Double Nat, No tcp connections
-
I have pfsense on a vm for a home lab. It is behind another router from my isp. I am able to ping internet hosts from devices on the pfsense lan. I also verified that routes are working. DNS is also working well from these clients through the firewall and isp.
Tcp connections don't work though. I think it has something to do with the stateful nature of the system. I tried disabling those rules to block bogon and private networks but the problem persists.
Anyone familiar with this?
-
@plankton45
I suspect, the LAN behind pfSense is not fully isolated from the network on the WAN side.Ensure that nothing else than pfSense has an interface in both networks. This also applies to the virtualization host.
-
@viragomann
Thanks for the suggestion. I'm using an XCP-NG host. Just found some documentation that explains how to install xen tools and the removal of tx checksum offloading. Not sure which did it, I suspect the latter.https://docs.xcp-ng.org/guides/pfsense/
Issue resolved.