• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Physical host unable to ping virtual host through virtual pfSense firewall

Virtualization
support proxmox
3
11
1.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    NollipfSense @dingodoggo69
    last edited by Apr 21, 2023, 11:51 PM

    @dingodoggo69 You need to show us your firewall rules.

    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

    D 1 Reply Last reply Apr 22, 2023, 12:11 AM Reply Quote 0
    • D
      dingodoggo69 @NollipfSense
      last edited by Apr 22, 2023, 12:11 AM

      @nollipfsense sorry, I should've said I just have any any rules on all interfaces but the WAN.

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @dingodoggo69
        last edited by Apr 22, 2023, 12:17 AM

        @dingodoggo69 โ€œanyโ€ rules allow ICMP not just TCP? Is the firewall on the target set to allow ICMP from outside its subnet?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        D 1 Reply Last reply Apr 22, 2023, 9:46 AM Reply Quote 0
        • D
          dingodoggo69 @SteveITS
          last edited by Apr 22, 2023, 9:46 AM

          @steveits given its set set to pass any traffic on both interfaces I would think any protocol would be accepted between subnets, unless I'm mistaken?

          S 1 Reply Last reply Apr 22, 2023, 1:27 PM Reply Quote 0
          • S
            SteveITS Galactic Empire @dingodoggo69
            last edited by Apr 22, 2023, 1:27 PM

            @dingodoggo69 The rule needs to say protocol โ€œIPv4 *โ€ not the default TCP. It happens a decent amount here on the forums and Iโ€™ve done it myself, so just asking.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            D 1 Reply Last reply Apr 23, 2023, 12:44 AM Reply Quote 0
            • D
              dingodoggo69 @SteveITS
              last edited by Apr 23, 2023, 12:44 AM

              @steveits yep I see what you mean, set to IPv4 and any protocol so shouldn't be that.

              1 Reply Last reply Reply Quote 0
              • N
                NollipfSense
                last edited by NollipfSense May 4, 2023, 6:21 AM May 4, 2023, 6:19 AM

                I am now facing this issue but the other way around...I can ping pfSense LAN from a Mac Pro connected Proxmox management port but cannot ping the physical host from pfSense LAN...keep getting host is down. I would like to get pfSense dashboard on the tab next to the tab with Proxmox management.

                login-to-view

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                D 1 Reply Last reply May 4, 2023, 6:49 AM Reply Quote 0
                • D
                  dingodoggo69 @NollipfSense
                  last edited by May 4, 2023, 6:49 AM

                  @nollipfsense have you checked host firewall settings? I fixed this by disabling the firewall on the host, ensuring NAT was setup for the LANs and setting a gateway within the DHCP servers.

                  N 1 Reply Last reply May 4, 2023, 7:07 PM Reply Quote 0
                  • N
                    NollipfSense @dingodoggo69
                    last edited by NollipfSense May 4, 2023, 7:09 PM May 4, 2023, 7:07 PM

                    @dingodoggo69 I had not configured firewall on Proxmox and is using whatever is set by default. I did setup firewall rule on pfSense to allow connections to and from Proxmox management port. Can I see your configuration?

                    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                    1 Reply Last reply Reply Quote 0
                    • N
                      NollipfSense
                      last edited by NollipfSense May 6, 2023, 8:18 PM May 6, 2023, 8:08 PM

                      Now, I got it right without the need to disable any firewall...my mistake was to move default gateway to pfSense. The default gateway is just for Proxmox management port to update itself and need to remain on the port originally assigned. Then, I made pfSense LAN that IP. Both accessible by my Mac Pro on the same browser tabs next to each other.

                      login-to-view

                      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.