Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN Traffic Problem

    Scheduled Pinned Locked Moved Firewalling
    16 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sergio77
      last edited by

      Hi all,

      I have a strange problem...

      My PfSense has 192.168.1.1 IP, my VM has 192.168.1.2 IP.

      From VM I try this:
      curl -k www.google.it
      with this output:
      curl: (7) Failed to connect to www.google.it port 80: Connection timed out

      In My Pfsense shell, I see this:
      19:05:40.453877 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090814887 ecr 0,nop,wscale 7], length 0
      19:05:41.454741 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090815888 ecr 0,nop,wscale 7], length 0
      19:05:43.470746 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090817904 ecr 0,nop,wscale 7], length 0
      19:05:47.630780 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090822064 ecr 0,nop,wscale 7], length 0
      19:05:55.822812 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090830256 ecr 0,nop,wscale 7], length 0
      19:06:11.950894 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090846384 ecr 0,nop,wscale 7], length 0
      19:06:44.463081 IP 192.168.1.2.54272 > 142.251.209.3.80: Flags [S], seq 1666965013, win 64240, options [mss 1460,sackOK,TS val 2090878896 ecr 0,nop,wscale 7], length 0

      I attach screen where you can see that traffic is allowed... but it doesn't work really...

      What can I check and change to let my VM navigate on Internet?

      Thanks
      Sergio

      Schermata 2022-05-30 alle 21.52.04.png

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Sergio77
        last edited by

        @sergio77
        Is pfSense able to access the internet for update check and package installation? Or other local devices behind it?

        Is your outbound NAT in automatic mode?
        Is there a rule for the source network?

        S 1 Reply Last reply Reply Quote 0
        • S
          Sergio77 @viragomann
          last edited by

          @viragomann I attached some screen to answer your question.
          Thanks
          Sergio

          Schermata 2022-05-31 alle 08.53.56.png Schermata 2022-05-31 alle 08.54.21.png Schermata 2022-05-31 alle 08.54.46.png Schermata 2022-05-31 alle 08.55.04.png

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @Sergio77
            last edited by

            @sergio77
            So the ping works from pfSense WAN, but not from LAN. This almost indicates that the outbound NAT doesn't work properly.
            However, there is an automatic rule in place for the LAN network.
            Did you try to reboot pfSense?

            Is pfSense installed in a VM? If so, which hypervisor?

            S 1 Reply Last reply Reply Quote 0
            • S
              Sergio77 @viragomann
              last edited by

              @viragomann updated and rebooted yesterday...

              Yes, It's a virtual server on Esxi 6.7.0 Update 3 (Build 17167734).

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @Sergio77
                last edited by

                @sergio77
                There should be nothing special on ESXi, as long as you're not running an HA system with CARP.

                To investigate if the outbound NAT is working properly run a packet capture on the WAN interface, while you ping a public IP from a LAN device.
                You should see packets going out from the WAN address.

                S 1 Reply Last reply Reply Quote 0
                • S
                  Sergio77 @viragomann
                  last edited by

                  @viragomann I did the test, but my capture log is empty...Schermata 2022-06-01 alle 11.32.06.png Schermata 2022-06-01 alle 11.32.17.png Schermata 2022-06-01 alle 11.32.47.png

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Sergio77
                    last edited by

                    @sergio77
                    In the host box enter the destination IP you“re pinging not a source.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      Sergio77 @viragomann
                      last edited by

                      @viragomann nothing is changed :-(

                      Schermata 2022-06-01 alle 12.48.07.png Schermata 2022-06-01 alle 12.47.57.png

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @Sergio77
                        last edited by

                        @sergio77
                        Maybe nothing from the VM is coming to pfSense?
                        Check that out by capturing ICMP packets on the LAN interface, while you try to ping a public IP on the VM.

                        If there is also nothing you're VM may use a different gateway, not pfSense LAN IP, or there is something wrong with the ESXi network.

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          Sergio77 @viragomann
                          last edited by

                          @viragomann This is the result...Schermata 2022-06-03 alle 09.48.48.png Schermata 2022-06-03 alle 09.48.39.png

                          V 1 Reply Last reply Reply Quote 0
                          • V
                            viragomann @Sergio77
                            last edited by

                            @sergio77
                            Did you specify an gateway IP address in the LAN interface settings? If so remove it, please.

                            S 2 Replies Last reply Reply Quote 0
                            • S
                              Sergio77 @viragomann
                              last edited by

                              @viragomann It doesn't seem... Schermata 2022-06-03 alle 17.56.06.png

                              A 1 Reply Last reply Reply Quote 0
                              • S
                                Sergio77 @viragomann
                                last edited by

                                @viragomann another screen from LAN Server...Schermata 2022-06-03 alle 17.58.07.png

                                V 1 Reply Last reply Reply Quote 0
                                • V
                                  viragomann @Sergio77
                                  last edited by

                                  @sergio77
                                  Yes, the VM might be okay. The upstream packets are arriving on pfSense LAN and you might see also the ICMP packets as passed in the firewall log.
                                  Can't understand, why there is nothing on the WAN.

                                  Do you have a basic interface configuration on pfSense, no CARP?

                                  Did you the ESXi configuration accordingly to the pfSense docs: Virtualizing pfSense with VMware vSphere / ESXi

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    ahsunh @Sergio77
                                    last edited by

                                    @sergio77 check your firewall rule on lan interface allow all lan traffic for protocol any and ipv4 is available?

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.