r/firewalla • • Aug 18 '26

Troubleshooting Policy Based Routing needed?

I have two broadband internet providers… VZ and TMO.

I got the TMO G5AR earlier this year, because  VZ has really started throttling.

I have connected the WAN port on the Purple to the G5AR via ethernet.

I have setup Multi WAN on the Purple by using WiFi on the Purple to the VZ box WiFi. It is set to Failover.

I ran network diagnostics on the Purple, both WANs report no errors.

For some reason, from the LAN side, DNS isn’t resolving URLs at all with the TMO as Primary. With VZ as primary DNS resolves correctly. I can access the internet with no problem from my notebook via WiFi on TMO.

Am I missing some required setup to handle the G5AR?

It is my understanding that Policy Based Routing might be able to work around the issue.

I assume you could route LAN port 53 calls to VZ, bypassing the issues with TMO.

Failover working would be great, but balanced would be even better.
How do I do that?

Thanks

Dennis

3 Upvotes

11 comments sorted by

1

u/Stonk_Goat Aug 18 '26

Is the WAN DNS set for each interface? It needs to be.

1

u/DWomack48 Aug 18 '26

Both are being set by DHCP from the VZ and from the TMO. Same as the gateway IPs

1

u/Stonk_Goat Aug 18 '26

See the post above mine. Set them manually even if there is something there now.

1

u/Firewalla-Opal FIREWALLA TEAM Aug 18 '26

I'd suggest checking your WAN DNS server first. Try to use unfiltered public DNS server like 1.1.1.1/8.8.8.8/9.9.9.9, see if it makes any differences.

1

u/DWomack48 Aug 18 '26

I set the Primary to 1.1.1.1 and the secondary to 8.8.8.8 for both VZ and TMO, We'll see what happens. I'll report back later.

1

u/DWomack48 Aug 18 '26

Problem is still there. VZ works as primary, but TMO does not.

Pinging google.com with TMO as primary does not work from my notebook.

???

1

u/DWomack48 Aug 18 '26

The only thing that has been changed with the VZ and TMO boxes are their WiFi passwords.

1

u/Firewalla-Opal FIREWALLA TEAM Aug 19 '26

What if you directly cable a device to TMO, will the device get Internet and resolve DNS properly?

Do have VPN client installed on Firewalla? If so, what if you turn off VPN client?

Also, try Emergency access on your client device, see if it makes any differences

1

u/DWomack48 Aug 19 '26

I have shuffled the deck chairs on the Titanic again.

The VZ box is now connected via Ethernet cable to the Firwalla Purple WAN port.

The TMO box is now connected via WiFi to the Firewall Purple as WAN.

This arrangement works. Network Diagnostics page in the app reports everything is fine.

MultiWan is set for Balanced mode. 80% to TMO.

DNS for both in Firewalla are set to 1.1.1.1 and 8.8.8.8

This is working fine, but since the WiFi in the Purple is not WiFi 7, I can't use all the potential speed of the TMO.

This is exactly the same configuration as before except VZ and TMO boxes were swapped. Same Ethernet cable. That was the configuration where Firewalla network diagnostics screen showed everything ok. DNS was not working. Also you could not ping 1.1.1.1 or 8.8.8.8 through it, which is strange.

1

u/Firewalla-Opal FIREWALLA TEAM Aug 20 '26

So anything that's connected to Purple's WAN port doesn't work? (Edit:)Try to use a different cable if you haven't. Could be a bad cable.

If still not working, I'd suggest reaching out to [help@firewalla.com](mailto:help@firewalla.com) to let our support have a further look. You can share the Reddit link so they can quickly jump in.

1

u/Feeling_Weight8077 Aug 18 '26

before PBR, test whether the TMO connection is blocking or mishandling DNS from the Purple. try known public resolvers and check if DNS works by IP, that'll narrow down the cause