Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Recommendations - large firewall sandwich deployment

    Scheduled Pinned Locked Moved General pfSense Questions
    27 Posts 3 Posters 9.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stevemitchell
      last edited by

      @sullrich:

      stevemitchell: sounds like pfsync is not syncing the states.  might want to double check on the backup node that you see the state size increasing to match close to the primary.   In terms of backup nodes, no, they will not process traffic in backup mode.

      I will check that - I had to take things out of the mix for now until I can figure out how I can maintain the source/internal address on the WAN side…

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by

        Use advanced outbound nat.

        Also might want to use static port depending on your apps in use internally.

        1 Reply Last reply Reply Quote 0
        • S
          stevemitchell
          last edited by

          @sullrich:

          Also might want to use static port depending on your apps in use internally.

          I did switch to the advanced outbound NAT and things seem to be showing up source address-wise correctly.

          Why would I want to use static ports?  Are you thinking of apps that don't like to be translated or routed?

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by

            By default PF scrambles the source port so if your applications are expecting the traffic on a specific source port it might  confuse them.

            1 Reply Last reply Reply Quote 0
            • S
              stevemitchell
              last edited by

              A gotcha.  Any way to disable that?  I saw various options that sounded like they might do that…

              1 Reply Last reply Reply Quote 0
              • S
                sullrich
                last edited by

                Advanced outbound nat, edit interface entry, click use static port.

                1 Reply Last reply Reply Quote 0
                • S
                  sullrich
                  last edited by

                  I am on vacation now and will be slow to respond.  Hopefully the book can help you in the meantime.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.