pfSense and Microsoft NLB Virtual UP and MAC # 03:**.**
Having DUP ACK issues in Wireshark on internal and WAN links. Some data is obviously passing and working, but slowness is apparent. Do I need to create manual ARP and or MAC entry on the firewalls to direct back to the internal NLB address? I will conform the MAC and ARP are not in the firewall, but where ca nI see the actual packet loss on the pfSense to prove my theory?
If it's local, you might not see it on the firewall.
If you are using MS NLB though, you might not have realized you need to set
net.link.ether.inet.allow_multicast=1in system tunables or the firewall may drop traffic to/from the addresses it uses.