Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    firewall routing problem

    Scheduled Pinned Locked Moved Firewalling
    11 Posts 3 Posters 1.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      viragomann @lightsaver
      last edited by

      @donmay said in firewall routing problem:

      the customer has a vpn server on our network that has the ip address 172.168.56.10

      Which subnet is that connected to?
      You LAN is 172.23.56.0/2, as you stated.

      @donmay said in firewall routing problem:

      i have allowed all traffic from lan to the 10.10.0.0/15 network.. still on the firewall logs it is dropping them

      Post a screenshot.

      1 Reply Last reply Reply Quote 0
      • L Offline
        lightsaver
        last edited by

        thank you for your replay.. it is actually connected in our internal network it has an internal ip of 172.23.56.10/24 and it serves as a gateway for all other devices that want to connect to the 10.10.0.0/15 network

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann
          last edited by

          So all LAN devices that want to connect to an IP in 10.10.0.0/15 have a static route for that network directing packets to 172.23.56.10?
          If so, it has nothing to do with pfSense, since that traffic won't pass it.

          Consider that there will be a static route for your LAN needed on the destination devices in 10.10.0.0/1 as well.

          1 Reply Last reply Reply Quote 0
          • L Offline
            lightsaver
            last edited by

            Hi ,Thanks very much for the reply,
            The static route is actually been set up on the pfsense itself,
            i actually created a gateway ip pointing to the 172.23.56.10 computer locally and then i created a static route on the firewall that if it recieved from the lan interface a traffic that should go to the 10.10.0.0/15 network, it should forward it to the 172.23.56.10 internal vpn server.

            1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann
              last edited by

              With the static route on pfSense you will get an asymmetric routing issue, cause packets from your LAN devices will pass pfSense while responses from the remote site won't.

              If you're using a DHCP server in your LAN and the concerned computers are configured to pull network settings from it, you may distribute the route by the DHCP server. So you don't have to add a route to each of the concerned devices.

              1 Reply Last reply Reply Quote 0
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                @donmay said in firewall routing problem:

                The static route is actually been set up on the pfsense itself,

                Yeah as mentioned by @viragomann that is asymmetrical and going to be problematic.. If you have a different gateway downstream of pfsense, it should be connected to pfsense via a transit network vs doing routing on the host.

                Say something like this
                tansitnetwork.png

                This is a typo right?
                172.168.56.10

                You meant 172.23.56.10, it has an IP on your lan network. 172.168 is public address space. And would amount to you running multiple L3 on a single L2, your lan network.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • L Offline
                  lightsaver
                  last edited by

                  I would like to use this opportunity to say thank you all for your wonderful help on this issue. i think i have been able to know more about asymmetrical routing now☺
                  i decided to go for the first option in this article
                  https://docs.netgate.com/pfsense/en/latest/firewall/troubleshooting-blocked-log-entries-due-to-asymmetric-routing.html
                  i am truly grateful

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    You went with sloppy state? That is not a "fix" that is a work around.. And to be honest it shouldn't even be mentioned in how to fix asymmetrical traffic. It amounts to a MacGyver solution using rubberbands and bubblegum..

                    You should correct your overall network design vs using bandaids.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    1 Reply Last reply Reply Quote 0
                    • L Offline
                      lightsaver
                      last edited by

                      what will you recommend i do then.. because i have this situation and the internal lan devices need access to this internal ...
                      what do i do then please ?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        You create a transit network as I showed in my drawing..

                        Now clients that want/need to go too this 10 network, can just be allowed via simple firewall rule. If you don't want everyone to be able to get there.

                        Transit network can be just a vlan if you want, or if you have an another interface on pfsense can just connect the downstream router there..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.