Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access from internet router to LAN

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @macaruchi
      last edited by

      @macaruchi is the connection from rt-1 itself, ie some rfc1918 address - this 192.168.1 address, or is some public IP? Coming through rt1?

      If its from a 192.168.1 address, the block rfc1918 rules that are default on any wan interface would prevent that traffic. So no your port forward wouldn't work.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply Reply Quote 1
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Yup that. ^ Otherwise nothing special should be required. What have you tried so far? How did it fail?

        M 1 Reply Last reply Reply Quote 0
        • M
          macaruchi @johnpoz
          last edited by

          @johnpoz said in Access from internet router to LAN:

          @macaruchi is the connection from rt-1 itself, ie some rfc1918 address - this 192.168.1 address, or is some public IP? Coming through rt1?

          The RT1 has 2 IP, WAn IP and LAN IP, LAN IP = 192,168.1.1 this is connected directly to pfsense interface with IP 192.168.1.2 static IP address

          If its from a 192.168.1 address, the block rfc1918 rules that are default on any wan interface would prevent that traffic. So no your port forward wouldn't work.

          The interface doesnt have blocked the RFC1918, that is it default, in this interface, BOGON Networks,

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @macaruchi
            last edited by

            @macaruchi what is the source IP in the traffic your trying to allow. If not rfc1918, or bogon - then you would still need to allow the access you want, either to the pfsense wan, or via a port forward.

            Also make sure there are no overlapping networks.. Pfsense normally prevents you from creating them, but if your wan interfaces are dhcp then sure there could be overlaps with your lan or both your wan networks.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              If it's from a public IP it would also need to forwarded through RT1.

              M 1 Reply Last reply Reply Quote 0
              • M
                macaruchi @stephenw10
                last edited by

                @stephenw10 said in Access from internet router to LAN:

                Yup that. ^ Otherwise nothing special should be required. What have you tried so far? How did it fail?

                I think the same but I cant access to 10.0.0.0/24 network :(

                1 Reply Last reply Reply Quote 0
                • M
                  macaruchi @stephenw10
                  last edited by

                  @stephenw10 said in Access from internet router to LAN:

                  If it's from a public IP it would also need to forwarded through RT1.

                  Yes! this is that I am trying to do but from RT1 I cant get to LAN network. The dhcp from RT1 is disable

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @macaruchi
                    last edited by

                    @macaruchi well lets see your port forwards.. You sure its not just the host blocking the access.

                    First thing I would suggest in any port forwarding troubleshooting is validate the traffic actually gets to pfsense wan. Pfsense can not forward what it never sees.

                    Go to like can you see me . org - sniff on the wan interface of pfsense and send some traffic..

                    Here simple test that takes 10 seconds. Sent a port, don't even have it forwarded or anything but can see that it actually gets to pfsense wan.

                    sniff.jpg

                    Did you setup the port forward on rt1 to send whatever traffic your trying to forward on pfsense to pfsense wan?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      macaruchi @johnpoz
                      last edited by

                      @johnpoz said in Access from internet router to LAN:

                      @macaruchi well lets see your port forwards.. You sure its not just the host blocking the access.

                      First thing I would suggest in any port forwarding troubleshooting is validate the traffic actually gets to pfsense wan. Pfsense can not forward what it never sees.

                      Go to like can you see me . org - sniff on the wan interface of pfsense and send some traffic..

                      Here simple test that takes 10 seconds. Sent a port, don't even have it forwarded or anything but can see that it actually gets to pfsense wan.

                      sniff.jpg
                      No, it doesnt

                      Did you setup the port forward on rt1 to send whatever traffic your trying to forward on pfsense to pfsense wan?

                      Yes

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @macaruchi
                        last edited by johnpoz

                        @macaruchi said in Access from internet router to LAN:

                        No, it doesnt

                        So how would you expect pfsense to forward something that never gets to pfsense?

                        Either you don't have the forward setup correctly in the router in front of pfsense, or the traffic is never even getting to that router for it to forward.. You sure when you went to can you see me that the IP it sent the traffic too was the routers wan IP that you setup the forward to pfsense wan IP?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.