@cmb:
Where you see nothing at all for that IP in a packet capture on WAN, not even ARP requests, it's a problem with your modem most often with cable, otherwise something to do with your ISP. If the VIP weren't actually configured or triggering an ARP response for some reason, you'd see repeated incoming ARP requests on WAN "who has x.x.x.x" for the IP in question, with no replies, when you're sending traffic in from the Internet to that destination IP. No point in digging into the VIP when there is nothing at all for that IP on WAN, as you know 100% for sure the problem is upstream.
Hello Community,
I know this is an almost a year old thread but we never got it resolved unfortunately.
As cmb suggested, it might have been an issue with the provider's modem but we were able however to test these IP addresses when connected directly to Comcast modem and all of them worked fine. As opposite to what we can use on pfsense:
Here is a list of which IPs work and which doesn't:
xx.xx.xx.241/28 - pfsense WAN
xx.xx.xx.242/28 - WORKS
xx.xx.xx.243/28 - DOESN'T WORK
xx.xx.xx.244/28 - WORKS
xx.xx.xx.245/28 - DOESN'T WORK
xx.xx.xx.246/28 - DOESN'T WORK
xx.xx.xx.247/28 - DOESN'T WORK
xx.xx.xx.248/28 - DOESN'T WORK
xx.xx.xx.249/28 - WORKS
xx.xx.xx.250/28 - WORKS
xx.xx.xx.251/28 - WORKS
xx.xx.xx.252/28 - WORKS
xx.xx.xx.253/28 - DOESN'T WORK
xx.xx.xx.254/28 - Comcast Gateway
As stated above, there is no incoming packets when checked by Packet capture.
Every IP is an separate entry on Virtual IPs tab - this seems to be correct for another subnet we have with different provider.
What else could I try checking?