So let's see if I am getting this ....

If the "intermediate router" sees the "destination
address" as part of its "connected network" then
it passes the packet to the destination directly. 
Then the destination host sees its "default
gateway" as the pfSense box and passes the return
traffic to it and lets it route accordingly ...
I'm assuming that's what you mean by asymmetric
routing.

So if I dedicate interfaces on the pfSense boxes
to the "intermediate" router then that takes all
the reflective routing capabilities away right?

I understand that asymmetric routing is NOT a best
practice - nor the preferred method, but in some
cases I'd think it is appropriate, but I do see
what you mean.

> 
> What you have is asymmetric routing. You can't
state fully filter
> traffic with any firewall if it's only seeing
part of the connection.
> 



---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Commercial support available - https://portal.pfsense.org

Reply via email to