Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Traffic blocked @1 @2 TCP:A TCP:PA by default

    Firewalling
    3
    10
    3814
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      HellMind last edited by

      I got a pfsense 2.0 runing on a esxi5
      The only way that I can make it work without conections timeouts and those firewall filter logs is, disabling the firewall filter

      Whats wrong?

      I tried everything , setting the fw to conservative

      I ve disabled tcp offloading and those stuff useless on a virtual environment

      I got 4 virtual interfaces connected to the same vswitch, its that the problem?

      1 Reply Last reply Reply Quote 0
      • C
        cmb last edited by

        That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).

        1 Reply Last reply Reply Quote 0
        • H
          HellMind last edited by

          @cmb:

          That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).

          Is there any tool to discover whats wrong?
          Cant be esxi?

          When you say whatever is causing that, what should I look  for?,  a broken switch?, a misconfigured virtual switch?,

          1 Reply Last reply Reply Quote 0
          • H
            HellMind last edited by

            How can be asymetric routing just just 1 router? and a single machine :S

            1 Reply Last reply Reply Quote 0
            • B
              biggsy last edited by

              I got 4 virtual interfaces connected to the same vswitch

              What does your ESXi network diagram look like?

              1 Reply Last reply Reply Quote 0
              • H
                HellMind last edited by

                Isnt complex


                1 Reply Last reply Reply Quote 0
                • B
                  biggsy last edited by

                  Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram?

                  You would have to VLAN the traffic if there's only one NIC.

                  1 Reply Last reply Reply Quote 0
                  • H
                    HellMind last edited by

                    @biggsy:

                    Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram?

                    You would have to VLAN the traffic if there's only one NIC.

                    I got just 1 iface

                    I think my hard doesnt allow for vlan

                    Also i tried with just 1 interface enabled, and its the same.

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb last edited by

                      @HellMind:

                      How can be asymetric routing just just 1 router? and a single machine :S

                      You don't need more than 1 router for that. You must have two anyway from the looks of that, you have something to get you out to the Internet. There isn't enough here to tell you where you're going wrong, need to know what NICs you have on the firewall, how they're being used in relation to the rest of the network.

                      1 Reply Last reply Reply Quote 0
                      • H
                        HellMind last edited by

                        I've just moved to routeros

                        Pfsense also present some stability issue on one of the boxes.
                        Using vmx3 should work better but using routeros with e1000 its better -_-

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post