Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense 2.2.2 in esx arp issues.

    Scheduled Pinned Locked Moved Virtualization
    11 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rbflurry
      last edited by

      Hello All.

      I will try and include as much details as possible but I still can not wrap my head around the problem.

      I am trying to use PFSense 2.2.2 in a Vmware environemnt to separate a Vlan from the rest of the network.

      I have two Vlans trunked up to the ESX host to two distributed switches.

      Then in pfsense I have two interfaces one on each Distributed switch.

      This is a very basic setup and I have done this setup on a smaller scale at home.

      Nating is disabled and I have two any any rules configured just for testing.

      The problem: When pinging from a host in the wan (host a) to a laptop connected inside the lan (host b) Using wireshark I can see the ping requests make it to host B but host B then sends arp requests over and over again trying to find the .1 (pfsense lan ip)

      Once Promiscuous mode is enabled on both the Virtual switch and PFsense everything works appropriately.

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        Gateway IP a CARP IP? Then that's the expected result. If it's not, then you have some kind of VMware problem. Well, either way it's a VMware problem, just one would be expected because of how its vswitches function.

        1 Reply Last reply Reply Quote 0
        • E
          EMWEE
          last edited by

          Did you bridged the two interfaces in pfSense? I remember having some issues with bridged interface in ESX. We need to use promiscuos mode to get things going.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            Similar situation for bridging, for the same reason with the vswitches.

            1 Reply Last reply Reply Quote 0
            • R
              rbflurry
              last edited by

              This is not bridged and no Carp.

              Leaning towards Vmware even more now.

              if I turn promisc off on everything and set a static Arp on host B It works as expected again.

              Now to find out why arp is working between vmware and cisco.

              Thank you all.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                I don't have any issues with arping, my vswitches are not in promisc mode..  Multiple segments and one connection that is a trunked to the vswitch.

                What are you running for esxi?  I agree this sure has nothing to do with pfsense.

                vswitchtrunked.png
                vswitchtrunked.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • R
                  rbflurry
                  last edited by

                  Using Vmware ESXi 5.5.

                  My setup is similar to yours except the Vswitch is setup for a single vlan rather than all of them like yours.

                  Time to bother the cisco guys…

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    you are using u2 of 5.5 I assume - freebsd 10.1 is not supported until u2 of 5.5

                    So you have multiple port groups on the same vswitch with different vlans on them?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • R
                      rbflurry
                      last edited by

                      Sorry not the best with Vmware. here is the setup. I think I blocked out the un-needed goods.

                      Capture.PNG
                      Capture.PNG_thumb

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        how is that suppose to work exactly where is the gateway for your different machines say on vlan 330?  Something has to route the vlans.  You have that vm on 1012 that is called firewall?  But its only on 1 vlan?

                        Is your router virtual?  What is doing the layer 3 between the vlans - and what is your physical connection of those 8 interfaces to your phyical switches setup?  Just trunk with all of those vlans?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • R
                          rbflurry
                          last edited by

                          Just switched back to e1000 interfaces from vmxnet 3 interfaces and now pfsense is seeing broadcasts including arps.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.