• OSPF + static routes does not work

    1
    0 Votes
    1 Posts
    297 Views
    No one has replied
  • Connecting to AWS

    1
    0 Votes
    1 Posts
    501 Views
    No one has replied
  • Second Wan Down

    1
    0 Votes
    1 Posts
    280 Views
    No one has replied
  • Do I need a Route from Lan to WAN

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ

    @chriss199815 said in Do I need a Route from Lan to WAN:

    I use it to segregate the Network in a clean fasson.

    That would be accomplish with say 10.0.0/24 and 10.0.1/24, or say 10.0.0/24 and 172.16.0/24 ;)

    What ya going to do if you use 10/8 and 192.168/16 and 172.16/12 for your 3 segments if you happen to need a 4th segment ;)

    rfc1918 is huge amount of space - but not so much if you use up one of the 3 network ranges on 1 segment...

    Well if your clients are not getting dhcp from pfsense, it would indicate they are not actually connected to a pfsense network - and then yeah that would explain why they can not get to the internet through pfsense ;)

    So you see no dhcp discover in pfsense logs? How exactly do you have pfsense and clients connected to your network? Is there some VM involved?

  • Routing remote access (OVPN) to peer-to-peer (OVPN) subnet

    3
    0 Votes
    3 Posts
    452 Views
    T

    Thanks!
    I'll check situation according your advice.

  • Multi Wan and PFSense Updates

    7
    0 Votes
    7 Posts
    800 Views
    LeeGardnerL

    Hello,
    I am a newcomer,
    I have just updated, I am still waiting...

  • Send Traffic from 1 host to a specific GW

    25
    0 Votes
    25 Posts
    2k Views
    S

    @smalldragoon said in Send Traffic from 1 host to a specific GW:

    anything in PFSense preventing RFC1918

    Each interface has a "Block private networks and loopback addresses" checkbox but that would normally be for inbound traffic.

  • Policy routing to access subnet of a gateway marked as down

    8
    0 Votes
    8 Posts
    784 Views
    B

    @viragomann I think this is the best approach. Initially I thought I would like to route other vms through it, but pfsense is taking care about all the traffic, so I'll definitely try this out :)

  • Routing between LAN fails, traceroute shows traffic goes to WAN ONLY

    9
    0 Votes
    9 Posts
    959 Views
    johnpozJ

    @dkyyz said in Routing between LAN fails, traceroute shows traffic goes to WAN ONLY:

    Firewall rules are like routing rules (not sure if my wording is correct)

    If you policy route with them sure..

    https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html#bypassing-policy-routing

  • Sharing static IP addresses

    1
    0 Votes
    1 Posts
    323 Views
    No one has replied
  • Routing public IP range

    1
    0 Votes
    1 Posts
    387 Views
    No one has replied
  • Openvpn tunnel -- > Home network-->NordVPN-->Internet

    2
    0 Votes
    2 Posts
    386 Views
    V

    @cb4718
    If NordVPN is your default route ("Don't pull routes" unchecked in the client settings) the access server OpenVPN tunnel should be routed to NordVPN as well.

    If it isn't and you're routing the traffic to NordVPN using policy routing rules you have also to set up policy routing on the OpenVPN interface for the tunnel network.
    Consider that you will also need to add an outbound NAT rule to the NordVPN interface for the tunnel network.

  • Modification of routing table causes network flashover

    1
    0 Votes
    1 Posts
    181 Views
    No one has replied
  • Netgate 1100 OPT (how to configure VLAN)

    2
    0 Votes
    2 Posts
    718 Views
    S

    @thomasyang If you want them on the same network, see this doc on Configuring the Switch Ports. Alternatively, plug a switch into LAN and then you have four ports.

  • Multi-WAN - what happens when both monitors go down?

    1
    0 Votes
    1 Posts
    193 Views
    No one has replied
  • Configuration example for dual firewall setup needed

    5
    0 Votes
    5 Posts
    2k Views
    B

    @johnpoz There are no hosts on 10.43.0.0/24. This network is just used for the link between FW1 and FW2 via crossover cable (FW1 NIC Port 3 (IP 10.43.0.1) to FW2 NIC Port 2 (IP 10.43.0.2)).

    That VPN Box is eventually misplaced. OpenVPN is actually running on the OPNsense box.

    ... I may have just figured out what was missing in this very moment, after some more try & error and your response. I can ping FW1 from FW2. The reason seems to be that for the crossover cabling the option "This interface does not require an intermediate system to act as a gateway" needed to be enabled on the interface. I will give some further feedback after more testing.

    Edit: My bad, That was just a terrible mistake when testing. I still cannot reach FW2 from FW1 or vice versa. Do I need to setup a gateway?

  • Route Failover

    1
    0 Votes
    1 Posts
    341 Views
    No one has replied
  • Multi-WAN speed drops to single-WAN speed at random

    5
    0 Votes
    5 Posts
    884 Views
    A

    BUMP

  • Routing only specific ports over OpenVPN

    3
    0 Votes
    3 Posts
    539 Views
    B

    For anyone else who has this idea, I think it's a bigger pain than is warranted. I did more reading on libtorrent. The ports in the normal option menu of torrent clients are listen ports. When a connection is made and you seed a torrent, libtorrent uses dynamic outbound ports. You can set these as static, often using obscure options, but the libtorrent devs suggest not doing so as it can cause issues with establishing connections.

    So instead of doing all that and possibly having connection issues I will just be containerizing the torrent client on my server, using macvlan to give it a dedicated IP on my LAN, then routing that IP over the VPN interface using PBR.
    As for the other torrent clients on random computers on my LAN, it's probably best we stop using those and just use my server's client. Or we can use the VPN client on those computers.

  • Routing and Policy Routing, who is first?

    1
    0 Votes
    1 Posts
    207 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.