<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Weird client pc behavior]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Last weekend I deployed a pfsense firewall to a company to protect their internal lan.<br />
Because they have many sites and in the future they want to use ipsec vpn between them,<br />
I have to change their internal lan subnet from 192.168.2.0/24 to 192.168.3.0/24 because<br />
other site uses the 192.168.2.0/24 subnet. And now the weird thing:<br />
after I put the the firewall in the network and I renumbered the LAN the original computers on LAN<br />
were not able to browse anyhing on the Internet except the companies mail server web interface (OWA) via https but other https based<br />
webpages did not come in. (computers getting ip from the correct range)</p>
<p dir="auto">My test notebook works well. With that on the same lan I can surf on the internet etc. etc.<br />
I have this default rule from LAN to WAN: <strong>allow any any</strong>. So everything should have worked but did not work.</p>
<p dir="auto"><strong>More weird:</strong> original PCs from local lan are able to communicate on other ports like TCP3389, DNS resolution also works, ICMP<br />
(ping) also works using with hostname or ip address to the WAN. I am suspecting that this is some virus activity but I do not<br />
know how to find information on the Internet about this.  ??? What I have not tried yet is netsh winsock reset on machines.</p>
<p dir="auto">Did anybody have same experience like this? (before ip renumbering everything worked)<br />
So it is definately not the pfsense what stops the traffic I can see in the logs that it is accepted and respones come back but<br />
the webpage does not show up in the browser. This happens all the machines in the lan.<br />
(not many approx. 5 machines: 4 windows xp and 1 windows 2008 server)</p>
<p dir="auto">Any help/response appreciated.<br />
klajosh</p>
]]></description><link>https://forum.netgate.com/topic/45396/weird-client-pc-behavior</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 11:11:11 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/45396.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 29 May 2012 12:15:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Weird client pc behavior on Sat, 02 Jun 2012 08:38:23 GMT]]></title><description><![CDATA[<p dir="auto">If your ISP limits to 1434, set both MTU and MSS to 1434 on that WAN.</p>
]]></description><link>https://forum.netgate.com/post/339669</link><guid isPermaLink="true">https://forum.netgate.com/post/339669</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Sat, 02 Jun 2012 08:38:23 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Sat, 02 Jun 2012 08:30:57 GMT]]></title><description><![CDATA[<p dir="auto">I forgot to tell that the internet link is a Wimax link. There<br />
is a cisco 850 router between the pfsense firewall and the<br />
whole world.</p>
]]></description><link>https://forum.netgate.com/post/339667</link><guid isPermaLink="true">https://forum.netgate.com/post/339667</guid><dc:creator><![CDATA[klajosh2]]></dc:creator><pubDate>Sat, 02 Jun 2012 08:30:57 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Sat, 02 Jun 2012 08:29:19 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">finally I found the problem. The problem was the MTU size on the ISP's backbone.<br />
They set it to <strong>1434</strong> and web browsing works fine. There is still one concern.<br />
From some networks I cannot reach the web interface of the pfsense but ssh works.<br />
I found out if I lower the mtu on WAN interface I can reach the web interface of pfsense<br />
from networks where I was not able to reach. My question what should I setup on WAN<br />
side to reach the webinterface of pfsense from everywhere? Or can someone send me<br />
a link about MTU settings? A good explanation? (now the MTU on WAN has its default<br />
value (<strong>1500</strong>).</p>
<p dir="auto">Thanks,</p>
<p dir="auto">klajosh</p>
]]></description><link>https://forum.netgate.com/post/339666</link><guid isPermaLink="true">https://forum.netgate.com/post/339666</guid><dc:creator><![CDATA[klajosh2]]></dc:creator><pubDate>Sat, 02 Jun 2012 08:29:19 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Wed, 30 May 2012 10:24:45 GMT]]></title><description><![CDATA[<p dir="auto">I'm afraid I'm out of ideas.  :(<br />
Your own laptop works OK but a freshly installed client does not? What's the difference?</p>
<p dir="auto">Generally speaking if you aren't seeing anything in the logs then it's usually a routing problem. Re-check your subnets and gateways. That doesn't explain why DNS, for example, works though.</p>
<p dir="auto">Do you have a managed switch on this network? Is it doing something odd?</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/339098</link><guid isPermaLink="true">https://forum.netgate.com/post/339098</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 30 May 2012 10:24:45 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Wed, 30 May 2012 07:53:49 GMT]]></title><description><![CDATA[<p dir="auto">I am still experiencing the same problem. A clean pc with freshly installed windows was brought there and showed the<br />
same symptoms. (everything worked but surfing on internet). what I tried so far:</p>
<ul>
<li>reduce the MTU on WAN side</li>
<li>I checked this option under System: Advanced: Firewall and NAT: Clear invalid DF bits instead of dropping the packets</li>
<li>on client machines netsh winsock reset did not help either.</li>
</ul>
<p dir="auto">I can see TCP:S from LAN to WAN what are allowed but nothing else.<br />
Please if you have any idea share with me.</p>
]]></description><link>https://forum.netgate.com/post/339081</link><guid isPermaLink="true">https://forum.netgate.com/post/339081</guid><dc:creator><![CDATA[klajosh2]]></dc:creator><pubDate>Wed, 30 May 2012 07:53:49 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Tue, 29 May 2012 16:13:59 GMT]]></title><description><![CDATA[<p dir="auto">I have checked that and there is no proxy setup in the browsers.</p>
]]></description><link>https://forum.netgate.com/post/338970</link><guid isPermaLink="true">https://forum.netgate.com/post/338970</guid><dc:creator><![CDATA[klajosh2]]></dc:creator><pubDate>Tue, 29 May 2012 16:13:59 GMT</pubDate></item><item><title><![CDATA[Reply to Weird client pc behavior on Tue, 29 May 2012 13:55:58 GMT]]></title><description><![CDATA[<p dir="auto">Windows policy lock down?<br />
Clients set to use a proxy?</p>
<p dir="auto">Could be a number of things.  :-\</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/338946</link><guid isPermaLink="true">https://forum.netgate.com/post/338946</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 29 May 2012 13:55:58 GMT</pubDate></item></channel></rss>