Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ICMP Redirect are not working pfSense 2.3.2

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      JonasOP
      last edited by

      Hi.

      Relatated to the attached drawing ICMP redirect from 10.10.0.40 to 192.168.0.0/24 are not working.
      At 10.10.0.40 i am not seeing any ICMP redirect packed when I am using wireshark.
      Windows firewall are turned off on .40 (MS server 2012 R2)

      An capture from the pfsense are not showing that the pfSense are sending back an icmp redirect packed to .40
      net.inet.ip.redirect are set to value 1 in the pfsense webinterface.
      showctl net.inet.ip.redirect are also showing that the value of net.inet.ip.redirect are 1 (enabled)

      The traffic are rx and tx on the same interface, so "static route filtering" are enabled on the pfSense.

      I have other installation with the exact same setup, and these are working just fine.

      Has anyone a good idea how to get the ICMP redirect to work?

      Kind regards
      Jonas
      Drawing1.jpg
      Drawing1.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        What exactly are you wanting to happen?

        So you want pfsense to redirect 10.10.0.1 to 10.10.0.3 to get to 192.168.0 over your mpls??

        I would call that a borked setup.. Why would you not just connect your mpls cpe to pfsense via a transit network so pfsense knows exactly how to route to 192.168 via the isp cpe router so you don't have to try and hack it to work with a redirects..

        transit.png
        transit.png_thumb

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • J Offline
          JonasOP
          last edited by

          Hi Johnpoz.

          This is an datacenter customer setup.
          All customers have their own pfsesne and a internal network for servers.

          I know this is not the best solution, otherwise using ICMP redirect are not wrong, and should work just fine.
          I want to use ICMP redirect i that case that i am running out of vlans in our envirement.
          (We are in these days, migrating to NSX and vxlan's.)
          I don't want use cpu resurces to move internal traffic between the customer and the datacenter.
          Typical customers have 1000mbit MPLS connections to the datacenter, and I don't want to use CPU/MEM resources for hundreds of customer's internal traffic.

          Kind regars
          Jonas

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            Ok - its still borked.. Maybe someone else be willing to help.. Contact pfsense direct for support would be my suggestion if you have paying customers with Gig Mpls connections you should be able to pay for some official support ;)

            That is not how it should ever be setup.. I don't help people configure borked configurations ;)  Just makes it look I would condone such a configuration, which I would never do..

            There is a reason they are not enabled out of the box…

            https://www.pfsense.org/get-support/

            If you do not want to use cycles on the pfsense to route the traffic as it should, then put in a host route so you host knows to talk to .3 out of the gate vs having to wait for a redirect to tell him he is going to the wrong place for that destination.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.