<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[All fragment reassemble]]></title><description><![CDATA[<p dir="auto">Здравствуйте. Недавно установил pfsense и начались проблемы.</p>
<p dir="auto">Есть 3 сети: 192.168.0.0/24 (<strong>LAN0</strong>), 192.168.1.0/24(<strong>LAN1</strong>), 192.168.2.0/24(<strong>LAN2</strong>). Схема такая:<br />
WAN–pfesnse--LAN0--vyatta_router--LAN1<br />
                                                  --LAN2</p>
<p dir="auto">Проблема возникает при доступе из LAN1 в LAN0. В Lan1, выборочно от 1 до 3 компьютеров, не могут попасть на файл сервер в Lan0 и на почтовый сервер(хотя отправка писем работает, а прием нет).<br />
В firewall появляется такая надпись:</p>
<pre><code>@1 scrub on re0 all fragment reassemble
@1 block drop in log all label "Default deny rule"
</code></pre>
<p dir="auto">Если сделать с проблемного компьютера пинг в Lan0, то все начинает работать нормально, кроме почты и то некоторое время, потом опять пропадает доступ.<br />
Помогите, пожалуйста, куда копать?</p>
<p dir="auto">PS Current state count: 810<br />
Заранее спасибо за помощь.</p>
]]></description><link>https://forum.netgate.com/topic/52442/all-fragment-reassemble</link><generator>RSS for Node</generator><lastBuildDate>Fri, 11 Sep 2026 00:46:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/52442.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 29 Jan 2013 06:08:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to All fragment reassemble on Wed, 30 Jan 2013 11:52:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/basta63">@<bdi>basta63</bdi></a>:</p>
<blockquote>
<p dir="auto">Спасибо, но там решения нет.</p>
</blockquote>
<p dir="auto">Что значит нет решения ? Читаем и переводим :</p>
<blockquote>
<p dir="auto">If you really want to bypass both the rules and the states, you could try adding floating rules to pass the traffic from that machine in and out on lan and wan with a state type of "no state"</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/375790</link><guid isPermaLink="true">https://forum.netgate.com/post/375790</guid><dc:creator><![CDATA[werter]]></dc:creator><pubDate>Wed, 30 Jan 2013 11:52:52 GMT</pubDate></item><item><title><![CDATA[Reply to All fragment reassemble on Tue, 29 Jan 2013 18:18:53 GMT]]></title><description><![CDATA[<p dir="auto">Спасибо, но там решения нет.<br />
И да, я решил свою проблему, необходимо было поставить галочку Static route filtering &lt;-Firewall/NAT &lt;-Advanced.</p>
]]></description><link>https://forum.netgate.com/post/375637</link><guid isPermaLink="true">https://forum.netgate.com/post/375637</guid><dc:creator><![CDATA[basta63]]></dc:creator><pubDate>Tue, 29 Jan 2013 18:18:53 GMT</pubDate></item><item><title><![CDATA[Reply to All fragment reassemble on Tue, 29 Jan 2013 11:48:33 GMT]]></title><description><![CDATA[<p dir="auto">http://forum.pfsense.org/index.php?topic=33562.0</p>
]]></description><link>https://forum.netgate.com/post/375545</link><guid isPermaLink="true">https://forum.netgate.com/post/375545</guid><dc:creator><![CDATA[werter]]></dc:creator><pubDate>Tue, 29 Jan 2013 11:48:33 GMT</pubDate></item></channel></rss>