Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 8 Jul 2019 09:53:22 -0700
From:      Michael Sierchio <kudzu@tenebras.com>
To:        "freebsd-net@freebsd.org" <freebsd-net@freebsd.org>
Subject:   Re: Bridge Not Forwarding ARP
Message-ID:  <CAHu1Y72BjAgrM6=gFAJK6D9drAqda_oKz1V=cA4Ex18=fdFAQQ@mail.gmail.com>
In-Reply-To: <CAPW8bZ2NaXB24p1mtH=A2f8ZukTPn7%2BPKXwUN2F0Osrn0exYNw@mail.gmail.com>
References:  <CAPW8bZ2NaXB24p1mtH=A2f8ZukTPn7%2BPKXwUN2F0Osrn0exYNw@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
What's your firewall ruleset look like?  (show, don't tell)

What does sysctl report on the interfaces and on arp?





On Mon, Jul 8, 2019 at 9:15 AM Dan Lists <lists.dan@gmail.com> wrote:

> I have a server running FreeBSD 11.2 that I am wanting to use as a bridge=
d
> firewall.  I have it set up and it mostly works.   The problem is that AR=
P
> replies are not being forwarded from the outside interface to the inside
> interface.   It appears to be working in the other direction.  I see the
> ARP request go out on the outside interface and the reply arrives back at
> the outside interface.   The ARP reply is never getting to the bridge or =
to
> the inside interface.
>
> The firewall server and the device behind it are in ESX.   I think I've
> worked all the ESX issues out.  When I manually add an ARP entry everythi=
ng
> works.   I've done this before with a physical server running FreeBSD 8.4
> and it works as expected.   The differences are physical vs virtual, and
> 8.4 vs 11.2.
>
> I'm at a loss as to why it is not working.   I've searched the web and
> found noting.  If anyone could offer suggestions on how to fix this or
> begin to debug it I would greatly appreciate it.
>
> Thanks,
>
> Dan
> _______________________________________________
> freebsd-net@freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-net
> To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
>


--=20

"Well," Brahm=C4=81 said, "even after ten thousand explanations, a fool is =
no
wiser, but an intelligent person requires only two thousand five hundred."

- The Mah=C4=81bh=C4=81rata



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAHu1Y72BjAgrM6=gFAJK6D9drAqda_oKz1V=cA4Ex18=fdFAQQ>