• No routing between internal networks with multi-wan?

    3
    0 Votes
    3 Posts
    473 Views
    DerelictD
    Bypassing policy routing is a known requirement in that case. It is not a bug nor a problem. https://doc.pfsense.org/index.php/Bypassing_Policy_Routing It sounds like that you have done should suffice. If it still does not work you are probably going to actually post what you have done so we can see where you went wrong. Keep in mind that rule changes do not affect existing states. Make your changes and clear states to be sure.
  • Considering Netgate to replace Zyxel - configuration question

    3
    0 Votes
    3 Posts
    471 Views
    T
    Thanks Chris.  That's what I though.  Looks like it's the 4-port firewall for me. Have any jokes about TCP?  I'm sure I would get those.
  • Multiple LAN routing trusted to untrusted?

    2
    0 Votes
    2 Posts
    362 Views
    V
    Such a setup is a basic feature of pfSense. pfSense filters the traffic usually on that interface where it comes in. So you would have filter rules on both LANs which allow any to any for internet access (default rule on LAN). Now you have only to set a block rule with destination = trusted LAN network on the top of the untrusted LAN rule set.
  • Pace 5268AC with AT&T and Pfsense (Co-Existance) - Make it work

    2
    0 Votes
    2 Posts
    3k Views
    A
    Dureal99d - Does this create a double NAT situation, or any issues with port forwarding from PFsense to internal Servers?
  • Routing between interfaces.

    10
    0 Votes
    10 Posts
    2k Views
    Z
    Hi. This is sorted.. it appears my son had a route in his NAS that was sending all traffic mouth over his PIA VPN.. He's now added a route for 192.168.1.0/24 back to the pfSense box and I can now access it fine from my LOAN PC. Thanks for your help.
  • Simple multi wan setup, managing what host uses what wan

    1
    0 Votes
    1 Posts
    315 Views
    No one has replied
  • Firewall not Routing Traffic

    7
    0 Votes
    7 Posts
    1k Views
    R
    @viragomann: There are only three things left to check: The network settings on clients and on pfSense (DHCP if used). Ensure that the network mask is set correctly and that the gateway is the pfSense LAN address. The firewall rules. But if you haven't changed anything there should still exist the default allow any-to-any rule on LAN. The outbound NAT. But in default settings, it should work also. There should exist a rule with source = LAN network and translation = WAN address. If that doesn't help you can check the routes on the client and run packet capture on pfSense to find out if packets destined for a web address arrive on the LAN interface. Tripled checked and all looks good.  A clean install using default settings should work right out of the gate, but for some reason doesn't.  I guess pfSense simply doesn't like this box for whatever reason.  Just odd that the firewall itself can reach the internet and not a single client can do the same.
  • Multi wan on 1 ethernet card one port

    1
    0 Votes
    1 Posts
    345 Views
    No one has replied
  • MultiWan on VLAN and Subnets

    2
    0 Votes
    2 Posts
    543 Views
    DerelictD
    https://doc.pfsense.org/index.php/Bypassing_Policy_Routing
  • CARP, MultiWAN, L2TP/PPP Interface

    3
    0 Votes
    3 Posts
    442 Views
    B
    Nobody?
  • Advice on multi nic setup

    2
    0 Votes
    2 Posts
    989 Views
    johnpozJ
    Bring your interface up on pfsense, give it a network that does not overlap your lan network.  Are you really using a /16 on your lan??  Seems bit much.. So lets say create 192.168.10/24 on your other interface (opt1) and you call this wifi or something. Then connect your AP to this interface.. If you want other ssids to be on different vlans.  Then you would create vlans on pfsense, assign them to the interface (em2?)  Then on your AP create the other SSIDs using the same vlan ID, lets call it 100 that you used when you created the pfsense vlan. That really is all there is too it.  Other than creating rules on your opt and any vlan interfaces that allow the traffic you want.  And enabling dhcp on the interface and vlan interfaces as you see fit. Why would you try creating a bridge?  You would have ZERO reason to do this, and if you wanted your AP or specific ssid of your AP to be on your lan network then connect your AP to your switch..
  • VPN NOT WORKING

    2
    0 Votes
    2 Posts
    519 Views
    jimpJ
    How exactly did you setup OpenVPN? The logs are cut off so I can't see it all, but it looks like it's saying the OpenVPN server is not using a Server Certificate ("unsupported certificate purpose")
  • Dual WAN and destination website routing

    2
    0 Votes
    2 Posts
    365 Views
    F
    Anyone? :)
  • MULTI-WAN HA Bandwidth Usage happening only on one WAN

    11
    0 Votes
    11 Posts
    813 Views
    K
    I do have natted ip routed only to WAN2 … and all personal devices too routed to WAN2 .... and the rest to WAN1+WAN2 .... i just finish adding a failover to WAN group .... so now VLAN 3 to 23 are on MULTIWAN and VLAN24 to 62 are on WAN2 hopefully this is increase the utilization on WAN2 .... LAN GOUP 1 = VLAN3 to 23 = MULTIWAN LAN GROUP2 = VLAN24 to 62 = WAN2 (FAILOVER ENABLED) and regarding services we have unbound and snort packages running on our pfsense ....
  • PfSense WAN access via VLAN

    6
    0 Votes
    6 Posts
    2k Views
    J
    It works! I removed the port group (VLAN ID1) in VMware. And I had to apply the VLAN configuration on port 2. [image: mybBuk] https://ibb.co/mybBuk Thanks for your help!
  • Have static routes slowed down with pfsense?

    14
    0 Votes
    14 Posts
    1k Views
    C
    Go away John. PS I reread this thread.  My pfsense has a point to point network to my layer 3 switch. There is no asymmetrical network.  pfsense forwards all traffic to my layer 3 switch so the L3 switch can route it. All my web pages now pop faster on the screen when using the RV320 router than when using my pfsense router on an old Xeon server motherboard.  Two years ago when I tested pfsense using testing web pages it was as fast or faster than the RV320 which now no longer holds true. So I have moved back to my old Cisco RV320 router. I just unplug one router and plug the other one in and I can tell the difference.  I do miss the time server in pfsense.
  • Routed - ripv2 configure

    6
    0 Votes
    6 Posts
    3k Views
    P
    Thank you for help. We use static routing earlier but from time to time something is change so we want enable any routing protocol. Cisco routers also use ripv2. I resolved my problem. I added parameter "passive" in /etc/gateways to interface which i don't want advertise.
  • DNS keeps failing on my multiwan setup even though a gateway is up.

    1
    0 Votes
    1 Posts
    411 Views
    No one has replied
  • Route outside VPN IPSec

    1
    0 Votes
    1 Posts
    385 Views
    No one has replied
  • OpenVPN Gateway is offline, but everything works

    2
    0 Votes
    2 Posts
    657 Views
    jimpJ
    Probably this, assuming you're on net30 topology which you appear to be: https://doc.pfsense.org/index.php/Why_can%27t_I_ping_some_OpenVPN_adapter_addresses Disable monitoring for that, or make sure you have a route pushed for the tunnel network and then setup a monitor address for .1 in the tunnel network, which might work.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.