PfSense IAX trixbox
-
If you mean is the LAN interface bridged with the WAN then yes.
-
yes, that is what i meant. can you post the mac addresses of the two pfsense nics as well as the trixbox nic?
-
trixbox:
eth0 Link encap:Ethernet HWaddr 00:1A:92:29:2E:5A
pfsense:
re0: flags=8943 <up,broadcast,running,promisc,simplex,multicast>metric 0 mtu 1500
options=389b <rxcsum,txcsum,vlan_mtu,vlan_hwtagging,vlan_hwcsum,wol_ucast,wol_mcast,wol_magic>ether 00:17:3f:9b:dd:25re1: flags=8943 <up,broadcast,running,promisc,simplex,multicast>metric 0 mtu 1500
options=389b <rxcsum,txcsum,vlan_mtu,vlan_hwtagging,vlan_hwcsum,wol_ucast,wol_mcast,wol_magic>ether 00:17:3f:9c:24:fcbridge0: flags=8843 <up,broadcast,running,simplex,multicast>metric 0 mtu 1500
ether 0e:67:bb:99:2b:ab</up,broadcast,running,simplex,multicast></rxcsum,txcsum,vlan_mtu,vlan_hwtagging,vlan_hwcsum,wol_ucast,wol_mcast,wol_magic></up,broadcast,running,promisc,simplex,multicast></rxcsum,txcsum,vlan_mtu,vlan_hwtagging,vlan_hwcsum,wol_ucast,wol_mcast,wol_magic></up,broadcast,running,promisc,simplex,multicast> -
this is weird. it's like the pfsense is doing some kind of proxy arp. what does your config look like?
-
I've just removed the NAT rule, which i mistakenly thought you wanted me to put in last night:
19:22:46.583484 arp who-has XX.155.38.205 tell XX.155.38.193
19:22:46.583855 arp reply XX.155.38.205 is-at 00:1a:92:29:2e:5aNow its only replying with the one MAC much more sensible.
What do you mean "config look like" firewall?
-
yeah, sorry, that was when i thought it was a NAT setup. i assume it still does not work? if so, it might be good to reboot the pfsense just to make sure everything is clean.
-
Hi,
Sorry had to go away for a few days. I've rebooted the pf box and yes - unfortunately exactly still the same problem.
-
Can you take another packet trace?
-
Thanks for all your help.
Finally got it.
In case this causes anyone else a problem:
FW –> NAT --> Outbound --> Manual Outbound NAT rule generation
And I should have.
Deleted the existing default rule.
Thanks again.
-
;D thanks i am here for the same kind a problem .Got a solution through this .
Thanks Team
K~