Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Possible bug?

    General pfSense Questions
    3
    4
    1274
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Steve Mustafa last edited by

      I found something pretty strange today.

      Setting up the rules correctly, I still wasn't able to ping between two completely independent subnets, connected to the pfsense box. Until I bridged them, but once I unbridged them, they still work.  Rules work properly, since one of the subnets is the DMZ, I cannot access the LAN from there but certainly the other way around (again, as per the rules)

      ASCII art:

      WAN –------ PFSense ----------LAN 192.168.1.0/22
                              |
                              |
                              ---------------DMZ 10.0.0.0/24  (I refer to this as the Orange subnet)

      rules:

      LAN

      Proto   Source Port Destination   Port   Gateway   Schedule
      *          LAN net    *    Orange net  *          *

      Orange

      Proto   Source Port Destination   Port   Gateway   Schedule
      *          LAN net    *    Orange net  *          *

      Of Course, the subnets are defined as Aliases and they're right.

      TIA

      1 Reply Last reply Reply Quote 0
      • GruensFroeschli
        GruensFroeschli last edited by

        Your rule on the DMZ interface doesn't make much sense.
        (LAN-subnet as source on an interface without LAN-subnet IPs).
        Also did you reset the states between tests?

        1 Reply Last reply Reply Quote 0
        • S
          Steve Mustafa last edited by

          Sorry for the incredibly late reply, but by the time you answered I had left the office and then the next day I had surgery. 
          So sorry.

          For some odd reason, if both rules are not in place, traffic will not move between the networks. I tried that till I got googly-eyed becaue I found it baffling.

          No, I didn't reset the tables, but on Saturday (first day I get back to work) I'll be sure to try it then.

          Cheers.

          1 Reply Last reply Reply Quote 0
          • jimp
            jimp Rebel Alliance Developer Netgate last edited by

            When you make a bridge, it is not fully destroyed until you reboot, even if you disable it in the GUI.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense Plus
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy