Dear List

When I traceroute to a server on the WAN subnet of pfsense, the traffic
is sent to the subnet's gateway first. This is not what I want. How do I
have to configure pfsense, that it sends local traffic to a locally
attached destination host on the WAN side directly? From the pfsense box
itself the server is addressed directly, but just not from traffic going
through pfsense:

>From a client inside to a server on the WAN subnet:
traceroute to sirup.3eck.net (212.71.113.109), 64 hops max, 52 byte packets
 1  kabeljau.3eck.net (212.71.113.98)  3.346 ms  2.703 ms  4.813 ms
 2  sirup.3eck.net (212.71.113.109)  2.870 ms  3.587 ms  2.905 ms
... I would expect first grosser-yoghurt (pfsense), then sirup. But the
first hop is the gateway of the WAN subnet.

Form the console of the pfsense box, same server:
traceroute to sirup.3eck.net (212.71.113.109), 64 hops max, 52 byte packets
 1  sirup.3eck.net (212.71.113.109)  0.213 ms  0.203 ms  0.185 ms

>From a client through an IPCop Firewall (natter), same server:
 1  natter (192.168.254.5)  2.512 ms  2.120 ms  2.063 ms
 2  sirup.3eck.net (212.71.113.109)  1.517 ms  1.740 ms  5.076 ms


Some Info on my setup:

Two pfsense 2.1-BETA1 (amd64) built on Sat Jan 19 running carp
Gateway fail-over

The situation is not only with traceroute packets, it with all traffic
from the inside LAN. This is odd, because WAN subnet, pfsense and LAN
are 1Gbit/s and the WAN GW only has a 100Mbit/s connection. Like this
the speed gets reduced for LAN to local WAN traffic.


Any help to configure pfsense right is appreciated.

Thank you!

Best regards, Adrian.



_______________________________________________
List mailing list
[email protected]
http://lists.pfsense.org/mailman/listinfo/list

Reply via email to