|
GruensFroeschli
|
 |
« Reply #3 on: November 08, 2006, 05:59:15 pm » |
|
ok i did some testing today with a few old computers i've set PfSense up on. Right now i'm able to get to the internet with loadbalancing from every "private" lan.
i'v set up firewall rules:
pub. == "not private address-range" pri. == "private address-range" 1to2 == link-interface-name for connection between pfSense1 and Pfsense2
LAN-Interface destination: pub. --> gatewaypool WAN & 1to2 destination: pri. --> gatewaypool 1to2
-------------------------------------
If i find the time i'll setup a test-system in the network-labor at school which will look about like that:
6 / | \ / | \ 5----1-----2 \ / \ / \ / \ / 4------3
If i'm not mistaken i will have to make a lot of different pools. i'll post them here to have them written down when i'll do them ^^"
PfSense1: from LAN dest. = pub. --> pool WAN, 2, 3, 4, 5, 6 dest. = priv. --> pool 2, 3, 4, 5, 6
from 1to2 source = 2, dest. = pub. --> pool WAN, 3, 4, 5, 6 source = 3, dest. = pub. --> pool WAN, 4, 5, 6 source = 4, dest. = pub. --> pool WAN, 3, 5, 6 source = 5, dest. = pub. --> pool WAN, 3, 4, 6 source = 6, dest. = pub. --> pool WAN, 3, 4, 5
source = 2, dest. = priv. --> pool 3, 4, 5, 6 source = 3, dest. = priv. --> pool 4, 5, 6 source = 4, dest. = priv. --> pool 3, 5, 6 source = 5, dest. = priv. --> pool 3, 4, 6 source = 6, dest. = priv. --> pool 3, 4, 5
and so on for every interface on every PfSense.
this would be a lot of work whenever a new PfSense gets added to the system and i think it's still not quite good with how the traffic can take long ways. -----------------------------------------------------
edit: moving questions regarding OLSR/RIP
|