<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Static Routes not working]]></title><description><![CDATA[<p dir="auto">Hello Team,</p>
<p dir="auto">I'm not sure whether it is an configuration problem or a bug. Currently I'm running 2.0.1-RELEASE (amd64)</p>
<p dir="auto">Here a short overview how our network looks like.</p>
<p dir="auto">Internal Net 192.168.0.0/16 -&gt; pfsense (192.168.0.254|172.24.2.1) -&gt; DMZ 172.24.2.0/26 -&gt; External Firewall (172.24.2.62) -&gt; Router -&gt; Internet</p>
<p dir="auto">This is working fine. There is an additional VPN Router in the DMZ with the IP 172.24.2.20 which has an established connection to one of our customers.</p>
<p dir="auto">The destination network behind this router is 10.236.18.112/29, so I  created the 172.24.2.20 as a gateway and created a static route under system -&gt; routing</p>
<p dir="auto">Screenshot: http://awesomescreenshot.com/0af6tsx82</p>
<p dir="auto">If I'm trying to communicate with the VPN, I can see the request on our external firewall, which is the default gateway. That shouldn't be the case if the static route would work. Is there anything todo in addition, that this will work?</p>
<p dir="auto">Log from our external firewall.<br />
<img src="http://www.abload.de/img/att01891fqm5w.png" alt="" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/45440/static-routes-not-working</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 02:16:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/45440.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 May 2012 16:02:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Static Routes not working on Mon, 04 Jun 2012 12:48:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cmb">@<bdi>cmb</bdi></a>:</p>
<blockquote>
<p dir="auto">Everything that passes out of a WAN interface (any interface with a gateway selected) gets routed to the WAN's gateway by default by the pass out rule, so if you have a static route on an interface with a gateway that goes somewhere other than the gateway on that interface, you need a floating rule to bypass said policy routing. Pass out on WAN from the appropriate source to the destination of the static route with no gateway selected with quick chosen.</p>
</blockquote>
<p dir="auto">Thanks, that did the trick :D</p>
]]></description><link>https://forum.netgate.com/post/339917</link><guid isPermaLink="true">https://forum.netgate.com/post/339917</guid><dc:creator><![CDATA[CaBaL2k]]></dc:creator><pubDate>Mon, 04 Jun 2012 12:48:29 GMT</pubDate></item><item><title><![CDATA[Reply to Static Routes not working on Mon, 04 Jun 2012 01:16:18 GMT]]></title><description><![CDATA[<p dir="auto">Everything that passes out of a WAN interface (any interface with a gateway selected) gets routed to the WAN's gateway by default by the pass out rule, so if you have a static route on an interface with a gateway that goes somewhere other than the gateway on that interface, you need a floating rule to bypass said policy routing. Pass out on WAN from the appropriate source to the destination of the static route with no gateway selected with quick chosen.</p>
]]></description><link>https://forum.netgate.com/post/339841</link><guid isPermaLink="true">https://forum.netgate.com/post/339841</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Mon, 04 Jun 2012 01:16:18 GMT</pubDate></item><item><title><![CDATA[Reply to Static Routes not working on Fri, 01 Jun 2012 14:59:45 GMT]]></title><description><![CDATA[<p dir="auto">I have to agree that result is unexpected, and pfsense appears to be ignoring your static route, unless you have snipped some redundant route from the routing table that you posted.</p>
]]></description><link>https://forum.netgate.com/post/339548</link><guid isPermaLink="true">https://forum.netgate.com/post/339548</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Fri, 01 Jun 2012 14:59:45 GMT</pubDate></item><item><title><![CDATA[Reply to Static Routes not working on Fri, 01 Jun 2012 10:57:13 GMT]]></title><description><![CDATA[<p dir="auto">Does anyone have an idea why it's not working?</p>
<p dir="auto">There must be something wrong with the routing if there are two gateways within the same zone:</p>
<p dir="auto">Internet:<br />
Destination        Gateway            Flags    Refs      Use  Netif Expire<br />
default            172.24.2.62        UGS         0  1940326    em1<br />
8.8.8.8            172.24.2.62        UGHS        0    15387    em1<br />
10.0.0.0/8         172.24.2.20        UGS         0   352985    em1<br />
127.0.0.1          link#8             UH          0      217    lo0<br />
[snip]</p>
<p dir="auto">[2.0.1-RELEASE][DGI@janus.debln01.loc]/home/DGI(11): traceroute 10.46.0.5<br />
traceroute to 10.46.10.5 (10.46.0.5), 64 hops max, 52 byte packets<br />
1  cerberus.dmz.debln01.loc (172.24.2.62)  0.397 ms  0.240 ms  0.214 ms<br />
2  ae0-17.frankfurt-1.celox.net (212.60.225.129)  1.724 ms  1.469 ms  1.960 ms<br />
3  bras2.ber.qsc.de (92.197.130.22)  7.110 ms  7.486 ms  7.969 ms<br />
4  core1.ber.qsc.de (87.234.13.141)  55.821 ms !N  40.591 ms !N  32.144 ms !N<br />
[2.0.1-RELEASE][DGI@janus.debln01.loc]/home/DGI(12):<br />
[snip]</p>
<p dir="auto">If I change the route from 172.24.2.20 into the other zone which is 192.168.0.0/16 it's working</p>
<p dir="auto">Internet:<br />
Destination        Gateway            Flags    Refs      Use  Netif Expire<br />
default            172.24.2.62        UGS         0  1981180    em1<br />
8.8.8.8            172.24.2.62        UGHS        0    15844    em1<br />
10.0.0.0/8         192.168.0.1        UGS         0   353213    em0<br />
127.0.0.1          link#8             UH          0      225    lo0</p>
<p dir="auto">[2.0.1-RELEASE][DGI@janus.debln01.loc]/home/DGI(17): traceroute 10.46.10.5<br />
traceroute to 10.46.10.5 (10.46.10.5), 64 hops max, 52 byte packets<br />
1  zeus (192.168.0.1)  0.397 ms  0.317 ms  0.212 ms<br />
2  pcdgi (192.168.10.53)  0.852 ms *  1.098 ms<br />
3  10.46.10.5 (10.46.10.5)  0.906 ms  1.264 ms  0.616 ms<br />
[2.0.1-RELEASE][DGI@janus.debln01.loc]/home/DGI(18):</p>
]]></description><link>https://forum.netgate.com/post/339506</link><guid isPermaLink="true">https://forum.netgate.com/post/339506</guid><dc:creator><![CDATA[CaBaL2k]]></dc:creator><pubDate>Fri, 01 Jun 2012 10:57:13 GMT</pubDate></item><item><title><![CDATA[Reply to Static Routes not working on Thu, 31 May 2012 08:28:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/clarknova">@<bdi>clarknova</bdi></a>:</p>
<blockquote>
<p dir="auto">Your attempt to connect to host 10.236.18.113 from the internal network is being passed by a firewall rule on pfsense's internal network interface. Can you identify this rule and determine whether it has a gateway defined?</p>
</blockquote>
<p dir="auto">It has no gateway defined, even if I configure there the gateway in explicit it doesn't change the behaviour.</p>
]]></description><link>https://forum.netgate.com/post/339305</link><guid isPermaLink="true">https://forum.netgate.com/post/339305</guid><dc:creator><![CDATA[CaBaL2k]]></dc:creator><pubDate>Thu, 31 May 2012 08:28:52 GMT</pubDate></item><item><title><![CDATA[Reply to Static Routes not working on Wed, 30 May 2012 16:22:45 GMT]]></title><description><![CDATA[<p dir="auto">Your attempt to connect to host 10.236.18.113 from the internal network is being passed by a firewall rule on pfsense's internal network interface. Can you identify this rule and determine whether it has a gateway defined?</p>
]]></description><link>https://forum.netgate.com/post/339182</link><guid isPermaLink="true">https://forum.netgate.com/post/339182</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Wed, 30 May 2012 16:22:45 GMT</pubDate></item></channel></rss>