Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense no internet

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mikeehendricks @SteveITS
      last edited by

      @SteveITS I already change the source to "ANY", but still i can't ping outside from VLAN 11.

      68443f30-92c0-4bc8-91a0-4c027d4fa963-image.png

      S 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Check the rules in Firewall > NAT > Outbound. Either whatever you've added manually or the auto rules. Are there rules for those VLAN subnets?

        M 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @mikeehendricks
          last edited by

          @mikeehendricks Traceroute from VLAN10 to 1.1.1.1 and see how far you get.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          M 1 Reply Last reply Reply Quote 0
          • M
            mikeehendricks @stephenw10
            last edited by

            @stephenw10 Here is my Outbout NAT config
            631a33c4-c8e1-4922-a996-6d2c4b482d95-image.png

            1 Reply Last reply Reply Quote 0
            • M
              mikeehendricks @SteveITS
              last edited by

              @SteveITS As from vlan10/11, i could only get into 192.168.11.1, i could not get beyond that but when i ping 10.0.28.2 from VLAN 11, it go through.
              b4f68f45-00dd-43f5-aa4a-9a33f2553138-image.png
              0c4391cb-5412-41e5-9ea5-d0e19e4d3bf6-image.png

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @mikeehendricks
                last edited by

                @mikeehendricks said in PFSense no internet:

                192.168.11.1

                And that is CS01 correct, from your screen cap above? Is CS01 routing that subnet on to pfSense? Seems like it is not since there is no response from pfSense.

                @mikeehendricks said in PFSense no internet:

                when i ping 10.0.28.2 from VLAN 11, it go through

                10.0.28.2 is the outside of CS01... So CS01 knows where that IP is, and can even answer because CS01 is 10.0.28.2.

                Can you ping 10.0.28.1, the pfSense IP in 10.0.28.0/24? I would think not if CS01 isn't set up to route those subnets.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                M 2 Replies Last reply Reply Quote 0
                • M
                  mikeehendricks @SteveITS
                  last edited by

                  @SteveITS 10.0.28.1 is accessible from CS01. Is there any config that i can do to be able to access 10.0.28.1 from inside VLAN 10/11?
                  7298bd58-e305-4960-a3db-d475a6cddb50-image.png

                  1 Reply Last reply Reply Quote 0
                  • M
                    mikeehendricks @SteveITS
                    last edited by mikeehendricks

                    @SteveITS When i check the States of LAN rules, i can see the IP that im pinging inside VLAN 11, but on the PC it's still request timed out
                    b4e5ea88-b701-4494-9c0e-3b6135ad849f-image.png
                    3bf6e130-74a7-4e59-a410-1dbddf09e26d-image.png
                    3b927baf-1564-4d4f-94cc-34e564cdcd16-image.png

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mcury Rebel Alliance @mikeehendricks
                      last edited by mcury

                      @mikeehendricks Seems to me that CS01 is sending the packet to pfsense, but pfsense doesn't have a route back since those networks are not directly connected to it, they are behind CS01, right ?

                      Try to add a static route in pfsense, pointing to those networks behind CS01 with the next hop being 10.0.28.2 (Gi0/0) of CS01. I'm assuming that is a layer 3 switch ? You would also need to create a NAT in pfsense allowing those networks.

                      dead on arrival, nowhere to be found.

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mikeehendricks @mcury
                        last edited by mikeehendricks

                        @mcury I already add a route from VLAN 10/11 to 10.0.28.2, and it works!
                        64084753-2942-476c-b789-980853e49a73-image.png
                        ca2b5915-dad3-4c27-ba9d-edb4eb562292-image.png
                        Thanks for your help!

                        M 1 Reply Last reply Reply Quote 1
                        • M
                          mcury Rebel Alliance @mikeehendricks
                          last edited by

                          @mikeehendricks said in PFSense no internet:

                          Thanks for your help!

                          You are welcome, glad that it helped.

                          dead on arrival, nowhere to be found.

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.