{"id":39,"date":"2016-05-02T17:14:34","date_gmt":"2016-05-02T20:14:34","guid":{"rendered":"http:\/\/xaxowareti.com.br\/?p=39"},"modified":"2016-05-02T17:14:34","modified_gmt":"2016-05-02T20:14:34","slug":"failover-no-pfsense-2-0-0","status":"publish","type":"post","link":"https:\/\/xaxowareti.com.br\/?p=39","title":{"rendered":"Failover no PFSense 2.0.0"},"content":{"rendered":"<h3 class=\"post-title entry-title\"><a href=\"http:\/\/pauloxmachado.blogspot.com.br\/2012\/07\/failover-no-pfsense-200.html\">Failover no PFSense 2.0.0<\/a><\/h3>\n<div class=\"post-header-line-1\"><\/div>\n<div class=\"post-body entry-content\">\n<div><\/div>\n<p>Segue a seguir o procedimento e failover aplicado no PFSense 2.0.0. O cen\u00e1rio utilizado \u00e9 com 2 conex\u00f5es com a internet (WAN) e apenas 1 conex\u00e3o de rede local (LAN).<\/p>\n<p>Observa\u00e7\u00e3o.: O servidor possui 3 placas de rede, 2 conectadas a internet e 1 conectada a rede interna. Na instala\u00e7\u00e3o eu defini apenas 1 wan e 1 lan. A segunda placa wan ser\u00e1 configurada abaixo.<\/p>\n<p>Vamos iniciar ativando a segunda interface WAN. V\u00e1 em: Interfaces &gt; Assign<\/p>\n<div class=\"separator\"><a href=\"http:\/\/4.bp.blogspot.com\/-P4I-BjCbi1w\/T_SdYdMyHLI\/AAAAAAAAAlE\/maiwqHTGOKc\/s640\/01%2520-%2520Interface%2520assign.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/4.bp.blogspot.com\/-P4I-BjCbi1w\/T_SdYdMyHLI\/AAAAAAAAAlE\/maiwqHTGOKc\/s400\/01%2520-%2520Interface%2520assign.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Clique no Bot\u00e3o Add:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/4.bp.blogspot.com\/-yVT8lGK7NDk\/T_SdcvzJz7I\/AAAAAAAAAlk\/qFa5gR5ZFpo\/s640\/02%2520-%2520Adicionar%2520wan2.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/4.bp.blogspot.com\/-yVT8lGK7NDk\/T_SdcvzJz7I\/AAAAAAAAAlk\/qFa5gR5ZFpo\/s400\/02%2520-%2520Adicionar%2520wan2.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Imediatamente o PFSense vai adicionar a interface restante. Agora basta clicar em Save<\/p>\n<div class=\"separator\"><a href=\"http:\/\/1.bp.blogspot.com\/-JTFRbICgsJo\/T_SdYoiE6_I\/AAAAAAAAAlM\/mDLjwcRjcbs\/s640\/03%2520-%2520Salvar%2520wan2.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-JTFRbICgsJo\/T_SdYoiE6_I\/AAAAAAAAAlM\/mDLjwcRjcbs\/s400\/03%2520-%2520Salvar%2520wan2.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Agora vamos ativar e renomear a interface para evitar confus\u00e3o. V\u00e1 em Interfaces &gt; OPT1<\/p>\n<div class=\"separator\"><a href=\"http:\/\/1.bp.blogspot.com\/-_VHfowDjd3E\/T_SdZ4WpVcI\/AAAAAAAAAlU\/Y_-1AlnY364\/s640\/04%2520-%2520Renomear%2520wan2.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-_VHfowDjd3E\/T_SdZ4WpVcI\/AAAAAAAAAlU\/Y_-1AlnY364\/s400\/04%2520-%2520Renomear%2520wan2.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Clique em <b>Enable Interface<\/b>, Altere o campo <b>Description<\/b> para WAN2, defina o tipo de conex\u00e3o em <b>Type<\/b> para <b>DHCP<\/b> e clique em salvar.<\/p>\n<div class=\"separator\"><a href=\"http:\/\/4.bp.blogspot.com\/-S_IyCqq4Kbo\/T_SdbP-t5pI\/AAAAAAAAAlc\/TRgckUKRHEM\/s640\/05%2520-%2520Conf%2520Wan2.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/4.bp.blogspot.com\/-S_IyCqq4Kbo\/T_SdbP-t5pI\/AAAAAAAAAlc\/TRgckUKRHEM\/s400\/05%2520-%2520Conf%2520Wan2.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Agora precisamos definir os endere\u00e7os de servidores DNS, para isso vamos no menu <b>System<\/b>, op\u00e7\u00e3o <b>General Setup<\/b>:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/2.bp.blogspot.com\/-gO_ZC3tsvDo\/T_Sdc4dp_lI\/AAAAAAAAAls\/wDmmKD4BGrA\/s640\/06%2520-%2520System%2520-%2520General%2520setup.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/2.bp.blogspot.com\/-gO_ZC3tsvDo\/T_Sdc4dp_lI\/AAAAAAAAAls\/wDmmKD4BGrA\/s400\/06%2520-%2520System%2520-%2520General%2520setup.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Preencha os campos com o seus servidores DNS de cada provedor de acesso e defina a respectiva interface de conex\u00e3o, ou fa\u00e7a como eu e defina os servidores DNS do google para cada interface:<\/p>\n<p>8.8.8.8 &#8211; WAN<br \/>\n8.8.4.4 &#8211; WAN<br \/>\n8.8.8.8 &#8211; WAN2<br \/>\n8.8.4.4 &#8211; WAN2<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-23JJmfo6JKw\/T_SddrpReNI\/AAAAAAAAAl0\/rvgER4sPJz4\/s640\/07%2520-%2520Conf%2520DNS.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-23JJmfo6JKw\/T_SddrpReNI\/AAAAAAAAAl0\/rvgER4sPJz4\/s400\/07%2520-%2520Conf%2520DNS.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Agora vamos iniciar o processo de configura\u00e7\u00e3o do failover propriamente. Vamos definir um Grupo de gateways, para isso v\u00e1 em System &gt; Routing:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-nwSOyOpU3ys\/T_Sdeq4Pl6I\/AAAAAAAAAl8\/TyEWAxDWsQs\/s640\/08%2520-%2520System%2520-%2520routing.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-nwSOyOpU3ys\/T_Sdeq4Pl6I\/AAAAAAAAAl8\/TyEWAxDWsQs\/s400\/08%2520-%2520System%2520-%2520routing.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>confirme na aba <b>Gateways<\/b>\u00a0que os gateways das interfaces WAN e WAN2 est\u00e3o preenchidos.<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-Ixct6Zl4ndQ\/T_SdmCoWeeI\/AAAAAAAAAnc\/bEt3tIf1MxM\/s640\/Gateways.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-Ixct6Zl4ndQ\/T_SdmCoWeeI\/AAAAAAAAAnc\/bEt3tIf1MxM\/s400\/Gateways.PNG\" width=\"400\" height=\"290\" border=\"0\" \/><\/a><\/div>\n<p>Agora entre na aba Groups e clique no bot\u00e3o Add:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/1.bp.blogspot.com\/-ZNKwXRlV5-4\/T_SdezCpvdI\/AAAAAAAAAns\/IGODXvVJK1Y\/s640\/09%2520-%2520Gateway%2520groups.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-ZNKwXRlV5-4\/T_SdezCpvdI\/AAAAAAAAAns\/IGODXvVJK1Y\/s400\/09%2520-%2520Gateway%2520groups.jpg\" width=\"400\" height=\"231\" border=\"0\" \/><\/a><\/div>\n<p>Preencha os campos da seguinte forma:<\/p>\n<p>Group Name: Multilan<br \/>\nGateway priority:<br \/>\n* Tier1 &#8211; WAN<br \/>\n* Tier 2 &#8211; WAN2<br \/>\ntrigger Level: Packet Loss<\/p>\n<div class=\"separator\"><a href=\"http:\/\/1.bp.blogspot.com\/-XgKFFgRK8cE\/T_Sdflyj6hI\/AAAAAAAAAmM\/g8yk5geq_co\/s640\/10%2520-%2520Multiwan.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-XgKFFgRK8cE\/T_Sdflyj6hI\/AAAAAAAAAmM\/g8yk5geq_co\/s400\/10%2520-%2520Multiwan.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Depois disso basta clicar em Save.<\/p>\n<p>Depois desses passos vamos as configura\u00e7\u00f5es de Firewall. V\u00e1 em Firewall &gt; Rules:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-OE3uNhv_GNw\/T_SdgiEx-qI\/AAAAAAAAAmU\/xOvZzGCUUSw\/s640\/11%2520-%2520Firewall%2520-%2520Rules.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-OE3uNhv_GNw\/T_SdgiEx-qI\/AAAAAAAAAmU\/xOvZzGCUUSw\/s400\/11%2520-%2520Firewall%2520-%2520Rules.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Entre na aba <b>Floating<\/b>\u00a0e clique no bot\u00e3o Add new rule:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/2.bp.blogspot.com\/-Y_InnDDMHt0\/T_Sdg50TtKI\/AAAAAAAAAmc\/dwheeNZeCms\/s640\/12%2520-%2520Floating.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/2.bp.blogspot.com\/-Y_InnDDMHt0\/T_Sdg50TtKI\/AAAAAAAAAmc\/dwheeNZeCms\/s400\/12%2520-%2520Floating.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Preencha os campos da seguinte maneira:<\/p>\n<p>Action: Pass<br \/>\nInterface: Selecione WAN e WAN2<br \/>\nDirection: Out<br \/>\nProtocol: TCP<br \/>\nSource: Any<br \/>\nDestination: Any<br \/>\nDestination Port Range<br \/>\n* From: HTTP<br \/>\n* To: HTTP<\/p>\n<div class=\"separator\"><a href=\"http:\/\/2.bp.blogspot.com\/-rEbODPRvK54\/T_SdhYGNcgI\/AAAAAAAAAmk\/4hc57ORsd-s\/s640\/13%2520-%2520Regras%2520Floating%2520-%25201.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/2.bp.blogspot.com\/-rEbODPRvK54\/T_SdhYGNcgI\/AAAAAAAAAmk\/4hc57ORsd-s\/s400\/13%2520-%2520Regras%2520Floating%2520-%25201.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Des\u00e7a a barra de rolagem at\u00e9 <b>Advanced Features<\/b>, Clique no bot\u00e3o<b>Advanced<\/b> na op\u00e7\u00e3o <b>Gateway<\/b>\u00a0e selecione <b>Multilan<\/b>:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/1.bp.blogspot.com\/-Eq0HWh57TKA\/T_SdiCdbS0I\/AAAAAAAAAms\/aEmF9S1Q5eE\/s640\/13%2520-%2520Regras%2520Floating%2520-%25202.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-Eq0HWh57TKA\/T_SdiCdbS0I\/AAAAAAAAAms\/aEmF9S1Q5eE\/s400\/13%2520-%2520Regras%2520Floating%2520-%25202.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Salve e v\u00e1 para Firewall &gt; NAT:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/4.bp.blogspot.com\/-oGrnynUT-0Q\/T_SdjFvGiXI\/AAAAAAAAAm0\/Cn52Av9pjsU\/s640\/14%2520-%2520Nat.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/4.bp.blogspot.com\/-oGrnynUT-0Q\/T_SdjFvGiXI\/AAAAAAAAAm0\/Cn52Av9pjsU\/s400\/14%2520-%2520Nat.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>V\u00e1 para a guia <b>Outbound<\/b>\u00a0e marque a op\u00e7\u00e3o <b>Manual Outbound NAT rule generation<\/b>\u00a0e salve. As regras abaixo ir\u00e3o aparecer na sua tela:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/2.bp.blogspot.com\/-vSjgNIT8aiE\/T_SdjgpHICI\/AAAAAAAAAm8\/gMOTj13hHt4\/s640\/15%2520-%2520Nat%2520Manual.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/2.bp.blogspot.com\/-vSjgNIT8aiE\/T_SdjgpHICI\/AAAAAAAAAm8\/gMOTj13hHt4\/s400\/15%2520-%2520Nat%2520Manual.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Vamos adicionar duas regras. Clique no bot\u00e3o Add e preencha os seguintes campos:<\/p>\n<p>Interface: WAN<br \/>\nProtocol: Any<br \/>\nSource: Any<br \/>\nDestination: Any<br \/>\nTranslation: Interface address<\/p>\n<p>e clique em salvar.<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-tfcDVhR-bcM\/T_SdkopiDgI\/AAAAAAAAAnE\/J04qjmaSLFI\/s640\/16%2520-%2520Conf%2520Nat%2520Manual%2520WAN.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-tfcDVhR-bcM\/T_SdkopiDgI\/AAAAAAAAAnE\/J04qjmaSLFI\/s400\/16%2520-%2520Conf%2520Nat%2520Manual%2520WAN.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Repita o procedimento criando nova regra s\u00f3 alterando a interface WAN por WAN2:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/2.bp.blogspot.com\/-5iut9mA3AyU\/T_SdlC6beSI\/AAAAAAAAAnM\/qw6qvYFt1h0\/s640\/17%2520-%2520Conf%2520Nat%2520Manual%2520WAN2.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/2.bp.blogspot.com\/-5iut9mA3AyU\/T_SdlC6beSI\/AAAAAAAAAnM\/qw6qvYFt1h0\/s400\/17%2520-%2520Conf%2520Nat%2520Manual%2520WAN2.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>O resultado ser\u00e1 a tela abaixo:<\/p>\n<div class=\"separator\"><a href=\"http:\/\/3.bp.blogspot.com\/-z9ZNrpdLEEU\/T_SdlRVQ5xI\/AAAAAAAAAnU\/53Qbqd2t3OI\/s640\/18%2520-%2520Tela%2520final.PNG\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/3.bp.blogspot.com\/-z9ZNrpdLEEU\/T_SdlRVQ5xI\/AAAAAAAAAnU\/53Qbqd2t3OI\/s400\/18%2520-%2520Tela%2520final.PNG\" width=\"400\" height=\"300\" border=\"0\" \/><\/a><\/div>\n<p>Pronto, o failover j\u00e1 estar\u00e1 funcionando. Agora s\u00f3 nos resta testar e confirmar que ele est\u00e1 realmente OK.<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Failover no PFSense 2.0.0 Segue a seguir o procedimento e failover aplicado no PFSense 2.0.0. O cen\u00e1rio utilizado \u00e9 com 2 conex\u00f5es com a internet (WAN) e apenas 1 conex\u00e3o de rede local (LAN). Observa\u00e7\u00e3o.: O servidor possui 3 placas de rede, 2 conectadas a internet e 1 conectada a rede interna. Na instala\u00e7\u00e3o eu [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-39","post","type-post","status-publish","format-standard","hentry","category-pfsense"],"_links":{"self":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/39","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39"}],"version-history":[{"count":1,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/39\/revisions"}],"predecessor-version":[{"id":40,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/39\/revisions\/40"}],"wp:attachment":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}