Solved

pfsense load balance

Posted on 2009-07-03
9
1,476 Views
Last Modified: 2012-05-07
Hi - I have a bsaic question regarding pfsense and load balancing dual wans.
We are getting a leased line, and we already have an ADSL connection. I know that the pfsense unit can do some sort of laod balancing. I would be happy if it could be configured to load balance Incoming traffic  across all hosts connected to the LAN. Ie, speraed the bandwidth.

Can someone tell me if this is possible, and how I can do it?

Many thanks in advance
Argint
0
Comment
Question by:argint
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
9 Comments
 
LVL 14

Expert Comment

by:Roachy1979
ID: 24772649
Are you wanting to load balance outbound http traffic or inbound?

For outbound traffic you might want to have a look at this guide

http://doc.pfsense.org/index.php/Multi_WAN_/_Load_Balancing

Inbound load balancing is covered in this document:

http://doc.pfsense.org/index.php/Inbound_Load_Balancing

Does this help or do you need more information?



0
 

Author Comment

by:argint
ID: 24857509
Hi there, Just back and saw the reply. Well, I had read those documents, but being new to pfsense, i couldnt quite work out if one could only load balance to indidual servers. What I was hoping for is to be able to connect bother our internet connections and have incoming bandwidth shared across all lan users for download.

We are less concerned about upload.

Anyone ever achieved this?

Regards
ARgint
0
 
LVL 5

Expert Comment

by:piwowarc
ID: 32682682
Pfsense lets using two WANs more as a redundancy than speed up. If you get 2 x 2 M you won't have a 4 M connection.

But pfsense has a realy nice traffic shaper. You can use it to distribute bandwidth between users equally (and kill p2p maniacs if you have them like I do).

http://doc.pfsense.org/index.php/Traffic_Shaping_Guide

Unfortunately to shape more than one WAN you need pfsense 2.0 which is still in Beta (not for long now, it should come as final this year).

I'm using pfsense exlusevily on 3 locations, 2 of them have crappy adsl bandwidth and pfsense really does the job (before deploying pfsense I did not know how much upload is used for ACKs when downloading).

You could try the Beta (if your environment istn't crucial) or wait for final version. Nonetheless stick with pfsene as it is a great product, free and heavily developed (with stable Unix engine inside, my boxes have like 150 days of uptime just because I reboot them twice a year, no need to do anything more).

Cheers
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 14

Expert Comment

by:Roachy1979
ID: 32684801
I concur :)

I had a pfSense running for over a year, the only reboot being due to an 8 hour power outage that was totally unplanned and we didn't have a generator backup at the site!  A really solid platform, which is pretty feature-rich.  Captive Portal and CARP make it a serious contender...
0
 

Author Comment

by:argint
ID: 32697252
Yes, pfsense has been rock solid for us, never falling over, Ive reset it just to test if it comes back up ok and it works a charm. Ive nothing but respect for this project. What I would like to do is buy 2 more and set up siste to site comms with our smaller offices. Presenlt I use log me in, take over a machine and look at the firewall, i could do this all with 3 pfsense boxes.

Failover would suffice to be honest, i should look in to this but sharing the bandwith of our cheaper secondary adsl connection would be even better.

Do i basically read this cannot be done? I do understand that we dont just add up the bandwidth and get faster, but we have a fatter pipe at the same speed to accomodate more load.

Is this correct?

I would like basic instructions on doing it if anyone already has.
Regards
Argint
0
 
LVL 5

Accepted Solution

by:
piwowarc earned 125 total points
ID: 32701403
Yes, you are correct. You can provide more connections on same bandwidth without dropping queues.

Here is a tutorial about Multi Wan Load Balancing (it's for pfsense 1.2.x)

http://doc.pfsense.org/index.php/Multi_WAN_/_Load_Balancing

Here is a tutorial about traffic shaping (which I higly recommend)

http://doc.pfsense.org/index.php/Traffic_Shaping_Guide

There are also few nic tips here

http://forum.pfsense.org/index.php/topic,11986.0.html

If you have Squid it can look strange (it takes up to 10 minutes to load Status-Queues) to show working traffic shaper. But it still works (at least I think it does). Someone posted a tutorial howto do it properly

http://forum.pfsense.org/index.php/topic,14436.0.html

Unfortunately you have to get 2.0 to do this on Multi Wan like I wrote before.

Since you plan to do failover anyway, try the Beta. They've been working on it for fairly long time and I think you may find it decent enough. Or just install tested 1.2.3 and do multi wan without traffic shapping and see the performance. If it's enough for you there's no need to reinvent the wheel.

Cheers
0
 

Author Comment

by:argint
ID: 32701756
thankyou for your feed back. the common thread i sense is our agreement that  pfsense is a fantastic product.
regards
argint
0
 
LVL 5

Expert Comment

by:piwowarc
ID: 32701832
By all means :)
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
URL to download Engenius BH-ENS202 firmware update 4 41
SIP / Streaming - real time communications testing 8 130
BGP prefix and routing 3 88
Router question 6 258
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question