Gateway Monitoring Via Custom Script or Telnet.
It would be very helpful to have the ability to monitor gateways via a custom script or telnet. ISPs are beginning to implement soft disconnects more and more aggressively (we had one implemented the day after the bill was due, on a holiday). We have seen AT&T Uverse, Optimum/Cablevision and Verizon Fios implement these soft disconnects. The disconnect is often a redirect or pop up that prevents browsing, its implemented via DNS poisoning or HTTP redirects, but other traffic is left untouched. ICMP still works as expected and so a gateway failover does not occur, even though the gateway is unusable for browsing traffic. I'd like to be able monitor the status of a gateway by actually attempting to browse with it. This could be done via netcat/telnet, wget curl or a custom script; we expect to see the word "google" when connecting to google.com on port 80.
#1 Updated by Bipin Chandra about 2 years ago
many ISPs in India also do a similar thing and etisalat in UAE do a similar thing, if the bill isnt paid by the 15th of the month then all of a sudden u open any web page and u keep getting their annoying ad asking to pay bill and it also says to restart router to be able to surf, problem is they still show this page even if bill is paid. ICMP works but browsing goes down till connection is disconnected and then reconnected
#2 Updated by Bridgetowermedia IT over 1 year ago
Well it seems that the man behind the curtain of support says that this isn't possible... I refuse to accept that this can't be done in a simple, reliable and supportable fashion. Like it or not Netgate I am going to build this feature in on my boxes. I think you greatly underestimate how many of your users will utilize this, many of us running pfsense are also running Teir 3 circuits (that utilize soft discos) to save money. Even outside of that, ICMP is outdated and not at all a good indicator of whether an end user can "access the internet".
I'm going to try building a script that will work with the existing infrastructure. Seems that the best way to go about it (without much effort or risk) is to use pfctl in a script to block ICMP responses from the configured monitoring host when the script detects a "_SoftDown_". SoftDown will be determined by Wget with "--bind-address" on specified gateway to check for a string in the returned html of a specified website. I'll run the script with cron every 5 minutes. Maybe I'll get fancy and try to email the email address configured in the GUI (maybe sending mail to root is enough) when SoftDown occurs.
#4 Updated by Bridgetowermedia IT over 1 year ago
Alright script is done, its pretty basic, See attached. Took Brendon's advice and used the Mark gateway as down option. Supports 2 gateways.
Not sure how to submit this to the devs to add to the release but maybe they will find it here.
#5 Updated by Bridgetowermedia IT over 1 year ago
Well that script didn't really seem to work... New Script attached. Sends emails via smtp to address configured on notifications page. drop the script in /etc/phpshellsessions/softdiscomon and use a cronjob to execute with command "/usr/local/pfSsh.php playback softdiscomon" I've currently got this running beautifully on 3 site firewalls with plans to expand to another 20.