Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot Connect to the Internet, Unknown Rule on System Logs

    Scheduled Pinned Locked Moved Routing and Multi WAN
    18 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Rob893
      last edited by

      Hello there,

      First time Pfsense user here. I cannot connect to the internet using Pfsense.

      I do not think it is the ISP router I have the Pfsense router hooked up to because my Unifi switch and access points work perfectly fine if I plug them directly into the ISP router.

      Pfsense version: 2.6.0

      The specifications for the router:
      • Motherboard: Biostar J4125NHU with latest BIOS (February 2023)
      • CPU: Intel Celeron J4125
      • RAM: 2x4gb Corsair DDR4 memory
      • SSD: Team Group 256 Gb M.2 Nvme
      • NIC: Intel I350-T4

      The Topography:
      ISP Fiber router (Fiberhome Model HG6243C set to Bridge Mode) > PFsense router.
      The Unifi switch and access points were supposed come after the Pfsense router, but since I have yet to figure out how to get Pfsense to work, I have them plugged into the ISP router.

      I have consulted https://docs.netgate.com/pfsense/en/latest/troubleshooting/connectivity.html and what was strange on my system is that upon checking system logs> firewall, I got two constant messages
      • WAN Default deny rule IPv4 (1000000103)
      • WAN Default deny rule IPv6 (1000000105)

      Problem is, I checked the WAN Firewall Rule, and there were no rules set up yet (it’s a fresh install). No rule for floating, and on LAN, I have Action:Pass and Protocol:Any. So, I have no idea why these two messages keep popping up. And more importantly, why I can’t connect to the internet.

      Any help would be appreciated. Thank you.

      J S 2 Replies Last reply Reply Quote 0
      • J
        Jarhead @Rob893
        last edited by

        @rob893 Do you get an IP on the WAN?
        Did you try to power cycle the ISP's router after connecting pfSense?
        If it really is a router, are you getting a public IP or private?
        Try to disable blocking rfc1918 on the WAN. Go to interfaces/WAN and scroll to the bottom.

        R 2 Replies Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @Rob893
          last edited by

          @rob893 said in Cannot Connect to the Internet, Unknown Rule on System Logs:

          checked the WAN Firewall Rule, and there were no rules set up yet

          All interfaces have a hidden default deny rule, so traffic is blocked. LAN has an allow any rule for IPv4 and 6.

          Normally I turn off the option to log the default block rules which avoids a lot of unnecessary log entries:
          25e5e683-4f1f-43e1-8b62-d571da165819-image.png

          re: connectivity, can you ping by IP address? (ping 8.8.8.8)

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          R 1 Reply Last reply Reply Quote 0
          • R
            Rob893 @Jarhead
            last edited by

            @jarhead
            The WAN IP is 192.168.1.1, status is online, other services are running too
            Just tried power cycling the router like you suggested. Still no internet though
            Router is giving me a public IP
            Rfc1918 and Bogon have been disabled during the initial setup

            pf3.png

            S V 2 Replies Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @Rob893
              last edited by

              @rob893 said in Cannot Connect to the Internet, Unknown Rule on System Logs:

              Router is giving me a public IP

              192.168.1.1 is a private/RFC1918 IP.

              That shouldn't matter for connectivity out though. Try the ping 8.8.8.8 and if that works try nslookup/dig to see if DNS is working.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @Rob893
                last edited by

                @rob893 said in Cannot Connect to the Internet, Unknown Rule on System Logs:

                The WAN IP is 192.168.1.1, status is online, other services are running too

                Which WAN? The pfSense screen shows something different.

                Router is giving me a public IP

                Where? To which device??

                1 Reply Last reply Reply Quote 0
                • R
                  Rob893 @SteveITS
                  last edited by

                  @steveits Ah thanks for the tip! As for pinging 8.8.8.8, I was able to do it if I connect my laptop to the ISP router. But if I connect it to the Pfsense router, I get request time outs

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Rob893
                    last edited by

                    @rob893 said in Cannot Connect to the Internet, Unknown Rule on System Logs:

                    But if I connect it to the Pfsense router, I get request time outs

                    The question was if you can ping from pfSense itself.
                    Go to Diagnostic > Ping and try, please.

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      Rob893 @viragomann
                      last edited by

                      @viragomann @SteveITS Ah sorry, my mistake. But no, I was not able to ping 8.8.8.8
                      ping.png

                      V 1 Reply Last reply Reply Quote 0
                      • R
                        Rob893 @Jarhead
                        last edited by

                        @jarhead I meant to say, these have been unchecked
                        check.png

                        1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @Rob893
                          last edited by

                          @rob893
                          If assume, you didn't touch the outbound NAT settings yet and it is still in automatic mode (Firewall > NAT > Outbound)?

                          If so at least the ping should work though.
                          Possibly your router requires to add new machines to a trusted device list to allow traffic?

                          R 1 Reply Last reply Reply Quote 0
                          • R
                            Rob893 @viragomann
                            last edited by

                            @viragomann Yes, it is still on automatic. By that, do you man the ISP router or the Pfsense router?

                            V S 2 Replies Last reply Reply Quote 0
                            • V
                              viragomann @Rob893
                              last edited by

                              @rob893
                              The ISP router. Some have a whitelist, where devices must be added to pass traffic.

                              1 Reply Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @Rob893
                                last edited by

                                @rob893 Given the 192.168.1.1 WAN gateway is online that would mean pfSense can ping it. So it would seem your ISP router isn't passing traffic out.

                                If you Diagnostics/Traceroute to 8.8.8.8 does it get any farther than 192.168.1.1?

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote 👍 helpful posts!

                                R 1 Reply Last reply Reply Quote 0
                                • R
                                  Rob893 @SteveITS
                                  last edited by

                                  @steveits trace.png
                                  It doesn't seem so. But I did try to run my ISP router normally (not in bridge mode), and it sort of did something.

                                  Before, windows would show a no connection icon.
                                  After the change, it shows the connected via ethernet icon

                                  I am however, still unable to connect to the internet

                                  S 1 Reply Last reply Reply Quote 0
                                  • S
                                    SteveITS Galactic Empire @Rob893
                                    last edited by

                                    @rob893 if your ISP router was in bridge mode I would expect pfSense to get a public IP address…

                                    From the traceroute it seems the ISP router isn’t passing the packets on.

                                    I would go back to your ISP next.

                                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                    Upvote 👍 helpful posts!

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      Rob893 @SteveITS
                                      last edited by

                                      @steveits Alright, I'll see if I can do something about the ISP router. Thanks for the help!

                                      1 Reply Last reply Reply Quote 0
                                      • R
                                        Rob893
                                        last edited by

                                        Well, I finally got it working. From the online manual I found on the internet, my ISP router is an ONT, not a ONR. Someone pointed out that it being an ONT means that bridge mode was unnecessary. So, first thing I did was plug Pfsense in without bridge mode.
                                        But that was not the end of it because I could ping 8.8.8.8 but was still unable to connect to the internet. Diving into the forums led me to this, which resolved the problem.
                                        https://forum.netgate.com/topic/106121/fresh-install-does-not-give-internet-access-resolved?_=1679934258140

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.