Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    connect subnets

    Scheduled Pinned Locked Moved Firewalling
    15 Posts 5 Posters 633 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @cobain
      last edited by

      @cobain on OPT1 interface, allow from “OPT1 Network” to 192.168.20.5 port 8088. Or whatever the IP is.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • C
        cobain
        last edited by

        I'm sorry, but it doesn't work, I share an image of the rules that I defined. am i doing something wrong?rule.PNG

        J 1 Reply Last reply Reply Quote 0
        • J
          Jarhead @cobain
          last edited by

          @cobain LAN cannot be a source on the OPT interface.
          Reverse source and destination.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Jarhead
            last edited by

            @jarhead well clearly it can be ;) see that rule it has some evaluations the 0 / 9KB

            Someone doesn't have actual isolation of their networks would be my guess ;)

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            C 1 Reply Last reply Reply Quote 0
            • C
              cobain @johnpoz
              last edited by

              @johnpoz Hello, could you explain to me what you mean?

              johnpozJ 1 Reply Last reply Reply Quote 0
              • C
                cobain
                last edited by

                Hi, Is it possible to connect?SUBEREDES1.png

                J 1 Reply Last reply Reply Quote 0
                • J
                  Jarhead @cobain
                  last edited by

                  @cobain Just reverse the source and destination on the OPT rule above.
                  The LAN can never be a source on any other interface so you have them backwards. The fact that that rule shows 0/9 means there was some traffic on it. You probably have your switch set wrong as the two subnets seem to be bleeding over.

                  C 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @cobain
                    last edited by johnpoz

                    @cobain in a correctly normal isolated networks, it would not be possible for anything other than that network to be source of traffic.

                    There is no possible scenario where this rule should see traffic

                    lansource.jpg

                    But as you can see this rule has seen some hits the 0/9 KB under states.. How would your 10.1.20 interface on pfsense see traffic from 10.1.1 into it?

                    The only way that could happen is if your networks are not actually isolated from each other.

                    The source on opt1 would be opt1 network, not lan net.. Looks like you pasted that opt1 in to the headings?

                    edit: the only time you would see non interface network traffic into an interface, is that interface was being used as a transit network. But lan net would never be into opt1 as a transit...

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      cobain @Jarhead
                      last edited by

                      @jarhead Thanks, for the help, I already made the adjustments in the interfaces, but sadly I can't get there to be communication between those 2 subnets.
                      Do you have any other suggestions that could help me?

                      J 1 Reply Last reply Reply Quote 0
                      • C
                        cobain @johnpoz
                        last edited by

                        @johnpoz Thanks, for the help, I already made the adjustments in the interfaces, but sadly I can't get there to be communication between those 2 subnets.
                        Do you have any other suggestions that could help me?

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • J
                          Jarhead @cobain
                          last edited by

                          @cobain Well, if you did that correct it would work so you would have to provide pics of the config on the pfsense and switch.
                          You obviously have something misconfig'd.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @cobain
                            last edited by

                            @cobain what are you rules.. please post up what you currently have set for lan and opt1

                            If they are really any any rules, and you don't have any floating rules that would block. And your not policy routing traffic out some gateway, like your wan or some vpn then issue with clients not being able to talk is either they are not actually using pfsense as their gateway. The clients have the wrong mask on them, seen this quite a bit actually.. Where users set static IP on a client and use say a /16 mask.. So it thinks the other network/vlan is just local and never sends traffic to its gateway to get to the other network, or to answer traffic.

                            Client firewalls is always big overlook by users..

                            Wrong protocols for example - your rule there were lan was source to opt1 on opt1 interface was only tcp/udp - so no pinging even if the rule was correct wouldn't work..

                            you can always sniff (packet capture on pfsense) to validate traffic is actually getting sent to pfsense on your lan for example, and then sniff on your opt1 interface to see that traffic is being sent on to your destination IP..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.