News: This forum is now permanently frozen.
Pages: [1]
Topic: Traffic blocked to servers with multiple subnets  (Read 1473 times)
« on: March 14, 2009, 14:15:49 »
bjseiler *
Posts: 3

Mar 14 05:55:59 firewall ipmon[93]: 05:55:59.732958 fxp2 @0:15 b 66.72.225.120,60331 -> 216.52.88.53,80 PR tcp len 20 52 -A IN
Mar 14 05:55:59 firewall ipmon[93]: 05:55:59.733319 fxp2 @0:15 b 66.72.225.120,60331 -> 216.52.88.53,80 PR tcp len 20 152 -AP IN


I have three different subnets on my opt1.  opt1 is bridged to wan. 

I would like to allow all traffic within opt1 so my servers can talk to each other.  Everything works except one strange case.  If one server is set up for only ips on one subnet and another server is set up with ips on another subnet, they can talk together just fine.

I have some servers on opt1 that are set up with ips from two subnets.  The problem is when one server tries talking to another server that has multiple subnets on it.

In the example firewall log above, 66.72.225.120 is trying to talk to 216.52.88.53 but it doesn't work because 216.52.88.53 is on a server that was originally set up with a 66.72.225.x ip and then the 216.52.88.53 was also added.

From the outside, all servers are reachable and everything works.  The only problem is this special case above.

QUESTION - Can anyone help me figure out what the rule is above that is blocking this traffic and what I can do to fix it?  I have tried setting up allow all rules on both wan and opt1 and that doesn't even work so it seems like some default rule is blocking it.
« Reply #1 on: March 14, 2009, 14:48:33 »
bjseiler *
Posts: 3

FYI - I have tried to use this function in Advanced

Bypass firewall rules for traffic on the same interface

But I'm not sure I had static routes set up.  If not, could somebody help with how I need to setup the static routes?  These are the networks -

216.xx.80.96/27

66.xx.225.97/27

216.xx.88.32/27

« Reply #2 on: March 15, 2009, 14:40:15 »
bjseiler *
Posts: 3

Assuming no easy answer to my problem above, is there any way to remove the default block all rule just on my opt1 interface?  I think it is the default rule that is blocking my internal traffic and though not ideal, I'd rather just allow all traffic within opt1 than continue to have this problem.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines