• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

LAN Traffic Problem

Scheduled Pinned Locked Moved Firewalling
16 Posts 3 Posters 1.6k Views 3 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    Sergio77
    last edited by May 30, 2022, 7:54 PM

    Hi all,

    I have a strange problem...

    My PfSense has 192.168.1.1 IP, my VM has 192.168.1.2 IP.

    From VM I try this:
    curl -k www.google.it
    with this output:
    curl: (7) Failed to connect to www.google.it port 80: Connection timed out

    In My Pfsense shell, I see this:
    19:05:40.453877 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090814887 ecr 0,nop,wscale 7], length 0
    19:05:41.454741 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090815888 ecr 0,nop,wscale 7], length 0
    19:05:43.470746 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090817904 ecr 0,nop,wscale 7], length 0
    19:05:47.630780 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090822064 ecr 0,nop,wscale 7], length 0
    19:05:55.822812 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090830256 ecr 0,nop,wscale 7], length 0
    19:06:11.950894 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090846384 ecr 0,nop,wscale 7], length 0
    19:06:44.463081 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090878896 ecr 0,nop,wscale 7], length 0

    I attach screen where you can see that traffic is allowed... but it doesn't work really...

    What can I check and change to let my VM navigate on Internet?

    Thanks
    Sergio

    Schermata 2022-05-30 alle 21.52.04.png

    V 1 Reply Last reply May 30, 2022, 8:32 PM Reply Quote 0
    • V Offline
      viragomann @Sergio77
      last edited by May 30, 2022, 8:32 PM

      @sergio77
      Is pfSense able to access the internet for update check and package installation? Or other local devices behind it?

      Is your outbound NAT in automatic mode?
      Is there a rule for the source network?

      S 1 Reply Last reply May 31, 2022, 6:56 AM Reply Quote 0
      • S Offline
        Sergio77 @viragomann
        last edited by May 31, 2022, 6:56 AM

        @viragomann I attached some screen to answer your question.
        Thanks
        Sergio

        Schermata 2022-05-31 alle 08.53.56.png Schermata 2022-05-31 alle 08.54.21.png Schermata 2022-05-31 alle 08.54.46.png Schermata 2022-05-31 alle 08.55.04.png

        V 1 Reply Last reply May 31, 2022, 10:03 AM Reply Quote 0
        • V Offline
          viragomann @Sergio77
          last edited by May 31, 2022, 10:03 AM

          @sergio77
          So the ping works from pfSense WAN, but not from LAN. This almost indicates that the outbound NAT doesn't work properly.
          However, there is an automatic rule in place for the LAN network.
          Did you try to reboot pfSense?

          Is pfSense installed in a VM? If so, which hypervisor?

          S 1 Reply Last reply May 31, 2022, 1:44 PM Reply Quote 0
          • S Offline
            Sergio77 @viragomann
            last edited by May 31, 2022, 1:44 PM

            @viragomann updated and rebooted yesterday...

            Yes, It's a virtual server on Esxi 6.7.0 Update 3 (Build 17167734).

            V 1 Reply Last reply May 31, 2022, 2:04 PM Reply Quote 0
            • V Offline
              viragomann @Sergio77
              last edited by May 31, 2022, 2:04 PM

              @sergio77
              There should be nothing special on ESXi, as long as you're not running an HA system with CARP.

              To investigate if the outbound NAT is working properly run a packet capture on the WAN interface, while you ping a public IP from a LAN device.
              You should see packets going out from the WAN address.

              S 1 Reply Last reply Jun 1, 2022, 9:33 AM Reply Quote 0
              • S Offline
                Sergio77 @viragomann
                last edited by Jun 1, 2022, 9:33 AM

                @viragomann I did the test, but my capture log is empty...Schermata 2022-06-01 alle 11.32.06.png Schermata 2022-06-01 alle 11.32.17.png Schermata 2022-06-01 alle 11.32.47.png

                V 1 Reply Last reply Jun 1, 2022, 10:33 AM Reply Quote 0
                • V Offline
                  viragomann @Sergio77
                  last edited by Jun 1, 2022, 10:33 AM

                  @sergio77
                  In the host box enter the destination IP you“re pinging not a source.

                  S 1 Reply Last reply Jun 1, 2022, 10:50 AM Reply Quote 0
                  • S Offline
                    Sergio77 @viragomann
                    last edited by Jun 1, 2022, 10:50 AM

                    @viragomann nothing is changed :-(

                    Schermata 2022-06-01 alle 12.48.07.png Schermata 2022-06-01 alle 12.47.57.png

                    V 1 Reply Last reply Jun 1, 2022, 8:20 PM Reply Quote 0
                    • V Offline
                      viragomann @Sergio77
                      last edited by Jun 1, 2022, 8:20 PM

                      @sergio77
                      Maybe nothing from the VM is coming to pfSense?
                      Check that out by capturing ICMP packets on the LAN interface, while you try to ping a public IP on the VM.

                      If there is also nothing you're VM may use a different gateway, not pfSense LAN IP, or there is something wrong with the ESXi network.

                      S 1 Reply Last reply Jun 3, 2022, 7:49 AM Reply Quote 0
                      • S Offline
                        Sergio77 @viragomann
                        last edited by Jun 3, 2022, 7:49 AM

                        @viragomann This is the result...Schermata 2022-06-03 alle 09.48.48.png Schermata 2022-06-03 alle 09.48.39.png

                        V 1 Reply Last reply Jun 3, 2022, 12:05 PM Reply Quote 0
                        • V Offline
                          viragomann @Sergio77
                          last edited by Jun 3, 2022, 12:05 PM

                          @sergio77
                          Did you specify an gateway IP address in the LAN interface settings? If so remove it, please.

                          S 2 Replies Last reply Jun 3, 2022, 3:57 PM Reply Quote 0
                          • S Offline
                            Sergio77 @viragomann
                            last edited by Jun 3, 2022, 3:57 PM

                            @viragomann It doesn't seem... Schermata 2022-06-03 alle 17.56.06.png

                            A 1 Reply Last reply Jun 5, 2022, 2:21 PM Reply Quote 0
                            • S Offline
                              Sergio77 @viragomann
                              last edited by Jun 3, 2022, 4:00 PM

                              @viragomann another screen from LAN Server...Schermata 2022-06-03 alle 17.58.07.png

                              V 1 Reply Last reply Jun 3, 2022, 4:28 PM Reply Quote 0
                              • V Offline
                                viragomann @Sergio77
                                last edited by Jun 3, 2022, 4:28 PM

                                @sergio77
                                Yes, the VM might be okay. The upstream packets are arriving on pfSense LAN and you might see also the ICMP packets as passed in the firewall log.
                                Can't understand, why there is nothing on the WAN.

                                Do you have a basic interface configuration on pfSense, no CARP?

                                Did you the ESXi configuration accordingly to the pfSense docs: Virtualizing pfSense with VMware vSphere / ESXi

                                1 Reply Last reply Reply Quote 0
                                • A Offline
                                  ahsunh @Sergio77
                                  last edited by Jun 5, 2022, 2:21 PM

                                  @sergio77 check your firewall rule on lan interface allow all lan traffic for protocol any and ipv4 is available?

                                  1 Reply Last reply Reply Quote 0
                                  1 out of 16
                                  • First post
                                    1/16
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                    This community forum collects and processes your personal information.
                                    consent.not_received