Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Packet drop and general unusability when firewall is turned on

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 597 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SimonG
      last edited by

      Hi,

      I have an SG-1000 firewall which is an IPSEC VPN to a Juniper firewall at our main site.  The VPN is up and works fine (its a NAT-T aggressive VPN).

      The problem is that when a PC behind the firewall pings over the VPN it drops a ping every 10 attempts or so and services like RDP just freeze almost constantly (connect then freeze).  IP phones drop out etc… Just completely unusable.

      I have turned off NAT all together (don't need it) and that hasn't helped.

      I set the firewall to conservative and that doesnt resolved it either.

      If I turn off the firewall packet filtering all together, then hey presto it works like a charm and everything (RDP, VOIP etc) works seamless.

      This device is a VPN endpoint so not a huge drama but has really put me off using pfsense for any real firewalling.

      Any ideas?

      The firewall rules are just IPSEC any to lan and LAN lan to any.

      1 Reply Last reply Reply Quote 0
      • S
        SimonG
        last edited by

        Any ideas, its really annoying!

        1 Reply Last reply Reply Quote 0
        • N
          Nullity
          last edited by

          I'd get a packet capture and analyze it with Wireshark.

          Please correct any obvious misinformation in my posts.
          -Not a professional; an arrogant ignoramous.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            How much traffic is it pushing at the time?

            What is the CPU usage like?

            Are there any interface errors showing on the GUI (Status > Interfaces) or in sysctl (sysctl -a | grep cpsw)?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.