• AWS VPC Routing and Positioning.

    2
    0 Votes
    2 Posts
    419 Views
    P
    OK, so lets try some more specific questions, should the pfsense instance be in one of those subnets, and I just write routing rules to give it access to the other subnets. Or do I create a fourth subnet (maybe public?) to give it access. Presumably I need to set up an interface in pfsense for each subnet? How do I do that in AWS - I'm a bit lost with their strange way of doing things. How do I limit access to certain subnets / machines on a user by user basis. Would I do that in pfsense or in AWS. What makes sense here. I'm guessing someone must have struggled with this environment before.
  • Subnet a subnet

    4
    0 Votes
    4 Posts
    737 Views
    johnpozJ
    You can always subnet a network down..  so that is a /23 so logical break would be /24, since your at 10.2.5 the break to /24 would create 10.2.4.0/24 and 10.2.5.0/24 Here is the thing.. What exactly are you going to do to subnet it down.. They are not routing that traffic to a routers of yours are they?  You are directly attached would be my assumption..  So unless you have some router in your classroom and they route that network to you via some other transit.. Then while sure its easy to subnet any network into smaller networks - your problem is more involved… And without more info its impossible to advice you what direction to go into. But if all you want is an isolated wifi network you could control - this would be as simple as connecting your typical wifi router which would nat the wifi clients to whatever IP it gets from your 10.2.5/23 network when you plug its wan in. Better would sure being this with pfsense box and some APs..  But any 20$ soho router you pick up at the computer store would be able to create an isolated wifi network on your current network.
  • Routing between Site-to-site VPN setups

    3
    0 Votes
    3 Posts
    397 Views
    B
    Doh! That's exactly what it was, thank you Derelict. Didn't even think about that. It's working great now. Thanks again! Brooks
  • Multiple routing tables by LAN address solution?

    1
    0 Votes
    1 Posts
    289 Views
    No one has replied
  • Help with google cloud, two separate offices, and telecommuters

    1
    0 Votes
    1 Posts
    328 Views
    No one has replied
  • Can't route between subnets

    4
    0 Votes
    4 Posts
    524 Views
    DerelictD
    Yes. Number that interface as 192.168.2.1/24, create the necessary firewall rules on that interface, and connect another switch to it.
  • MultiWAN. Cannot route specific traffic to specific gateway

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    Then your problem is upstream. pfSense cannot control which interface reply traffic arrives on. It can only control which interface is used for sending. Based on the information given so far…. You will need to provide a lot more details to make a real diagnosis.
  • 2 separate openvpn connections with no dns leaking?

    1
    0 Votes
    1 Posts
    292 Views
    No one has replied
  • Dual lan, bridging and filtering (plus fiber modem / router bypass)

    3
    0 Votes
    3 Posts
    736 Views
    P
    @ytn: Anyone have any ideas / suggestions? I am primarily trying to find a solution for the fiber modem bypass / bridging. Should I post this question in a different area? Thanks. I'm looking for the same solution but no one seems to have this worked out perfectly yet on pfSense that I can find.
  • Multi-wan and cradlepoint issue

    3
    0 Votes
    3 Posts
    380 Views
    chpalmerC
    My Cradlepoint goes offline regularly after not using it for a few hours.
  • Voip Telephones don't get connection

    1
    0 Votes
    1 Posts
    254 Views
    No one has replied
  • Multi Wan and wrong default gateway

    7
    0 Votes
    7 Posts
    2k Views
    J
    Hello, in my case I was able to solve it like this: I noticed that I did not need the VPN gateway, so I enabled gateway monitoring and also enabled it to always be off. So the VPN gateway in my case and to the present moment was not identified as default gateway –------- Olá, no meu caso consegui resolver do seguinte modo: Notei que eu não precisava do gateway da VPN, então habilitei o monitoramento do gateway e também habilitei para ficar sempre off. Assim o gateway da VPN no meu caso e até o presente momento não foi identificado como default gateway
  • Source routing to 2 gateways on same subnets

    13
    0 Votes
    13 Posts
    7k Views
    C
    so, check the "non local gateway" in routing>gateway of each gateway. Becoz you got multiple wan from one isp routing. pfsense non sense of gateway routing from one isp. make sure separate each gateway route. sorry for my bad english.
  • Routing in a pfSense

    1
    0 Votes
    1 Posts
    482 Views
    No one has replied
  • One WAN as Default gateway while using 3 WANs as load balancing

    5
    0 Votes
    5 Posts
    886 Views
    K
    Do note that traffic originating from the pfSense system itself will always use the default gateway. It's not possible to redirect locally originating traffic to a specific WAN connection or to a gateway group in pfSense/FreeBSD.
  • NON-transparent squid + multiwan failover

    1
    0 Votes
    1 Posts
    310 Views
    No one has replied
  • 3 WAN with load balancing n failover

    4
    0 Votes
    4 Posts
    1k Views
    A
    hi, Yes I have kept the weight settings as default. It was required if I do a load balance between WAN B(~9 Mbps) n WAN C (~5 Mbps). regards, Ashima
  • 2 LANSs - need mutual exclusivity

    4
    0 Votes
    4 Posts
    433 Views
    DerelictD
    Ugh. On LAN1 reject destination LAN2 network then pass what you want below it. On LAN1 reject destination LAN1 network then pass what you want below it. Do not attempt to block traffic with pass rules. Explicitly block the traffic you want blocked with block/reject rules. That said, your design is hosed. If you want 10.0.20.0/24 and 10.1.20.0/24 to be firewalled, they need to be separate firewall interfaces. You are probably going to need a managed switch and the ability to tag multiple VLANs to vmware to accomplish what you want. 2 LANSs - need mutual exclusivity You do not have two LANs. You have one LAN. Your hosts are out on the "WAN" as far as pfSense is concerned.
  • How can i do a Transfer Net

    3
    0 Votes
    3 Posts
    435 Views
    I
    Thank you very much! Now its working perfect. Many greets
  • Multi wan - mailserver on dmz - lan users can't access mail server

    2
    0 Votes
    2 Posts
    313 Views
    jahonixJ
    Your users are probably not accessing the mail server by its IP but via its hostname, right? (like mail.example.com) Have a look at split-DNS locally then.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.