Problem with policy routing

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

Problem with policy routing

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Problem with policy routing
Problem with policy routing
2024-04-25 13:07:01 - last edited 2024-05-06 09:52:44
Model: OC200  
Hardware Version: V2
Firmware Version: 2.15.2 Build 20240410 Rel.31260

Hello everyone, I have a problem with my policy routing. I have 3 ISPs (WAN, WAN/LAN1, WAN/LAN2).


I created a VLAN (123), created a wireless network with this VLAN and routed it through WAN/LAN1.

At the moment, my WAN/LAN1 is offline, it should be, and I expect that there should be no Internet on my wireless network (VLAN123), because it is redirected through the WAN/LAN1 port, but the Internet works through WAN, or through WAN/LAN2, if WAN does not work.

Use the other WAN port, this checkbox is not selected.

The same problem with VLAN124 and the WAN/LAN2 port.

 

Load balancing has this setting

  0      
  0      
#1
Options
1 Accepted Solution
Re:Problem with policy routing-Solution
2024-04-30 07:25:47 - last edited 2024-05-06 09:52:44

Hi  @Hank21 

today I did some more tests, and noticed that when WAN/LAN1 is offline, but has an IP address other than 0.0.0.0, then all the policy routing rules work as expected.

Recommended Solution
  0  
  0  
#13
Options
12 Reply
Re:Problem with policy routing
2024-04-26 06:53:51

denis-odessit wrote

Hello everyone, I have a problem with my policy routing. I have 3 ISPs (WAN, WAN/LAN1, WAN/LAN2).


I created a VLAN (123), created a wireless network with this VLAN and routed it through WAN/LAN1.

At the moment, my WAN/LAN1 is offline, it should be, and I expect that there should be no Internet on my wireless network (VLAN123), because it is redirected through the WAN/LAN1 port, but the Internet works through WAN, or through WAN/LAN2, if WAN does not work.

Use the other WAN port, this checkbox is not selected.

The same problem with VLAN124 and the WAN/LAN2 port.

 

Load balancing has this setting

 

Hi @denis-odessit 

Have you also configured the Link Backup on Load Balancing? Try to disable the link backup and try again.
 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:Problem with policy routing
2024-04-26 07:58:36 - last edited 2024-04-26 08:00:18

  Hi @Hank21 ,

for some reason the last screenshot is not loading, I have these settings

  0  
  0  
#3
Options
Re:Problem with policy routing
2024-04-26 08:34:57

 

denis-odessit wrote

  Hi @Hank21 ,

for some reason the last screenshot is not loading, I have these settings

Hi @denis-odessit 

I just made the test with the configuration you provided and it works fine. That is, my VLAN 123 will lose Internet connection when the WAN/LAN1 offline, when the other VLAN is still having Internet connection via WAN and WAN/LAN2.

 

May I know the model and the firmware of your gateway? Please try to upgrade to the latest firmware and try again.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#4
Options
Re:Problem with policy routing
2024-04-26 08:43:11 - last edited 2024-04-26 08:46:07

  @Hank21,

I have devices ER605 v2.0 (2.2.4 Build 20240119 Rel.44368), OC200 v2.0 (2.15.2 Build 20240410 Rel.31260) ,  TL-SG2428P v4.0 (4.0.8 Build 20240115 Rel.72847), 6xEAP225(EU) v4.0 (5.1.6 Build 20240313 Rel. 43415), 2xEAP245(EU) v4.0 (1.2.1 Build 20230824 Rel. 61490), EAP225-Outdoor(EU) v3.0 (5.1.6 Build 20240313 Rel. 43415), everything is updated to the latest versions

 

this is the complete routing policy table

  0  
  0  
#5
Options
Re:Problem with policy routing
2024-04-26 09:37:44

Hi @denis-odessit 

Could you share the IP address you got when you connected to the test SSID? Was it 192.168.101.x? Please help to share how you made the test. And if you tracert 8.8.8.8, will it be different when the WAN/LAN1 is online or offline?

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#6
Options
Re:Problem with policy routing
2024-04-26 10:03:36

  @Hank21 ,

if WAN/LAN 1 is online everything works as expected, when I connect to the test wifi I get the address 192.168.101.11, if you do a trace route when wan/lan1 is offline, the traffic goes through WAN, I see the WAN gateway ip on the second hop, if WAN and WAN/LAN1 are not working (offline), on the second hop I see the WAN/LAN2 gateway ip, but if all 3 ISPs are online, on the second hop I see the WAN/LAN1 gateway ip as expected.

 

My WAN/LAN1 is a Starlink, and on shore it doesn't work, it only starts working a few miles from shore, and when I'm on shore the Starlink doesn't receive CGNAT, and the WAN/LAN1 gateway has ip 0.0.0.0, there may be a problem in this?

  0  
  0  
#7
Options
Re:Problem with policy routing
2024-04-26 10:27:58

Hi  @Hank21 ,

Looks like the problem is in Starlink, I'm currently at sea and my WAN (5G modem) is offline, I route traffic through the WAN and the internet is not working as expected. But in the same situation, when I’m on the shore and everything is the other way around, WAN is online and WAN/LAN1 is offline, it doesn’t work that way. But how to solve this now?

 

Sorry for my English, it's not my native language

  0  
  0  
#8
Options
Re:Problem with policy routing
2024-04-26 14:51:45

  @denis-odessit 

 

The Starlink situation is weird.  In my SL days, 192.168.100.100 was the address of the dish itself, this really shouldn't be what's assigned to the WAN port of the Omada router.  

 

I assume you're using V2 (square dish) and bypassing the supplied router from Starlink?

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#9
Options
Re:Problem with policy routing
2024-04-26 16:29:31

 Hi @d0ugmac1,

I use Flat High Performance (maritime), when I'm in the port, I'm outside service address, and starlink gives me the address 192.168.100.100, and dishy has the address 192.168.100.1. I don't use a Starlink router at all

  0  
  0  
#10
Options
Re:Problem with policy routing
2024-04-29 06:54:51

Hi @denis-odessit 

We tried to re-duplicate your real scenario and we found that the policy routing was working properly. Could you please help to double confirm whether there is any policy routing rule contains your test device that will allow it access the Internet via WAN or WAN1LAN2? According to your routing policy table, there are at least 2 rules contain the IP group as the source. You can provide the screenshots about the ipconfig result on your test device, and provide the screenshots of the IP group.

 

Besides, may I know how did you make the test? Did you only use the PING/tracert command to test? Could you try to access some websites and see when WAN/LAN1 offline, will you still able to access the Internet like searching something online? You can take the screenshots of the result as well.

 

Thanks for cooperation.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#11
Options