Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    connect subnets

    Scheduled Pinned Locked Moved Firewalling
    15 Posts 5 Posters 629 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cobain
      last edited by

      Hi, I need to allow connection between 2 subnets, the subnet 192.168.10.0/24 must authenticate to the authentication portal on the network 192.168.20.1/24

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @cobain
        last edited by

        @cobain
        So simply allow it by a firewall rule.
        We sadly don't know, what protocol and port your "authentication portal" is using. So we cannot tell you the details.

        Also ensure that the destination device is accepting access from the other subnet.

        C 1 Reply Last reply Reply Quote 0
        • C
          cobain @viragomann
          last edited by

          @viragomann

          Thank you
          The authentication portal uses port 8088.
          Could you give me more details, an example of how to declare the rule.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @cobain
            last edited by

            @cobain on OPT1 interface, allow from “OPT1 Network” to 192.168.20.5 port 8088. Or whatever the IP is.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            1 Reply Last reply Reply Quote 0
            • C
              cobain
              last edited by

              I'm sorry, but it doesn't work, I share an image of the rules that I defined. am i doing something wrong?rule.PNG

              J 1 Reply Last reply Reply Quote 0
              • J
                Jarhead @cobain
                last edited by

                @cobain LAN cannot be a source on the OPT interface.
                Reverse source and destination.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Jarhead
                  last edited by

                  @jarhead well clearly it can be ;) see that rule it has some evaluations the 0 / 9KB

                  Someone doesn't have actual isolation of their networks would be my guess ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    cobain @johnpoz
                    last edited by

                    @johnpoz Hello, could you explain to me what you mean?

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • C
                      cobain
                      last edited by

                      Hi, Is it possible to connect?SUBEREDES1.png

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        Jarhead @cobain
                        last edited by

                        @cobain Just reverse the source and destination on the OPT rule above.
                        The LAN can never be a source on any other interface so you have them backwards. The fact that that rule shows 0/9 means there was some traffic on it. You probably have your switch set wrong as the two subnets seem to be bleeding over.

                        C 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @cobain
                          last edited by johnpoz

                          @cobain in a correctly normal isolated networks, it would not be possible for anything other than that network to be source of traffic.

                          There is no possible scenario where this rule should see traffic

                          lansource.jpg

                          But as you can see this rule has seen some hits the 0/9 KB under states.. How would your 10.1.20 interface on pfsense see traffic from 10.1.1 into it?

                          The only way that could happen is if your networks are not actually isolated from each other.

                          The source on opt1 would be opt1 network, not lan net.. Looks like you pasted that opt1 in to the headings?

                          edit: the only time you would see non interface network traffic into an interface, is that interface was being used as a transit network. But lan net would never be into opt1 as a transit...

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          C 1 Reply Last reply Reply Quote 0
                          • C
                            cobain @Jarhead
                            last edited by

                            @jarhead Thanks, for the help, I already made the adjustments in the interfaces, but sadly I can't get there to be communication between those 2 subnets.
                            Do you have any other suggestions that could help me?

                            J 1 Reply Last reply Reply Quote 0
                            • C
                              cobain @johnpoz
                              last edited by

                              @johnpoz Thanks, for the help, I already made the adjustments in the interfaces, but sadly I can't get there to be communication between those 2 subnets.
                              Do you have any other suggestions that could help me?

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • J
                                Jarhead @cobain
                                last edited by

                                @cobain Well, if you did that correct it would work so you would have to provide pics of the config on the pfsense and switch.
                                You obviously have something misconfig'd.

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @cobain
                                  last edited by

                                  @cobain what are you rules.. please post up what you currently have set for lan and opt1

                                  If they are really any any rules, and you don't have any floating rules that would block. And your not policy routing traffic out some gateway, like your wan or some vpn then issue with clients not being able to talk is either they are not actually using pfsense as their gateway. The clients have the wrong mask on them, seen this quite a bit actually.. Where users set static IP on a client and use say a /16 mask.. So it thinks the other network/vlan is just local and never sends traffic to its gateway to get to the other network, or to answer traffic.

                                  Client firewalls is always big overlook by users..

                                  Wrong protocols for example - your rule there were lan was source to opt1 on opt1 interface was only tcp/udp - so no pinging even if the rule was correct wouldn't work..

                                  you can always sniff (packet capture on pfsense) to validate traffic is actually getting sent to pfsense on your lan for example, and then sniff on your opt1 interface to see that traffic is being sent on to your destination IP..

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.