Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    interface work al 80%

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @miami71it
      last edited by

      @miami71it so on your vpn server side.. Do you not have a local networks box?

      local.jpg

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply Reply Quote 0
      • M
        miami71it @johnpoz
        last edited by

        @johnpoz the local network is set up there
        but I don't understand why if I connect the external networks with the cable I see them if I connect with wifi, I only see the local and the external ones no

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @miami71it
          last edited by johnpoz

          @miami71it wouldn't matter what network your attached to on pfsense, if the remote networks are available via vpn connection.

          So you have this?

          setup.jpg

          And your server on HQ has listed both your 192.168.2 and 192.168.110 network.

          But client on 192.168.3 can not get to anything on 192.168.110 network? Can it get to pfsense IP on that network, 192.168.110.1?

          Or your saying device in 192.168.110 can not get to devices on 192.168.3? Can it ping the pfsense IP on the site 192.168.3.1?

          Or you say you can connect to 192.168.110 network with a wire and it works, but if wifi on 192.168.110 it does not work?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          M 1 Reply Last reply Reply Quote 0
          • M
            miami71it @johnpoz
            last edited by

            @johnpoz Yes, the network is made as you did the scheme. When I connect to wifi the dhcp gives me the 192.168.110.x network and I can ping the 192.168.2.x network but I don't pin the 192.168.3.x network, not even the site 1 network pfsense. LAN the dhcp gives me the ip 192.168.2.x and from there I can ping the network of site 1.

            H 1 Reply Last reply Reply Quote 0
            • H
              heper @miami71it
              last edited by

              @miami71it

              might be best to take screenshots of your firewall rules on the WIFI tab
              also screenshots of your VPN-server configuration.

              screenshots of the routing table on both pfsense might help.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Seems like you probably have a missing route to 192.168.110.x at the remote site.

                Bit it could also be a missing firewall rule somewhere.

                Steve

                M 1 Reply Last reply Reply Quote 0
                • M
                  miami71it @stephenw10
                  last edited by

                  @stephenw10 here are the rulesImmagine.png

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    And the rules and routes at the remote site?

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      miami71it @stephenw10
                      last edited by

                      @stephenw10 Immagine.png

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @miami71it
                        last edited by johnpoz

                        @miami71it this is not 192.168.110/24

                        wrong.jpg

                        So how would the site know to go back down the tunnel to get to 192.168.110? I specifically asked you this very question - and you said it was correct, clearly not from your screenshot.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          miami71it @johnpoz
                          last edited by

                          @johnpoz that ip is from another network
                          but sorry, but if I connect with the cable it works because it doesn't work with wifi? even without local network rules?

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Check Diag > Routes at the remote site. Does it have a route back to 192.168.110.x?

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @miami71it
                              last edited by

                              @miami71it said in interface work al 80%:

                              that ip is from another network

                              You are not telling your site where to go to get to a 192.168.110 network - so NO its never going to work - ever.. The site doesn't know how to get to a 192.168.110 network, so it sends it out its default gateway.

                              You tell it how to get to 192.168.2, so as I stated before tell it how to get to 192.168.110

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                miami71it @johnpoz
                                last edited by

                                @johnpoz sorry but I don't want to be insistent, I understand what you are saying, I have to put 192.168.110.0/24 in the local network, this is very clear to me but before doing it I wanted to understand how but if I connect with the LAN cable it works and with WIFI it doesn't, that was what I was trying to understand

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @miami71it
                                  last edited by

                                  @miami71it said in interface work al 80%:

                                  I have to put 192.168.110.0/24 in the local network

                                  When - sure wasn't in your screenshot

                                  If you plug in with a cable you are on the 192.168.2 network.. Sorry but with 192.168.3 site not knowing how to get to 192.168.110 there is no possible way it worked with a wire connected and client getting 192.168.110.x address..

                                  Doesn't matter if your wired or wireless, without a route to 192.168.110 there is no way it was working.

                                  If you plug in and get a 192.168.2.x address - then sure you told the other side how to get to 192.168..2 via coming down the tunnel.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  M 1 Reply Last reply Reply Quote 0
                                  • M
                                    miami71it @johnpoz
                                    last edited by

                                    @johnpoz 369 / 5.000
                                    Risultati della traduzione
                                    ok now you have clarified my ideas.
                                    in fact from site 1 in the remote network there is the network 192.168.2.x, so I have to put them also the 110, in practice it comes out like this
                                    192.168.2.0/24, 192.168.110.0/24

                                    doing so now I pingo

                                    I apologize again, I understood what you wanted me to do, but I wanted to understand the motivation, it is also done to learn :)
                                    now I have learned
                                    a thousand thanks

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Yup, a route must exist both ways. 😉

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.