• PFSense without NAT: no internet connectivity from LAN

    2
    1 Votes
    2 Posts
    2k Views
    johnpozJ

    And did you setup your ISP router to nat these networks?  Since your not natting them on pfsense?  You also have a asymmetrical setup here for devices to to and with devices in your lab..

    192.168.10.0/24: LAN, for normal machines
    192.168.20.0/24: DEV, for dev/test machines
    192.168.30.0/24: SRV, for servers made available to the internet

    Your best solution here is to just put your isp modem/router into bridge mode and use pfsense as your edge router/firewall.  Or just double nat..  I have yet to see a soho gateway from an ISP that allows you to nat other networks other than the one that is its lan, etc.

  • Internet connectivity drops after using speedtest

    6
    0 Votes
    6 Posts
    778 Views
    A

    The capacity of the virtual drive I use for pfSense is 5GB and honestly I don't see why I should use a larger capacity than what I have now.
    Therefore, the reason why I couldn't see the drive to install 2.3.x was not the capacity of the drive or the controller since I've tried all the resolutions I found in here.

    I suppose that the real question here is the unsupported version I'm using and not the issue I'm having even though sometimes issues are continued through versions until they are reported and fixed.

    Anyone can see that my setup is a bit of unique with 5 WAN connections over DHCP and I this is why I raised my question. Otherwise, no one else has an issue like this using a single or dual wan with real static IP's.
    What I will try though, is to disable all the other WAN ports and perform a speedtest having only 1 LAN and 1 WAN.

  • Bridge and GIF tunnel

    2
    0 Votes
    2 Posts
    1k Views
    E

    What, nobody knows how this supposed to work?

  • Default gateway switching priority + policy routing to a down gateway

    6
    0 Votes
    6 Posts
    2k Views
    luckman212L

    Sorry for not being more specific in my last comment, but that PR#3609 is only for 2.4. In case anyone needs it, I made a version that applies clean to 2.3.3- you can grab it from this commit (apply in System Patches)

    https://github.com/luckman212/pfsense/commit/87d5f6579223410c629eddf5ca4386cb435e0a9e

  • GATEWAY WITH STRANGE READINGS!

    2
    0 Votes
    2 Posts
    560 Views
    H

    what is strange about it ?

    if you ping from you windows terminal to where ? to the monitor-ip ?

  • 2 Lan(s) network couldn't access each other.

    3
    0 Votes
    3 Posts
    569 Views
    Y

    Thank you so much, Windows's firewall on 192.168.0.110 was blocked incoming protocol from other sub net.
    Now, I can access to 192.168.0.110 via 192.168.2.0 sub net.  ;D

  • Understanding diffrences between em0 and WAN address

    7
    0 Votes
    7 Posts
    2k Views
    R

    So i just tried something and it seems to work. not sure if i was suppose to create a em0 interface when i created my pfsense router.

    1. Go to Interface -> assign
    2. assign em0 as only one with a vlan exist on WAN
    3. enable the interface em0
    4. go to Firewall rules and select the em0 tab
    5. create a rule to block all traffic.

    WAN_interface_4.png
    WAN_interface_4.png_thumb

  • 2 link same subnet with failover

    1
    0 Votes
    1 Posts
    367 Views
    No one has replied
  • Routing from WAN to DMZ (routing loop ?)

    12
    0 Votes
    12 Posts
    1k Views
    P

    Yes, you're right it's asymetrical.
    It's working now but we'll upgrade the pfsense with some NICs later…

    Thanks again.

  • Route internet traffic through webfilter

    1
    0 Votes
    1 Posts
    303 Views
    No one has replied
  • Correct DMZ setup

    7
    0 Votes
    7 Posts
    3k Views
    DerelictD

    Because, as you are finding out, the servers need to know how to route the different traffic. They can't just have a default gateway. You end up with asymmetric routing, hairpinning, NAT reflection, etc.

    Yes. That looks much, much better. Note that the web server no longer has any routing decisions to make. It just sends everything to the inside firewall and it makes all those decisions for it.

  • Guest Wifi Issues

    1
    0 Votes
    1 Posts
    404 Views
    No one has replied
  • How-To: 2.0 Load-Balance + Transparent Squid (3 easy steps)

    Locked
    36
    0 Votes
    36 Posts
    47k Views
    D

    Sir, this thread is about pfSense 2.0 and has been resting in peace for 4 years until you've summoned the zombies.

  • Pfsense and OVH Failover IPs

    1
    1 Votes
    1 Posts
    597 Views
    No one has replied
  • Sb8200 cable modem/2gig port

    3
    0 Votes
    3 Posts
    1k Views
    M

    cool cool johnpoz

    his internet plan is same as mine. 250down/25up

    comcast said needs biz account for another ip address.. he did get an F with bufferfloat was I fixed with traffic sharper..

    i just get the unifi hd 4x4 for my house well 2 of them.. i was hyped… but I'm happy...only around 700USD.. LOL...  replaced my ac pro 3x3.. single story 2100 sq all my kids are happy...

  • Resolved: Unidirection inter subnet routing problem

    8
    0 Votes
    8 Posts
    805 Views
    V

    As a workaround you may set up an SNAT rule for the AP. Maybe that's what also the USG did. I've seen this also on a Fortigate.

  • 0 Votes
    1 Posts
    558 Views
    No one has replied
  • Routing all traffic via VPN?

    2
    0 Votes
    2 Posts
    464 Views
    V

    Yes, you need a route on the client, but not static.
    The OpenVPN server can push the route to the client after the connection is established, when connection is closed the route is deleted again.

    To set this up go to the server settings and check "Redirect gateway".

    Ensure that there is an outbound NAT rule for the vpn tunnel subnet in place on pfSense with NAT address = WAN address.

  • Load balancing not working correctly upon reboot

    1
    0 Votes
    1 Posts
    329 Views
    No one has replied
  • 0 Votes
    3 Posts
    466 Views
    G

    Awesome! Thank you for your help!

    Now I just have to find out the IP Adresses for Steam and I'm fine :)

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.