Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No downstream/inbound traffic coming in

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 1 Posters 309 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kutsheax
      last edited by kutsheax

      e625de48-baf9-402f-9682-315cef65826f-image.png

      Hi All,

      I have a problem where all external lans are unable to to access all the xen hosts using dhcp server with ip's 10.133.201.6 to 62, DHCP is working fine and all the vm's are leased. From the XEN hosts, i can reached all external LANS, with out a problem. My biggest issue is the inbound.

      The rules on my vlan876 is as follows
      External -> Vlan876net -> ANY
      Vlan876net ->External Lan ->ANY

      only upstream works. there are now any WAN requirements as this is an internal firewall and only acts as a DHCP server and nothing else.

      I'ved try playing with floating, static routes,1:1 and port forwarding without any success. currently, the pfsense is pointing the nexthop to the checkpoint fw interface - 10.133.201.1. And from what i observed from checkpoint fw logs, traffic is passing out the cp firewall but stops on the pfsense. From checkpoint FW, i can reach all the ip's and CARP of the pfsense interface and all of the xen host.

      Setup:
      on Pfsense
      i have Lagg0(lacp) interface without ip as i believe is a physical connections only(traffic pass through). Vlan876 interface lies under the Lagg0. i have enabled the manual outbound NAT, in which all the vlan876 were able to connect to my external lans.

      The carp seems to be working fine as the node2 becomes a backup.
      Here's my policy:
      7464d5f2-6765-4896-ad08-b67d4821e321-image.png

      upstream routes:
      00ee931a-ac21-4655-92d6-829daeba2282-image.png

      Interfaces: wan and lan is just there without any physical connections:

      35d83ccb-3108-4aac-9577-dca656be8774-image.png

      appreciate if anyone point me on the right direction.

      Regards.

      1 Reply Last reply Reply Quote 0
      • K
        kutsheax
        last edited by

        i'ved added two new reject rules on interface vlan876. still not working =(
        a7c72de6-08ff-4ad7-be15-ed2020d987f9-image.png

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.