<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[static are not used when trying to communicate between 2 pfsense CE]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I've got a strange issue in my configuration. I have 1 pfsense use for openvpn client and another pfsense for a local network. I also got a gateway internet which is the default GW for both pfsense. Static route were created to make openvpn client ping the LAN behind the other pfsense without going to the gateway internet. Fallback routes were also created. But when a vpn client ping the LAN behind the other pfsense the echo reply request go through the gateway internet even I had static route... !</p>
<p dir="auto">Here is a small explanation with a diagram :<br />
<a href="/assets/uploads/files/1751356997690-capture-d-%C3%A9cran-du-2025-07-01-09-38-02.png">Capture d’écran du 2025-07-01 09-38-02.png</a></p>
<p dir="auto">Did anyone had an issue like that ?</p>
]]></description><link>https://forum.netgate.com/topic/197992/static-are-not-used-when-trying-to-communicate-between-2-pfsense-ce</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 00:37:00 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/197992.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Jul 2025 08:04:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to static are not used when trying to communicate between 2 pfsense CE on Tue, 01 Jul 2025 16:41:35 GMT]]></title><description><![CDATA[<p dir="auto">Ok I tried your solution, and it's ok. Really thank you, for the solution and for the explaination. I really don't like doing thing without understanding what I'm doing and why.</p>
<p dir="auto">One more time Thank you</p>
]]></description><link>https://forum.netgate.com/post/1219336</link><guid isPermaLink="true">https://forum.netgate.com/post/1219336</guid><dc:creator><![CDATA[urbantao]]></dc:creator><pubDate>Tue, 01 Jul 2025 16:41:35 GMT</pubDate></item><item><title><![CDATA[Reply to static are not used when trying to communicate between 2 pfsense CE on Tue, 01 Jul 2025 15:13:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/urbantao">@<bdi>urbantao</bdi></a><br />
No, it's a feature of pfSense.</p>
<p dir="auto">reply-to is useful in a multi-WAN setup, where multiple upstream gateways are connected multiple interfaces and each specified in the respective interface settings.</p>
<p dir="auto">pfSense uses the WAN rule, which allows the incoming traffic to tag the connection with the gateway assigned to the respective interface. With this pfSense can route response packets back to the proper gateway, no matter if it's the default upstream gateway.</p>
<p dir="auto">However, in your setup two gateway are connected to a single interface. Hence this does not work for you, because pfSense routes the response packets to the upstream gateway (which is assigned to the WAN) and you have to disable reply-to for traffic from the VPN router.</p>
]]></description><link>https://forum.netgate.com/post/1219330</link><guid isPermaLink="true">https://forum.netgate.com/post/1219330</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Tue, 01 Jul 2025 15:13:19 GMT</pubDate></item><item><title><![CDATA[Reply to static are not used when trying to communicate between 2 pfsense CE on Tue, 01 Jul 2025 14:59:24 GMT]]></title><description><![CDATA[<p dir="auto">Oh thx for the hint !</p>
<p dir="auto">Your suspicious is exactly what you describe. But I don't understand why ? Is that a bug or a mistake from me ?</p>
]]></description><link>https://forum.netgate.com/post/1219329</link><guid isPermaLink="true">https://forum.netgate.com/post/1219329</guid><dc:creator><![CDATA[urbantao]]></dc:creator><pubDate>Tue, 01 Jul 2025 14:59:24 GMT</pubDate></item><item><title><![CDATA[Reply to static are not used when trying to communicate between 2 pfsense CE on Tue, 01 Jul 2025 13:06:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/urbantao">@<bdi>urbantao</bdi></a><br />
I suspect, that the response packets are sent to the upstream gateway anyway due to reply-to tagging.</p>
<p dir="auto">You should be able to circumvent this by editing the rule, which allow access from VPN on the WAN. In the advanced options you can check  "Disable reply-to".<br />
If you have multiple rules on WAN move this one up to the top.</p>
<p dir="auto">Alternatively you can disable reply-to globally by checking<br />
<em>System &gt; Advanced &gt; Firewall &amp; NAT &gt; Disable reply-to</em>.</p>
]]></description><link>https://forum.netgate.com/post/1219307</link><guid isPermaLink="true">https://forum.netgate.com/post/1219307</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Tue, 01 Jul 2025 13:06:42 GMT</pubDate></item></channel></rss>