Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OSPF: Ping works fine with routes. Other traffic does not.

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 1 Posters 745 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      MLIT
      last edited by

      Ignore this –- I've found the real problem. Read the 3rd post.
      test_map(1).jpg
      R1_NAT_Outbound.JPG
      R3_NAT_Outbound.JPG
      test_map(1).jpg_thumb
      R1_NAT_Outbound.JPG_thumb
      R3_NAT_Outbound.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • M Offline
        MLIT
        last edited by

        Did some further digging –- This is not a routing issue. It is a firewall issue. I created static routes and it did not work. I then turned off packet filtering completely and it suddenly begins working.

        Any idea what rule I can add to fix this? Thanks!

        1 Reply Last reply Reply Quote 0
        • M Offline
          MLIT
          last edited by

          So I finally found a log entry where it denies my traffic out GRE0 on R3. I've attached it below. I've added a rule on the proper interface, but I'm not sure why it isn't matching.

          From the command line with pfctl -s rules I found the rule:

          -pass in quick on gre0 reply-to (gre0 192.168.113.1) inet all flags S/SA keep state label "USER_RULE"

          This is the rule I added to the GRE interface that is supposed to allow all traffic from any IP address. The thing that sticks out to me is the "in" –-- It looks like from the log that the traffic is being blocked is going "out". I've tried making an "out" version of this rule and it doesn't seem to work. I'm not very familiar with pf (Have a lot more experience with iptables).

          Anyway, I've attached pictures of the packet being blocked and the rule I've attached to the GRE interface. Any help would be very much appreciated at this point. Thank you!

          Firewall_Log.JPG
          Firewall_Rules.JPG
          Firewall_Log.JPG_thumb
          Firewall_Rules.JPG_thumb

          1 Reply Last reply Reply Quote 0
          • M Offline
            MLIT
            last edited by

            This is a bug.

            I've filed a report:

            https://redmine.pfsense.org/issues/4479

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.