So let's see if I am getting this .... If the "intermediate router" sees the "destination address" as part of its "connected network" then it passes the packet to the destination directly. Then the destination host sees its "default gateway" as the pfSense box and passes the return traffic to it and lets it route accordingly ... I'm assuming that's what you mean by asymmetric routing.
So if I dedicate interfaces on the pfSense boxes to the "intermediate" router then that takes all the reflective routing capabilities away right? I understand that asymmetric routing is NOT a best practice - nor the preferred method, but in some cases I'd think it is appropriate, but I do see what you mean. > > What you have is asymmetric routing. You can't state fully filter > traffic with any firewall if it's only seeing part of the connection. > --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] Commercial support available - https://portal.pfsense.org
