• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense 1.0.1 on new hardware makes trixbox angry

Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
4 Posts 3 Posters 2.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dharmatech
    last edited by Aug 15, 2008, 4:00 PM Aug 15, 2008, 3:51 PM

    We wanted to upgrade our pfsense box w/new hardware.  When we installed pfsense on the new machine and restored the config file from our current firewall our trixbox couldn't ping out.  Everything else worked… our LAN could get out and our VPN was fine so I don't think it's a problem w/faulty NICs.  Clearing the arp entry for the new firewall didn't seem to help.  When we log into the trixbox, we can't ping out.  tcpdump on the new firewall shows that a ping request and reply is happening but the firewall seems to be eating it instead of passing it on to the trixbox.  If we swap out the new firewall for the old, trixbox can ping away and our VOIP works as expected.

    Any ideas for troubleshooting this problem?  We tried the 1.2 release as well... same problem.

    Thanks.

    1 Reply Last reply Reply Quote 0
    • S
      stechnique
      last edited by Aug 17, 2008, 1:28 AM

      Several of us use trixbox behind pfsense 1.2 with no problems, anything special in your pfsense config?
      Can pfsense ping trixbox?

      1 Reply Last reply Reply Quote 0
      • D
        dharmatech
        last edited by Aug 19, 2008, 8:36 PM

        Yes, pfSense can ping the trixbox, and the trixbox can ping pfsense.  The problem comes when we try to ping anything outside the WAN IP address from the trixbox, including the next hop gateway.

        We're using 1:1 NAT to our trixbox, and proxy arp configured for this IP.  It seems that as soon as we configure 1:1 NAT for the machine, that's when we can no longer ping outside.  We could just port forward through our WAN address, but our VOIP provider is expecting us at the address we're currently using.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Sep 3, 2008, 2:35 PM

          For the sake of the archives (or if you still haven't resolved this) - this is ARP cache related on your ISP's side, the gateway of your firewall is hanging onto the old MAC address for that VIP for usually hours, you'll either have to wait or manually clear it in this circumstance.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received