OPNSense Firewall Multi-WAN Failover and Load Balancing - Virtual Lab Building Series: Ep 6

preview_player
Показать описание
Hey all and welcome to my channel! In episode 6 of our cyber security virtual lab building series, we continue with our OPNSense firewall configuration and configure the Multi-WAN failover and Load Balancing features, to create redundant paths to the internet. We will cover the VirtualBox network adapter configurations, setup gateway monitor and groups as well as modify some firewall and DNS rules to make this work.

By the end of this video, you will have a solid understanding of OPNSense Multi-WAN failover setups with some practical hands on experience completing this setup within VirtualBox. With slight adaptions these steps can be used in real-world production environments.

If you have been enjoying this series so far, please don't forget to like and subscribe!

Links used in video:

NOTE: I am not sponsored by or affiliated to any of the products or services mentioned in this video, all opinions are my own based on personal experiences.

DISCLAIMER: All information, techniques and tools showcased in these videos are for educational and ethical penetration testing purposes ONLY. NEVER attempt to use this information to gain unauthorized access to systems without the EXCPLICIT consent of its owners. This is a punishable offence by law in most countries.

#multiwan #firewall #failover #cybersecurity
Рекомендации по теме
Комментарии
Автор

Your channel is incredible. Please keep up the good work.

MirajMusicUSA
Автор

Nice step by step. Thanks for providing that. 😊

ViniciusSoaresBatista
Автор

Good video, Keep going !! Thumbs up !

JasonsLabVideos
Автор

Thanks got it working first try thanks to you, subscribed.

crazybebop
Автор

Excellent video. Thank you for for this.

Quietstorm
Автор

This video is great! Thanks so much.
Im trying to do this on a pc running Opnsense natively. The setup is 6 ethernet ports. 1 WAN, and 5 configured as a bridged/switch. My issue is that I can't figure out how to assign the "switch" interface to use the WAN_Failover "group" as default gateway. Primary WAN is a Cable Modem, failover is a 5G Mobile Phone. I don't need load balance, just automatic failover (and back again when service is restored).
Thanks for the awesome content.

unapologetic
Автор

Pretty nice! Can you pls show us, how to use an iPhone for tethering as additional WAN interface for failover and load balancing?

Voigt_Analytics
Автор

Hi, very nice guide ! New to OPNSense, so it's all a bit new to me. I was wondering how the part with the gateways would be done when both WAN interfaces both have an IPV4 and and IPV6 interface ? Do you make 2 groups in that case, one for IPV4 and one for IPV6 ?

WimvanEupen
Автор

Great video thank you! Do you happen to know how to get multi WAN working with Unbound DNS?

danaug
Автор

Nice, just what i needed! Would be great if you could add chapter/bookmarks as well, is that possible to do after upload?

JoerBrando
Автор

very intuitive demonstration ! I've got it working right away.
Yet still, I'm trying to set up some rules to specify traffic for, let's say chat app (knowing the dest server IP address or port number) through ISP1, while other traffic like video streaming through ISP2, when two WANs are both online.
I'd love to know if it is feasible with OPNsense, many thanks !

nqnrjdk
Автор

Great walkthrough thanks very helpful. I found however the internet would hang from time to time and had to turn off "Shared forwarding" located in Firewall-Settings-Advanced now load balancing works as expected although I can't access the firewall interface once I apply the new gateway to the vLAN, using Unbound as my DNS. would you have any suggestions as to how I could rectify this?

RonFinegan
Автор

Great video (although I did have to play it 1.25x fast for my taste). I've done all this as well but I notice when I change the GATEWAY in my default LAN rule, there seems to be a loss of connection to the net. I have DSL and Cable to the house (prioritized based on bandwidth)

Interestingly, if I fix it to my DSL or Cable gateway, or even to default, it works just fine as a failover. I have sticky connections on for VPN/security items but that shouldn't be a deal breaker. Weird.

TheRealXyzven
Автор

Hi. I was wondering if port forwarding needs to be set up differently with a failover setup running on OPNsense. Thanks

jeytis
Автор

Awesome video! Since I have two VLANs (tags 10 & 20). Do you need to change the default gateway for both vlans/subnets to the GW gateway, and adding corresponding DNS rule under firewall? Thanks.

TangDynasty
Автор

Sorry... all the interface is DHCP...
I don't understand where you put the static IP to the 2 X WAN connections...
Thanks a lot for the video

MrDenisJoshua
Автор

the one thing i wish i could see is any real world perf tests with wan balancing. I appreciate the video and does make sense, but i am at the point where I'm trying to determine if it's worth pulling my 4 wan links right into opn vs leaving it on my er605 wan balancing router. I know both solutions would have some overhead but not sure how good opn would do?

jumpieva
Автор

You are the man. one question. still a noob here. I unplugged one of the wan interfaces physically from the cable (NOTE! I did the exact experiment in a physical environment and now the WAN link is not getting back up) what should I do?

N_scape__Scamrs
Автор

Regarding the previous video "Ep.5", in "Ep.6" you are using an "Opnsense Firewall Failover Lab", from which did you clone it? From the master, slave of the video "Ep.5"?

jdjggxb
Автор

Hi, great video! question: how do You deal with voip connection in failover ? seems that there is a known issue when failover occurs: voip registration keeps using old connection; I have read in a github discussion that they were thinking about a firewall state flush but don't know if it has been ever developed. I have tried it on field and still have the same issue with actual version of opnsense; do You have any information about this that You can share? thanks in advance

matteovinti