Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 2100 - setup question

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    67 Posts 6 Posters 10.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      netboy @netboy
      last edited by

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • N
        netboy @netboy
        last edited by

        @netboy OK

        Removed BLOCK rule from LAN interface and included this

        03bbbffe-c685-4481-bf5f-fd62b4196f45-image.png

        Shall I apply this and test?

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          That will work. I would set the protocol to 'any' though to include ping etc.

          N 1 Reply Last reply Reply Quote 0
          • N
            netboy @stephenw10
            last edited by

            @stephenw10
            This is what my firewall rules are now

            ffab19ef-907c-4408-baf5-341cb8399198-image.png

            Did a ping test and works - does not block!

            dc6486c4-a245-4073-b6ed-de112a365a8b-image.png

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yeah, you have to test from a device in the IOP4 subnet. Pings generated from pfSense itself do not get filtered by those firewall rules. Only outbound rules would be applied and by default everything is allowed outbound.

              Steve

              N 1 Reply Last reply Reply Quote 0
              • N
                netboy @stephenw10
                last edited by

                @stephenw10

                Looks like a SUCCESS!

                36935045-399a-4d94-85c5-e5a463109977-image.png

                Thank yo Stephenw10 and all others

                N 1 Reply Last reply Reply Quote 1
                • N
                  netboy @netboy
                  last edited by

                  @netboy Able to ping from 192 subnet to 172

                  a864c39d-fc04-4a67-9714-a93057a04abe-image.png

                  I think I have to thank everybody in this forum. Netgate 2100 Max is a fantastic router though pricey.

                  I shall seek further help if need be.

                  Thank you everybody

                  N 1 Reply Last reply Reply Quote 1
                  • N
                    netboy @netboy
                    last edited by

                    @netboy I am documenting below "how I made my printers work over the network in windows 10"

                    My printers are in 172.16.0.XXX subnet and my computers are in 192.168.0.XXX subnet. 192.168.0.XXX can talk to (ALLOW) 172.16.0.XXX but not vice versa.

                    The first thing I did was connected my computer to 172 subnet and configure the printers.

                    I then connected my computers to 192 subnet and used the windows tool to configure TCP/IP printers and gave the "static" IP address of the printers and it worked.

                    N 1 Reply Last reply Reply Quote 1
                    • N
                      netboy @netboy
                      last edited by netboy

                      @netboy I am back! I have one problem. Let me explain.

                      My NAS has 2 NIC's one on 192.168.0.XXX (PvT) subnet & another172.16.0.XXX (IoT) subnet.

                      Now I want to:

                      • Create a GROUP with a List of MAC address that are in my 172.16.0.XXX (IoT) subnet hat can access my NAS (which is also in 172.16.0.XXX (IoT) ) [ MACgroupAllow ]

                      • Firewall rule : ALLOW MACgroupAllow access to my NAS MAC XX.XX.XX.XX and

                      • BLOCK all traffic within my subnet 172.16.0.XXX (IoT) in accessing my NAS MAC XX.XX.XX.XX

                      This is my existing firewall rules in IoT subnet

                      9c512398-caec-460d-ad89-c2dc1b2831f9-image.png

                      Does it make sense? I am not sure I have explained my functionality well .

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        That would need to be done on the NAS dircetly. Traffic between clients on the IoT subnet and the NAS IP address also in the IoT subnet does not go through pfSense, it just goes directly. So pfSense cannot filter it.

                        With that said pfSense is a layer 3 firewall so filtering MAC addresses (layer 2) is not something it's is setup to do. You can do something like that by setting fixed dhcp leases for each MAC and then filtering by those IPs. But only for traffic passing the firewall.

                        Steve

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          netboy @stephenw10
                          last edited by netboy

                          @stephenw10 OK got it!

                          Question.

                          I want to edit my Hostname and Description on certain MAC's listed under "DHCP Leases" - I am aware you can click the "pencil" icon to the right but I DO NOT want a static IP but only want to edit the Hostname and Description and maintaining the "non-static" nature. How do I go about doing it?

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            You can add a static lease entry without an IP address and it will just use a dynamic IP from the pool. But you end up with two lease entries like:

                            Screenshot from 2022-11-02 17-15-02.png

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • F
                              FSC830
                              last edited by

                              In my DHCP leases the correct hostname is displayed, so I am wondering, why you want to modify the hostname entry in DHCP leases?
                              This sounds as all (or at least multiple) devices using the same hostname.
                              Therefore my approach would be to set the hostnames at the devices in a way so you can differ in DHCP leases which host is actually obtaining a lease.

                              Regards

                              N 1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Yes, the hosts usually send the hostname as part of the DHCP request. Setting a description for each host is about the only reason I could imagine doing this.

                                1 Reply Last reply Reply Quote 0
                                • N
                                  netboy @FSC830
                                  last edited by

                                  @fsc830 My hostname are blanks and I have no idea what they are?

                                  1 Reply Last reply Reply Quote 1
                                  • F
                                    FSC830
                                    last edited by

                                    Hostnames are blank!??
                                    Which kind of devices are you using?
                                    Never seen a blank hostname in my LAN. Every new device I installed has had at least some kind of generic name, i.e. Samsung XXX (smartphone) or FOSCAMxyz (IP cam).

                                    And usually you can set an individual hostname during setup or later in network/system settings.

                                    Regards

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      SteveITS Galactic Empire @FSC830
                                      last edited by

                                      @fsc830 FWIW, I just pulled up my leases page at home and the eeros (static lease) have no hostname shown, and 8 other devices (mostly IoT) show the IP in the hostname field.

                                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                      Upvote 👍 helpful posts!

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        It's quite common for appliance style devices to not send a hostname. Or to send a hostname that doesn't help much. Using static leases with an appropriate description works around that.

                                        1 Reply Last reply Reply Quote 0
                                        • F
                                          FSC830
                                          last edited by

                                          Thanks for both answers, do not use IoT or appliance style devices here (at least not yet). 😊

                                          Regards

                                          1 Reply Last reply Reply Quote 0
                                          • N netboy referenced this topic on
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.