Project

General

Profile

Actions

Bug #4559

closed

Sync States causes sessions to NOT be NATed with multicast mac

Added by Sam Bingner about 9 years ago. Updated over 4 years ago.

Status:
Not a Bug
Priority:
High
Assignee:
-
Category:
XMLRPC
Target version:
-
Start date:
03/27/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
i386

Description

I am using Microsoft NLB for OWA. It uses a multicast MAC address for the cluster, which is fine as long as sync states is disabled.

When Synchronize States is enabled and both firewalls are online the following happens:

Connection establishes correctly, and some traffic passes. Eventually the connection stops NATing traffic out and pfsense sends the reply packet from the OWA server with a source address of it's internal localnet IP (192.168.0.20). This of course does not work properly as that is not allowed to travel back to the client over the internet, and it is not coming from the address the connection was established to in any case.

Using CARP maintenance mode on either firewall does not affect this. The only two cases where traffic continues to work properly is Synchronize States being unchecked or EITHER firewall being offline (reboot etc). Connecting through the same rules to another internal address that is not NLB also corrects this issue.

Yes, net.link.ether.inet.allow_multicast=1 is set on both firewalls.

Actions

Also available in: Atom PDF