Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Firewalling» Traffic blocked @1 @2 TCP:A TCP:PA by default
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: Traffic blocked @1 @2 TCP:A TCP:PA by default  (Read 1267 times)
0 Members and 1 Guest are viewing this topic.
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« on: May 17, 2012, 05:37:32 pm »

I got a pfsense 2.0 runing on a esxi5
The only way that I can make it work without conections timeouts and those firewall filter logs is, disabling the firewall filter

Whats wrong?

I tried everything , setting the fw to conservative

I ve disabled tcp offloading and those stuff useless on a virtual environment

I got 4 virtual interfaces connected to the same vswitch, its that the problem?
Logged
cmb
Administrator
Hero Member
*****
Offline Offline

Posts: 6049


View Profile WWW
« Reply #1 on: May 18, 2012, 01:46:34 am »

That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).
Logged

pfSense Commercial Support

Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #2 on: May 18, 2012, 03:19:42 am »

That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).
Is there any tool to discover whats wrong?
Cant be esxi?

When you say whatever is causing that, what should I look  for?,  a broken switch?, a misconfigured virtual switch?,
Logged
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #3 on: May 19, 2012, 03:58:36 am »

How can be asymetric routing just just 1 router? and a single machine :S
Logged
biggsy
Full Member
***
Offline Offline

Posts: 208


View Profile
« Reply #4 on: May 19, 2012, 06:37:41 am »

Quote
I got 4 virtual interfaces connected to the same vswitch

What does your ESXi network diagram look like?
Logged
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #5 on: May 19, 2012, 03:07:34 pm »

Isnt complex
Logged
biggsy
Full Member
***
Offline Offline

Posts: 208


View Profile
« Reply #6 on: May 19, 2012, 04:56:33 pm »

Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram? 

You would have to VLAN the traffic if there's only one NIC.

Logged
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #7 on: June 02, 2012, 05:27:39 pm »

Do you have only that one NIC in your ESXi host or did you just cut off the bottom of diagram?  

You would have to VLAN the traffic if there's only one NIC.


I got just 1 iface

I think my hard doesnt allow for vlan

Also i tried with just 1 interface enabled, and its the same.

« Last Edit: June 02, 2012, 05:47:13 pm by HellMind » Logged
cmb
Administrator
Hero Member
*****
Offline Offline

Posts: 6049


View Profile WWW
« Reply #8 on: June 03, 2012, 07:57:52 pm »

How can be asymetric routing just just 1 router? and a single machine :S

You don't need more than 1 router for that. You must have two anyway from the looks of that, you have something to get you out to the Internet. There isn't enough here to tell you where you're going wrong, need to know what NICs you have on the firewall, how they're being used in relation to the rest of the network.
Logged

pfSense Commercial Support

Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
HellMind
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #9 on: June 04, 2012, 12:53:50 am »

I've just moved to routeros

Pfsense also present some stability issue on one of the boxes.
Using vmx3 should work better but using routeros with e1000 its better -_-
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.027 seconds with 20 queries.