lapped)
GPU cooling
BFG Stock + eVGA Backplate
OS
Vista x64
Monitor
Acer x223w
1 Million+ Folding at Home points
superk is offline Overclocked Account   Reply With Quote
Old 09-06-09   #2 (permalink)
4.0ghz
 
superk's Avatar
 
intel nvidia

Join Date: Apr 2008
Posts: 3,582
Blog Entries: 5

Rep: 312 superk is a proven membersuperk is a proven membersuperk is a proven membersuperk is a proven member
Unique Rep: 233
Hardware Reviews: 2
Trader Rating: 44
Default

ok so I figured it out.

the firewall configuration above is accurate, HOWEVER one small change. Instead of www.whatever.com I needed to create an alias for www.whatever.com, which is good because it offers me the opportunity to add not only one site, but the sites entire dns pool.

I executed

# host www.whatismyip.com

received three IP addresses. I shoved em all into a firewall alias, shoved the alias into a firewall rule, and VOILA! Problem solved
__________________
.: My Case Mods :.

Hades (Antec 900) * Antec 1200


.: My Case Rebirths :.

Agamemnon * Heracles


.: My Lego Cases :.

Lego PC v1 * Lego PC v3 * Lego Xbox

System: Apollo
CPU
Core i7 920 D0
Motherboard
Asus P6T
Memory
3x2GB OCZ Gold DDR3-1600
Graphics Card
Sapphire 4870X2
Hard Drive
2 x 500gb RAID 0, 2 x 1TB Caviar Black
Sound Card
Onboard
Power Supply
Cooler Master 850w 6 Rail
Case
Antec Twelve Hundred
CPU cooling
T.R.U.E. (lapped)
GPU cooling
BFG Stock + eVGA Backplate
OS
Vista x64
Monitor
Acer x223w
1 Million+ Folding at Home points
superk is offline Overclocked Account   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 10:35 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.09590 seconds with 8 queries