Mar 14 05:55:59 firewall ipmon[93]: 05:55:59.732958 fxp2 @0:15 b 66.72.225.120,60331 -> 216.52.88.53,80 PR tcp len 20 52 -A IN Mar 14 05:55:59 firewall ipmon[93]: 05:55:59.733319 fxp2 @0:15 b 66.72.225.120,60331 -> 216.52.88.53,80 PR tcp len 20 152 -AP IN
I have three different subnets on my opt1. opt1 is bridged to wan.
I would like to allow all traffic within opt1 so my servers can talk to each other. Everything works except one strange case. If one server is set up for only ips on one subnet and another server is set up with ips on another subnet, they can talk together just fine.
I have some servers on opt1 that are set up with ips from two subnets. The problem is when one server tries talking to another server that has multiple subnets on it.
In the example firewall log above, 66.72.225.120 is trying to talk to 216.52.88.53 but it doesn't work because 216.52.88.53 is on a server that was originally set up with a 66.72.225.x ip and then the 216.52.88.53 was also added.
From the outside, all servers are reachable and everything works. The only problem is this special case above.
QUESTION - Can anyone help me figure out what the rule is above that is blocking this traffic and what I can do to fix it? I have tried setting up allow all rules on both wan and opt1 and that doesn't even work so it seems like some default rule is blocking it.
|