Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic being blocked/not making it out to WAN Gateway?

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 1 Posters 323 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      realityman_
      last edited by

      Currently running pfSense 2.4.5, snort, and pfBlocker. I also have fq_codel running on the WAN interface via a floating rule. VLANs are configured and pfSense acts as "router on a stick." Unbound is my resolver with forwarding sent to 1.1.1.1 1.0.0.1 and 8.8.8.8.

      This has just started happening recently and (seemingly) randomly. I know nothing is random, but I haven't been able to point a cause->effect yet. My clients are able to do DNS lookups (can prove via dig), and it will also resolve to an IP via trace route. However it can't resolve past the first hop, which is pfSense.

      I can log in to pfSense fine. I tried a traceroute of google.com from the UI and it works fine from the WAN interface. It doesn't work from the VLAN20 interface, it just responds 127.0.0.1 over and over. I'm not sure if that's by design, meaning, I wasn't sure if pfSense fully simulated a VLAN20 client calling tracing to google.com or not, so it may not be a valid test.

      What else can I be looking at?

      R 1 Reply Last reply Reply Quote 0
      • R Offline
        realityman_ @realityman_
        last edited by

        Also one thing of note is that I show the gateway as 66.133.48.1 but my actual ip address online shows 66.133.61.112 when it works. I see some general 103 blocks so I wonder if there is maybe asymmetric routing going on somehow nuking everything?

        1 Reply Last reply Reply Quote 0
        • R Offline
          realityman_
          last edited by

          Ok it just did it again and I see "config_aqm Unable to configure flow set, flow set busy!" which seems to be not good?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.