You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think there are two issues here: first is the timeout which is global as you say; second is the toggle for 'Sticky Connections' which I believe also adds sticky-address to the outgoing rules.
Output of: pfctl -sr | grep stick:
pass in quick on em2 route-to { (em0 1.2.3.4), (em4 2.3.4.5) } round-robin sticky-address inet from 192.168.1.0/24 to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"
pass in quick on em2 route-to { (em0 1.2.3.4), (em4 2.3.4.5) } round-robin sticky-address inet from 192.168.2.0/24 to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"
pass in quick on em5 route-to { (em0 1.2.3.4), (em4 2.3.4.5) } round-robin sticky-address inet from 192.168.6.0/24 to any flags S/SA keep state label "USER_RULE: Allow LUNCHROOM IPv4 to Any"
*Note: WAN GW IP replaced with 1.2.3.4 and WAN2 GW IP replaced with 2.3.4.5
The description seems to imply this only applies to the load balancer, however I believe this also applies to outgoing gateway connections (see: https://forum.pfsense.org/index.php?topic=49054.msg260494#msg260494)
Whichever is the correct function needs to be clearly described, as this does not appear to be the case at the moment.
Image for reference, with some of the possibly unclear sections underlined.
PS: I hope I'm not nit-picking here, you are doing an excellent job with this fork!
The text was updated successfully, but these errors were encountered: