Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    windows clients can only ping gateway

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 4 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elliopitas
      last edited by

      i have no idea why this happens but suddenly windows clients in my home lan can only ping the gateway. all android devices, smart tv, printers etc work fine.
      the windows pcs are being configured correctly with DHCP and other devices can ping them just fine. assigning IP manually doesn't change anything either.

      now I have 2 pfsense routers in my home. my edge router and my server router. if I connect any window PC on the server router that is connected to the edge router internet works just fine.
      i also have any allow any to all lan devices on firewall and i dont see any entries that they are being blocked
      e8f843ed-aeea-48cb-b947-874d6435a16a-image.png

      i haven't changed any configuration of any networking equipment for months other than this.
      https://forum.netgate.com/topic/172083/router-randomly-freezes/2?_=1654003495199

      S stephenw10S 2 Replies Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @elliopitas
        last edited by

        @elliopitas It's not a DNS issue? Have you tried pinging by IP e.g. 8.8.4.4?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        E 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator @elliopitas
          last edited by

          @elliopitas said in windows clients can only ping gateway:

          windows clients in my home lan can only ping the gateway.

          You mean the clients gateway? The pfSense LAN interface address? Or the ISP gateway address?

          Steve

          1 Reply Last reply Reply Quote 0
          • E
            elliopitas @SteveITS
            last edited by

            @steveits yea they can only ping the gateway IP address. they can't ping any local or network IP addresses

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              So the pfSense LAN interface address only?

              1 Reply Last reply Reply Quote 0
              • E
                elliopitas
                last edited by

                @stephenw10 said in windows clients can only ping gateway:

                So the pfSense LAN interface address only?

                yes

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  What error do you see if you try to ping some other device on the local subnet?

                  E 1 Reply Last reply Reply Quote 0
                  • E
                    elliopitas @stephenw10
                    last edited by

                    @stephenw10 said in windows clients can only ping gateway:

                    What error do you see if you try to ping some other device on the local subnet?

                    hmm I seen to fixed the local network somehow but i still get a timeout if i ping my other lan or the internet
                    here's also the routing table
                    alt text

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Do you see that traffic arriving and being passed by pfSense?

                      Start a continuous ping to, say, 8.8.8.8. Them check the pfSense state table in Diag > States. Filter it by 8.8.8.8 and make sure there are WAN and LAN states.

                      If there are no states then either that traffic is being blocked (should be in the firewall log) or it never arrives.

                      A common thing that can present like this is a rogue dhcp server on your network providing a bad gateway. Make sure pfSense shows your test client in the dhcp leases.

                      Steve

                      E 1 Reply Last reply Reply Quote 0
                      • E
                        elliopitas @stephenw10
                        last edited by

                        @stephenw10 said in windows clients can only ping gateway:

                        Do you see that traffic arriving and being passed by pfSense?

                        Start a continuous ping to, say, 8.8.8.8. Them check the pfSense state table in Diag > States. Filter it by 8.8.8.8 and make sure there are WAN and LAN states.

                        If there are no states then either that traffic is being blocked (should be in the firewall log) or it never arrives.

                        A common thing that can present like this is a rogue dhcp server on your network providing a bad gateway. Make sure pfSense shows your test client in the dhcp leases.

                        Steve
                        I can see that the device is leased a DHCP address from the server from DHCP leases tab. there are no states or any traffic from the specific client blocked but I did notice some strange entries but they ware there before this issue

                        b7dc1fbd-a705-4aab-972a-3463135041e6-image.png
                        I have no clue who 192.168.2.1 client is. and that address doesn't belong to any of my home networks
                        I only have 192.168.0.0/24 and 192.168.1.0/24

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Check the ARP table if it's locally attached. It really wants to use UPnP though. ๐Ÿ˜‰

                          If there are no states or blocked traffic from a test client and the error it shows is a timeout where is it sending pings?

                          You might have something blocking it and not logging like Snort or Suricata maybe?

                          E 1 Reply Last reply Reply Quote 1
                          • E
                            elliopitas @stephenw10
                            last edited by

                            @stephenw10 said in windows clients can only ping gateway:

                            Check the ARP table if it's locally attached. It really wants to use UPnP though. ๐Ÿ˜‰

                            If there are no states or blocked traffic from a test client and the error it shows is a timeout where is it sending pings?

                            You might have something blocking it and not logging like Snort or Suricata maybe?

                            it's not in the arp table.
                            i don't have anything like that. my LAN consists of 2 pfsense routers 4 ubiquity aps, 1 ap and unifi controller running on a raspberry pi

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Run a pcap. What MAC address is it coming from? If that's another router check there to see where it's being routed from.

                              Steve

                              E 1 Reply Last reply Reply Quote 0
                              • E
                                elliopitas @stephenw10
                                last edited by

                                @stephenw10 said in windows clients can only ping gateway:

                                Run a pcap. What MAC address is it coming from? If that's another router check there to see where it's being routed from.

                                Steve

                                I get

                                11:24:12.375776 c8:3a:35:f1:9f:08 > 01:00:5e:7f:ff:fa, ethertype IPv4 (0x0800), length 440: (tos 0x0, ttl 4, id 0, offset 0, flags [DF], proto UDP (17), length 426)
                                    192.168.2.1.3213 > 239.255.255.250.1900: [udp sum ok] UDP, length 398
                                11:24:12.483271 c8:3a:35:f1:9f:08 > 01:00:5e:7f:ff:fa, ethertype IPv4 (0x0800), length 440: (tos 0x0, ttl 4, id 0, offset 0, flags [DF], proto UDP (17), length 426)
                                    192.168.2.1.3213 > 239.255.255.250.1900: [udp sum ok] UDP, length 398
                                
                                

                                so the mac of the device is c8:3a:35:f1:9f:08 and the mac of the interface its trying to reach is 01:00:5e:7f:ff:fa right?
                                i cant find any device or interface in my arp and DHCP tables. checked manually some devices too to see if it was them and i can't find a device that matches this mac

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @elliopitas
                                  last edited by johnpoz

                                  @elliopitas said in windows clients can only ping gateway:

                                  01:00:5e

                                  Is a multicast mac your not going to find that in your arp table. But the other one c8:3a:35 is Tenda company, they make networking gear. https://www.tendacn.com/us/default.html

                                  
                                  MAC Address Details
                                  
                                  Company
                                      Tenda Technology Co., Ltd.
                                  Address
                                      Shenzhen Guandong 518057
                                      CHINA
                                  Range
                                      C8:3A:35:00:00:00 - C8:3A:35:FF:FF:FF
                                  Type
                                      IEEE MA-L
                                  
                                  
                                  

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  E 1 Reply Last reply Reply Quote 0
                                  • E
                                    elliopitas @johnpoz
                                    last edited by

                                    @johnpoz said in windows clients can only ping gateway:

                                    @elliopitas said in windows clients can only ping gateway:

                                    01:00:5e

                                    Is a multicast mac your not going to find that in your arp table. But the other one c8:3a:35 is Tenda company, they make networking gear. https://www.tendacn.com/us/default.html

                                    
                                    MAC Address Details
                                    
                                    Company
                                        Tenda Technology Co., Ltd.
                                    Address
                                        Shenzhen Guandong 518057
                                        CHINA
                                    Range
                                        C8:3A:35:00:00:00 - C8:3A:35:FF:FF:FF
                                    Type
                                        IEEE MA-L
                                    
                                    
                                    

                                    ok found the device and fixed it. but still the problem persists

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      If everything is configured with the same subnet size then your problem is probably in the switch. That traffic should be going directly between clients. If it's using wifi then check client isolation.

                                      Steve

                                      E 1 Reply Last reply Reply Quote 0
                                      • E
                                        elliopitas @stephenw10
                                        last edited by

                                        @stephenw10 said in windows clients can only ping gateway:

                                        If everything is configured with the same subnet size then your problem is probably in the switch. That traffic should be going directly between clients. If it's using wifi then check client isolation.

                                        Steve

                                        Wi-Fi isolation is not enabled, the clients can ping each other on Wi-Fi, and the switch is working fine since the printer and my linux laptop that are also connected to the same switch have no problems.
                                        i will back up configuration and reset the router I cant figure out what else to do

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          I wouldn't expect that to make any difference since that traffic doesn't go through the router at all.

                                          If other devices can ping them then they are able to reply. It's almost certainly some Windows issue locally.

                                          Steve

                                          1 Reply Last reply Reply Quote 0
                                          • E
                                            elliopitas
                                            last edited by

                                            ok so i solved the problem...
                                            idk why I didn't do this earlier but I checked the arp table of the computers that were not working and the mac didn't match my router.
                                            turns out that my brother's switch killed itself and decided to give itself statically the same IP as the router, arp poisoning the network so the computers could only access devices in the same subnet.
                                            idk why this affected only Windows devices

                                            1 Reply Last reply Reply Quote 2
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.