I placed fxp0 and external intf (reth0) into the same IP subnet.
VPN is up, but I don't see any lan-2-lan
In my icmp.log i see the following:
Feb 27 11:15:21 11:15:21.298644:CID-1:RT:'external-interface'(reth0.0) and 'routing-interface'(fxp0.0) belong to different zones. Re-route failed, pkt dropped.
I can ping internet from fw as there are routes via df-gw, but seems anything via tunnel is being dropped. I havn't tried reverting fxp0's IP into some local again. This is just an experiement i.e. I know fxp0 should be isolatated and placed onto mgmt network.
does the messgae from icmp.log make any sense now?
-ajaz