Host 1:1 NAT in DMZ and slow access from LAN

  • hi, I have an ftp server in DMZ which has 1:1 NAT with a VIP on WAN.
    accessing this host with its private IP from LAN is very slow, like if traffic was outgoing from WAN and then coming back in, as I have the same speed I could expect from the WAN link itself.

    I activated AON, I have only two rules which NAT WAN and WAN2 for LAN subnet, NAT reflection is actually disabled.

    what could I be doing wrong?


  • Are you using the trafficshaper? If yes your reflected traffic will be shaped as well.

  • unfortunately no, I'm not running the traffic shaper..

  • well, rebooting pfsense for another task has also fixed this..

