Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to make pfSense "scrub" lan VMs MAC-addresses?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 604 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Gargamella
      last edited by

      Hi, how can i make so that all the VMs in my proxmox server, that goes thru my pfSense VM, gets their MAC-address replaced by the pfSense own?
      Because Hetzner is very nit-picky about what MAC-addresses that shows up, and currently, all VM guests MAC-addresses shows up, or some of them, and all is set to go thru only the pfSense VM.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Something upstream of pfSense (on the WAN side) could not see the downstream (LAN side) MAC addresses of hosts in the default config.
        Do you have it setup as a transparent firewall, WAN and LAN bridged?

        Otherwise the only way they could see that is if there's traffic not going through pfSense.

        Steve

        G 1 Reply Last reply Reply Quote 0
        • G
          Gargamella @stephenw10
          last edited by

          @stephenw10 said in How to make pfSense "scrub" lan VMs MAC-addresses?:

          Something upstream of pfSense (on the WAN side) could not see the downstream (LAN side) MAC addresses of hosts in the default config.
          Do you have it setup as a transparent firewall, WAN and LAN bridged?

          Otherwise the only way they could see that is if there's traffic not going through pfSense.

          Steve

          Im quite sure i have set it up by all rules and means im supposed to.

          But i have seen a thread on proxmox forum talking about this and they concluded(?) that hetzner seems to broadcast on the whole subnet until they find a matching MAC-address to send the packages to. So it might be this part thats my problem if its true.

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @Gargamella
            last edited by

            @gargamella

            MAC addresses are "scrubbed" from every packet passing through a router. On the WAN side you'll only see the WAN side MAC address.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              There was a similar thread to this a few months back. User kept getting warnings from Hetzner about unregistered MAC addresses. It was a configuration issue though IIRC.
              As long as LAN side clients are sending all their traffic through pfSense anything on the WAN side cannot see the LAN side MACs.
              Since it's all virtual though Hetzner may be looking on the LAN side?

              Steve

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.