One of the main interests of pfSsense is the possibility of load balancing with multiple ADSL lines. However, it raises some problems with certain sites whose sessions are linked to the client IP. Indeed, suppose that when one logs in to a site with login / password the connection is being made on a first line but the display of the next page goes through a second: the site will see two IP addresses different and will consider that this is not the same session and the user will again be called to enter his login. You can create a rule in the firewall to force the traffic to the site IP on a given line, which solves the problem.
Another example is the case of YouTube, which often display a message "Sorry, this video is no longer available". The video is actually there but the case load balancing sessions ... The difficulty here is that YouTube has a large number of different IP addresses and it is difficult to create as many rules manually.
To remedy this, simply create an alias that will integrate YouTube into pfSense ranges of IP addresses used by YouTube. It will then create a rule in the firewall to redirect traffic to a single row.
Continue reading "pfSense, load-balancing and YouTube"










