Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense no internet

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Check the rules in Firewall > NAT > Outbound. Either whatever you've added manually or the auto rules. Are there rules for those VLAN subnets?

      M 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @mikeehendricks
        last edited by

        @mikeehendricks Traceroute from VLAN10 to 1.1.1.1 and see how far you get.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        M 1 Reply Last reply Reply Quote 0
        • M
          mikeehendricks @stephenw10
          last edited by

          @stephenw10 Here is my Outbout NAT config
          631a33c4-c8e1-4922-a996-6d2c4b482d95-image.png

          1 Reply Last reply Reply Quote 0
          • M
            mikeehendricks @SteveITS
            last edited by

            @SteveITS As from vlan10/11, i could only get into 192.168.11.1, i could not get beyond that but when i ping 10.0.28.2 from VLAN 11, it go through.
            b4f68f45-00dd-43f5-aa4a-9a33f2553138-image.png
            0c4391cb-5412-41e5-9ea5-d0e19e4d3bf6-image.png

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @mikeehendricks
              last edited by

              @mikeehendricks said in PFSense no internet:

              192.168.11.1

              And that is CS01 correct, from your screen cap above? Is CS01 routing that subnet on to pfSense? Seems like it is not since there is no response from pfSense.

              @mikeehendricks said in PFSense no internet:

              when i ping 10.0.28.2 from VLAN 11, it go through

              10.0.28.2 is the outside of CS01... So CS01 knows where that IP is, and can even answer because CS01 is 10.0.28.2.

              Can you ping 10.0.28.1, the pfSense IP in 10.0.28.0/24? I would think not if CS01 isn't set up to route those subnets.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote ๐Ÿ‘ helpful posts!

              M 2 Replies Last reply Reply Quote 0
              • M
                mikeehendricks @SteveITS
                last edited by

                @SteveITS 10.0.28.1 is accessible from CS01. Is there any config that i can do to be able to access 10.0.28.1 from inside VLAN 10/11?
                7298bd58-e305-4960-a3db-d475a6cddb50-image.png

                1 Reply Last reply Reply Quote 0
                • M
                  mikeehendricks @SteveITS
                  last edited by mikeehendricks

                  @SteveITS When i check the States of LAN rules, i can see the IP that im pinging inside VLAN 11, but on the PC it's still request timed out
                  b4e5ea88-b701-4494-9c0e-3b6135ad849f-image.png
                  3bf6e130-74a7-4e59-a410-1dbddf09e26d-image.png
                  3b927baf-1564-4d4f-94cc-34e564cdcd16-image.png

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mcury Rebel Alliance @mikeehendricks
                    last edited by mcury

                    @mikeehendricks Seems to me that CS01 is sending the packet to pfsense, but pfsense doesn't have a route back since those networks are not directly connected to it, they are behind CS01, right ?

                    Try to add a static route in pfsense, pointing to those networks behind CS01 with the next hop being 10.0.28.2 (Gi0/0) of CS01. I'm assuming that is a layer 3 switch ? You would also need to create a NAT in pfsense allowing those networks.

                    dead on arrival, nowhere to be found.

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mikeehendricks @mcury
                      last edited by mikeehendricks

                      @mcury I already add a route from VLAN 10/11 to 10.0.28.2, and it works!
                      64084753-2942-476c-b789-980853e49a73-image.png
                      ca2b5915-dad3-4c27-ba9d-edb4eb562292-image.png
                      Thanks for your help!

                      M 1 Reply Last reply Reply Quote 1
                      • M
                        mcury Rebel Alliance @mikeehendricks
                        last edited by

                        @mikeehendricks said in PFSense no internet:

                        Thanks for your help!

                        You are welcome, glad that it helped.

                        dead on arrival, nowhere to be found.

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.