Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ping WAN VIP from LAN

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JointTech
      last edited by

      Hi -
      Awesome software, thanks.

      I am running into one small issue.  I setup VIPs on the WAN.  These are Proxy ARP.
      I setup Port Forwarding and the Rules to go with it.

      From outside the LAN I can access the resources no problem.

      From inside the LAN I can't even ping the VIPs.

      From inside the LAN I CAN access the services on the WAN ip.

      I have heard this called a loopback or hair-pining.  I've heard some routers don't do this.  But it seems I am doing this on the WAN IP just cant do it on the VIPs.

      I have the default allow LAN -> * rule.  Anywhere else I should be checking?

      Is Disable NAT Reflection relevant here?

      any help would be great.
      (this is not an emergency, I did not bring an untested firewall onsite to a client and now need immediate help with this free product.  I use it in my office and I like to try new things.

      I'm sick of seeing the paniced yells for help from people that didnt do their homework and now want some free support for the free product.)

      whew /RANT

      1 Reply Last reply Reply Quote 0
      • J
        JointTech
        last edited by

        heh

        Unchecked Disable NAT Reflection and it works.

        Strange that even though it was checked I could still do NAT reflection on the main IP.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          Are you really really sure that you can ping these VIP's now?
          Because it's NOT possible to ping proxy type VIP's.

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.