Have mostly used the blue to be able to turn off the backup firewall if the UPS is running out of battery.
But I have never been able to get blue to connect to Internet or green. At this point I am trying to open everything, but no. I have followed these:
And today I tried again some creative rules, but it don’t want to work. Clearly I am missing some knowledge. Right now I have these settings:
System - Home
If you don’t use any proxy, your blue access is set up right and your firewall policy is set to allowed, you don’t need anything else to get blue members internet access.
You can delete all your firewall rules. They are double/triple and not necessary. Also you don’t need any routing entries.
Your blue acces is set to allow any connected client, so this will work.
Edit: You may keep the firewall rule blue to green but that’s all.
Deleted all firewall rules except blue to green and deleted routing, Applied changes. No change.
Rebooted. No change.
The silly part.
3. Went to Firewall - Firewall Options, changed FORWARD and OUTGOING to “Blocked” and saved.
4. Changed FORWARD/OUTGOING back to “Allowed”. And now it works.
After not working for one year, that was the solution. Turn FORWARD/OUTGOING off and then on. Well, at least it works now.
I have two firewalls, their main IP numbers are:
Ipfire1 (primary): 192.168.222.251
Ipfire2 (secondary): 192.168.222.252
Then I have the addon keepalived to set them both up as a virtual cluster, using the VRRP protocol for failing-over the IP address 192.168.222.254 from one machine to another. All clients use only 192.168.222.254.
So right now Ipfire1 (primary) is both 192.168.222.251 and 192.168.222.254. If Ipfire1 goes down, Ipfire2 (secondary) will become 192.168.222.252 and 192.168.222.254.