Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Two interfaces have stopped seeing each other

    NAT
    2
    5
    254
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kastegir last edited by

      I have upgraded to 2.4.2 and now my two internal interfaces no longer communicate.

      I have Int1 10.10.1.0
      and Int2 10.10.2.0

      They used to be able to see each other with no issues.

      Now they can't talk to each other at all. When I try and trace route, they appear to be attempting to using the WAN gateway to go out and see each other. Obviously causing an issue.

      It worked fine until I did the last upgrade.

      Any Suggestions?

      1 Reply Last reply Reply Quote 0
      • Derelict
        Derelict LAYER 8 Netgate last edited by

        If you have two local interfaces with pass rules and the traffic is going out WAN the traffic is probably being matched by a policy routing rule (a rule with a gateway/gateway group set.)

        https://doc.pfsense.org/index.php/Bypassing_Policy_Routing

        Chattanooga, Tennessee, USA
        The pfSense Book is free of charge!
        DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • K
          kastegir last edited by

          I don't wee where I change that. Is something new in 2.4.2? because it literally stopped working right after the upgrade.

          1 Reply Last reply Reply Quote 0
          • K
            kastegir last edited by

            Never mind that fixed it!

            Thanks!

            1 Reply Last reply Reply Quote 0
            • Derelict
              Derelict LAYER 8 Netgate last edited by

              No. It is not new.

              There is something called "negate routes" that attempts to automatically bypass policy routing for certain networks.

              It can miss things in certain cases so it might have been automatically negated before and is not now.

              Glad you found it.

              Chattanooga, Tennessee, USA
              The pfSense Book is free of charge!
              DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post