Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No internet on Guest LAN

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @stephenkwabena
      last edited by

      @stephenkwabena well this shows you have like 203 current states allowed

      sessions.jpg

      Had you messed with outbound nat and changed it from auto? When you add a new network the auto nat would add your new network to be natted to your wan address.

      But if you had followed some vpn guide for example that had you set to manual - then yeah you would have to manually add your outbound nat.. This is common user error have seen.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      S 1 Reply Last reply Reply Quote 1
      • S
        stephenkwabena @johnpoz
        last edited by

        @johnpoz this is my outbound setting and I didn't do any changes there
        Outbound Nat.PNG

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @stephenkwabena
          last edited by

          @stephenkwabena well from your firewall tab you show a lot of states, but yeah the amount of traffic passed seems really low for connections actually work, especially 203 of them ;)

          Hmmm??

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          S 1 Reply Last reply Reply Quote 0
          • S
            stephenkwabena @johnpoz
            last edited by

            @johnpoz So any help from here?

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Do devices on that interface pull a dhcp lease? Do you see that lease in the pfSense dhcp status page?

              Start a ping from a client on it and then check the states in pfSense. Make sure it's opening a state on HOTSPOT and WAN.

              Steve

              S 1 Reply Last reply Reply Quote 0
              • S
                stephenkwabena @stephenw10
                last edited by

                @stephenw10 Yes they do

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Can we see those states? I assume you don't see ping replies?

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    stephenkwabena @stephenw10
                    last edited by

                    @stephenw10 Please, where can find?

                    johnpozJ JonathanLeeJ 2 Replies Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @stephenkwabena
                      last edited by

                      @stephenkwabena Might be helpful if you looked at menus - its not like this stuff is hidden.

                      states.jpg

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 1
                      • J
                        Jarhead @stephenkwabena
                        last edited by Jarhead

                        @stephenkwabena said in No internet on Guest LAN:

                        I have upgraded to pfsense 2.7.0-BETA, when I added a new interface for Guest's or hotspot, there is no internet on that LAN.
                        Below are my configuration

                        How many times are you gonna post the exact same problem in different threads??

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          stephenkwabena @Jarhead
                          last edited by stephenkwabena

                          @Jarhead I'm sorry for posting in different threads and promise it will not repeat itself again

                          1 Reply Last reply Reply Quote 0
                          • JonathanLeeJ
                            JonathanLee @stephenkwabena
                            last edited by

                            @stephenkwabena click on the the numbers next to the acl in your photo they show 203, it will show active states look at what they are doing.

                            Make sure to upvote

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @JonathanLee
                              last edited by johnpoz

                              @JonathanLee said in No internet on Guest LAN:

                              click on the the numbers next to the acl in your photo they show 203

                              Great tip! This will limit the states to the ones created per that rule.. But, with that we won't be able to see the nat state that shows that it was changed to the public IP on the wan..

                              It would good to see that the traffic was actually natted to his public ip in the state table - because if its not, then that could be his reason he is not able to actually connect to anything.

                              states.jpg

                              When I click on mine for example - it shows the states by the rule id "303" in my example - but it doesn't show the WAN state where see that it was natted to my wan IP..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 2
                              • JonathanLeeJ
                                JonathanLee @stephenkwabena
                                last edited by JonathanLee

                                @stephenkwabena Check what interfaces you have approved to use the DNS resolver also

                                Screenshot 2023-06-22 at 8.05.24 AM.png
                                (Example DNS Resolver)

                                This should include your loopback and your new interface as a selected item under network interface

                                Make sure to upvote

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  stephenkwabena @JonathanLee
                                  last edited by

                                  @JonathanLee I checked "All" but I have noticed something else, sometimes I can browse for sometime then I can't browse again

                                  johnpozJ 1 Reply Last reply Reply Quote 1
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Do the created states differ when it fails?

                                    S 1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator @stephenkwabena
                                      last edited by

                                      @stephenkwabena said in No internet on Guest LAN:

                                      sometimes I can browse for sometime then I can't browse again

                                      most likely because your dns is failing.. you showed on one of your many posts timing out trying ping google on the resolve of google.com if you can not resolve whatever.domain.tld to an IP - then no your not going to be able to "browse" the internet.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        stephenkwabena @stephenw10
                                        last edited by

                                        @stephenw10 said in No internet on Guest LAN:

                                        Do the created states differ when it fails?

                                        Yes nothing shows at the states but when able to browse I can see "10.10.5.10 established 222.678.145.233 (something like this)"

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator @stephenkwabena
                                          last edited by

                                          @stephenkwabena yeah that would mean its working - if you can not resolve www.google.com for example then no you would never create a state..

                                          When you can not browse - validate that you can resolve the fqdn your trying to go to. If not then no its never going to work, if you get an IP for the fqdn your trying to go to. Then check you states.. If you see say syn sent, but no answer then were you trying to go didn't answer and problem is upstream, etc.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.