On Sat, Nov 29, 2008 at 10:34 PM, DLStrout <[EMAIL PROTECTED]> wrote:
> So let's see if I am getting this ....
>
> If the "intermediate router" sees the "destination
> address" as part of its "connected network" then
> it passes the packet to the destination directly.
> Then the destination host sees its "default
> gateway" as the pfSense box and passes the return
> traffic to it and lets it route accordingly ...
> I'm assuming that's what you mean by asymmetric
> routing.
>

yes


> So if I dedicate interfaces on the pfSense boxes
> to the "intermediate" router then that takes all
> the reflective routing capabilities away right?
>

Your asymmetric routing goes away if the router is off a different
interface on pfSense from the clients.  As far as I know, "reflective
routing" is a term you made up (google it - your threads using it are
the first 5 hits), so I won't comment on that.  :)


> I understand that asymmetric routing is NOT a best
> practice - nor the preferred method, but in some
> cases I'd think it is appropriate, but I do see
> what you mean.

I didn't say it was bad, it's unavoidable a lot of the time. You just
can't statefully filter traffic in that scenario.

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Commercial support available - https://portal.pfsense.org

Reply via email to