1:1 NAT, TCP works but ICMP does not



  • I have configured 1:1 NAT with public IP subnet to internal subnet.

    Everything was working with old 2.2.5 release.

    The system was upgraded to latest 2.4.4-p2.

    Now ping to the public IPs goes nowhere. From outside it is shown in trace as a hop but the trace goes on till max hop. Pings timeout.

    From pfsense itself the traffic is being sent out to WAN where it loops and dies.

    All TCP ports are working as expected.

    Shell Output - route -n get x.x.x.90

    route to: x.x.x.90
    destination: 0.0.0.0
    mask: 0.0.0.0
    gateway: y.y.y.149
    fib: 0
    interface: alc0
    flags: <UP,GATEWAY,DONE,PROTO1>
    recvpipe sendpipe ssthresh rtt,msec mtu weight expire
    0 0 0 0 1500 1 0


Log in to reply