Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Traffic blocked @1 @2 TCP:A TCP:PA by default

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      HellMind
      last edited by

      I got a pfsense 2.0 runing on a esxi5
      The only way that I can make it work without conections timeouts and those firewall filter logs is, disabling the firewall filter

      Whats wrong?

      I tried everything , setting the fw to conservative

      I ve disabled tcp offloading and those stuff useless on a virtual environment

      I got 4 virtual interfaces connected to the same vswitch, its that the problem?

      1 Reply Last reply Reply Quote 0
      • C Offline
        cmb
        last edited by

        That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).

        1 Reply Last reply Reply Quote 0
        • H Offline
          HellMind
          last edited by

          @cmb:

          That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).

          Is there any tool to discover whats wrong?
          Cant be esxi?

          When you say whatever is causing that, what should I look  for?,  a broken switch?, a misconfigured virtual switch?,

          1 Reply Last reply Reply Quote 0
          • H Offline
            HellMind
            last edited by

            How can be asymetric routing just just 1 router? and a single machine :S

            1 Reply Last reply Reply Quote 0
            • B Offline
              biggsy
              last edited by

              I got 4 virtual interfaces connected to the same vswitch

              What does your ESXi network diagram look like?

              1 Reply Last reply Reply Quote 0
              • H Offline
                HellMind
                last edited by

                Isnt complex

                Untitled.png
                Untitled.png_thumb

                1 Reply Last reply Reply Quote 0
                • B Offline
                  biggsy
                  last edited by

                  Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram?

                  You would have to VLAN the traffic if there's only one NIC.

                  1 Reply Last reply Reply Quote 0
                  • H Offline
                    HellMind
                    last edited by

                    @biggsy:

                    Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram?

                    You would have to VLAN the traffic if there's only one NIC.

                    I got just 1 iface

                    I think my hard doesnt allow for vlan

                    Also i tried with just 1 interface enabled, and its the same.

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      cmb
                      last edited by

                      @HellMind:

                      How can be asymetric routing just just 1 router? and a single machine :S

                      You don't need more than 1 router for that. You must have two anyway from the looks of that, you have something to get you out to the Internet. There isn't enough here to tell you where you're going wrong, need to know what NICs you have on the firewall, how they're being used in relation to the rest of the network.

                      1 Reply Last reply Reply Quote 0
                      • H Offline
                        HellMind
                        last edited by

                        I've just moved to routeros

                        Pfsense also present some stability issue on one of the boxes.
                        Using vmx3 should work better but using routeros with e1000 its better -_-

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.