• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Internet inaccessible after updating to 2.5.2

General pfSense Questions
internet inaccessible at&t 2.5.2
6
8
1.5k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Serintysw
    last edited by Jul 10, 2021, 11:00 PM

    I upgraded from 2.4.5 to 2.5.2 today, and after a reboot lost all internet connectivity on my devices and on the whitebox pfsense router itself. I have my pfsense router behind a 5268AC AT&T router in DMZPlus mode. I'm no networking expert, but have validated / tried the following:

    1. The public IP address is being assigned correctly to the pfsense router.

    2. I tried rebooting both the pfsense and at&t routers.

    3. Restoring from a previous config

    4. Pinging 8.8.8.8 on the pfsense router (100% loss)

    5. Doing a speed test on the AT&T router (success)

    6. Switching my PC to the AT&T router to see if there was internet access (there is)

    7. Factory reset on pfsense router

    8. Clean install on pfsense router

    I'm really frustrated at this, but I know I don't have the knowledge to solve this myself. Are there any steps I can take to resolve this? It's been working for at least a year with no hiccups until now. I severely regret updating.

    1 Reply Last reply Reply Quote 0
    • S
      senseivita
      last edited by Jul 11, 2021, 5:32 AM

      Hey me too! From 2.4.5p3 to 2.5.2. It was a nightmare, tunnels connected but didn't pass traffic. DNS gone. It blocked all traffic basically β€” except to the firewall itself β€” even the #1/ICMP/anyβ†”οΈŽany/pass on all interfaces and IPv6 which doesn't need NAT. I thought NAT might be responsible.

      I reverted just now, the 2.4.5p3 snapshot, it's still checking backups consistency, I increased it to 1000 so it takes a while.

      Little tip: if you have the ability to use snapshots (i.e; virtual machine) use them instead of backups. The packages from the pkg manager are updated too when a new base system is out. Although if you're good with the CLI and FreeBSD you might be able tot get them from the FreeBSD repos. :)

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      S 1 Reply Last reply Jul 11, 2021, 11:42 AM Reply Quote 0
      • S
        stephenw10 Netgate Administrator @senseivita
        last edited by Jul 11, 2021, 11:42 AM

        @skilledinept said in Internet inaccessible after updating to 2.5.2:

        Although if you're good with the CLI and FreeBSD you might be able tot get them from the FreeBSD repos. :)

        All the 2.4.5 packages still exist you just need to set the update branch to '2.4.X deprecated'.

        @Serintysw that sounds like it could be no default route or a bad default route for some reason.

        pfSense is able to pull a public IP using DHCP? And can ping the gateway IP? But nothing beyond that?

        Steve

        S 1 Reply Last reply Jul 11, 2021, 1:25 PM Reply Quote 0
        • B
          bcruze
          last edited by Jul 11, 2021, 1:16 PM

          go to system > routing

          make sure default gateway for ip4 is not set to Automatic.. but wan.

          if you do not use Ip6 change it to none

          good luck!

          1 Reply Last reply Reply Quote 0
          • S
            senseivita @stephenw10
            last edited by Jul 11, 2021, 1:25 PM

            @stephenw10 said in Internet inaccessible after updating to 2.5.2:

            All the 2.4.5 packages still exist you just need to set the update branch to '2.4.X deprecated'.

            That's cool, I don't remember having that option available back then, it was a while, I think the first 2.4. I can't stop storing VM templates now.

            @Serintysw totally sounds like the routes you might get better sense of things it you ping by segments, i.e; instead of going all the way to a public server just check you get echo back from the next gateway, then a client to pfSense, and then to the AT&T firewall and so on for as many hops as you have.

            You can add/remove routes from the console if you can't reach remotely. They're temporary so they need to be added on the GUI again so they stick.

            πŸ”’ Log in to view

            It turns out I was on 2.5.0 BTW, my bad. ο˜… It must've been 2.5.1 when NAT went crazy then.

            Good luck!

            Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

            A 1 Reply Last reply Jul 13, 2021, 4:13 AM Reply Quote 0
            • A
              avi1962 @senseivita
              last edited by Jul 13, 2021, 4:13 AM

              @skilledinept
              Check this. I had a problem like this. This item did not exist in version 2.4. LAN is set by default.
              πŸ”’ Log in to view

              S 1 Reply Last reply Jul 31, 2021, 10:33 AM Reply Quote 0
              • S
                senseivita @avi1962
                last edited by Jul 31, 2021, 10:33 AM

                Sorry about the silence. I installed a fresh 2.5.2 for a backup network and had no issues with it. Then upgraded again the same firewall I had problems in before and this time I just had to reorder a rule or two and changed them back to force them to reload and it's been working OK now.

                That WAN interface circled there is for the proxy settings not for the system. The system's in System β†’ Routing.

                Furthermore, the proxy bypasses all of your rules making it much harder to diagnose. Avoid setting up the proxy at least in the forced (transparent) or automated (WPAD) ways until you're sure what interfaces are handling your traffic. When the proxy takes in the traffic it disappears from your firewall's view [maybe] until it exits an interface. pfSense filter/logs inbound traffic on each interface, not outbound. The result is that you don't see the traffic or the rule that's allowing it to pass.

                When or if you have your network back up already, I recommend you become fully aware of your network by setting split horizon DNS and unchecking all of these in System β†’ Advanced β†’ Firewall & NAT:

                πŸ”’ Log in to view
                πŸ”’ Log in to view

                It makes your network (and yourself) super reliable.

                Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

                1 Reply Last reply Reply Quote 0
                • M
                  mrpushner
                  last edited by Jan 3, 2022, 5:44 PM

                  Hi, So you are saying that "reordering you FW rules" then putting them back the way they were fixed you issue with not being able to access the internet after the update to 2.5.2?

                  MP

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.