Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense fresh install / No internet on VLAN's

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    23 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @marcel1988
      last edited by

      @marcel1988 said in Pfsense fresh install / No internet on VLAN's:

      Can you elaborate on that?

      @Bob-Dig said : your first firewall rule on MAIN blocks RFC1918.

      The 'definition' of RFC1918 is :

      Blocks traffic from IP addresses that are reserved for private networks per RFC 1918 (10/8, 172.16/12, 192.168/16) and unique local addresses per RFC 4193 (fc00::/7) as well as loopback addresses (127/8). This option should generally be turned on, unless this network interface resides in such a private address space, too.

      and your MAIN network falls right into RFC1918.
      Your first firewall rule blocks all your 'LAN' (MAIN) traffic.
      No traffic will match/ reach the second, pass all rule : the counters stay at zero.
      The first rule does have matches : its blocking all your traffic coming into that interface.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      M 1 Reply Last reply Reply Quote 0
      • M
        marcel1988 @Gertjan
        last edited by

        @Gertjan

        That rule is made since i did a checkbox on the "Block private networks and loopback addresses"

        So when i disabled that checkbox, it should work?

        M 1 Reply Last reply Reply Quote 0
        • M
          marcel1988 @marcel1988
          last edited by

          @marcel1988 said in Pfsense fresh install / No internet on VLAN's:

          @Gertjan

          That rule is made since i did a checkbox on the "Block private networks and loopback addresses"

          So when i disabled that checkbox, it should work?

          I tried that, but no change. The firewall rule is gone but there is stil no internet on VLAN10, 20, 30, or 40.

          A 1 Reply Last reply Reply Quote 0
          • A
            Antibiotic @marcel1988
            last edited by

            @marcel1988 I think you have to create firewall rules to allow traffic on your VLAN's))))

            pfSense plus 24.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            M 1 Reply Last reply Reply Quote 0
            • M
              marcel1988 @Antibiotic
              last edited by marcel1988

              @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

              @marcel1988 I think you have to create firewall rules to allow traffic on your VLAN's))))

              There is on the main. This is copied from the LAN firewall rule. (Same on all the VLAN firewall rules)
              alt text

              A 2 Replies Last reply Reply Quote 0
              • A
                Antibiotic @marcel1988
                last edited by

                @marcel1988 Oh , did you setup Adguard as well. Could be wrong set up with DNS resolution. I think better to uninstall Adguard, than try with default unbound resolver.

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • A
                  Antibiotic @marcel1988
                  last edited by Antibiotic

                  @marcel1988 If you want to block something from kids you can use pfblockerNG more power ad blocker, than Adguard

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    marcel1988 @Antibiotic
                    last edited by

                    @Antibiotic

                    first, this should be working WITH AdGuard home. SO no need to uninstall it.

                    second: pfblockerNG does not have specific blocking for app/websites with just one click.

                    A 2 Replies Last reply Reply Quote 0
                    • A
                      Antibiotic @marcel1988
                      last edited by

                      @marcel1988 Ok , up to you. But it potential additional problem. If you aware that Adguard dns resolution working

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @marcel1988
                        last edited by

                        @marcel1988 Did you set dns forwarding in Unbound settings?

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          marcel1988 @Antibiotic
                          last edited by

                          @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

                          @marcel1988 Did you set dns forwarding in Unbound settings?

                          This is what you mean? This is untouched and empty
                          alt text

                          A 3 Replies Last reply Reply Quote 0
                          • A
                            Antibiotic @marcel1988
                            last edited by

                            @marcel1988
                            ea63278e-df70-49ae-b890-a6eae24cfb6d-image.png
                            9f15b078-2a7d-4069-93c9-b8ff9fec1278-image.png
                            9fc90a0e-33ef-4a87-a741-80c08ff25bea-image.png

                            Dnssec in case of forwarding should be disable!

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            1 Reply Last reply Reply Quote 0
                            • A
                              Antibiotic @marcel1988
                              last edited by Antibiotic

                              @marcel1988 Not DNS forwarder, but Unbound dns resolver forward mode. I show my settings just as example for forwarding mode

                              pfSense plus 24.11 on Topton mini PC
                              CPU: Intel N100
                              NIC: Intel i-226v 4 pcs
                              RAM : 16 GB DDR5
                              Disk: 128 GB NVMe
                              Brgds, Archi

                              1 Reply Last reply Reply Quote 0
                              • A
                                Antibiotic @marcel1988
                                last edited by

                                @marcel1988
                                b961bdf1-0cb2-40db-8ec1-7ea5343bb176-image.png

                                pfSense plus 24.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                M 1 Reply Last reply Reply Quote 0
                                • M
                                  marcel1988 @Antibiotic
                                  last edited by

                                  @Antibiotic

                                  That did nothing.
                                  BUT, when i change the listen port back to 53, and changed the Network interfaces from Localhost to Any everything is working and the pc's are getting internet.
                                  But, the can also communicate between eachother.

                                  A 1 Reply Last reply Reply Quote 0
                                  • A
                                    Antibiotic @marcel1988
                                    last edited by

                                    @marcel1988
                                    Idk how configured your Adguard server, looks like problem with a port listening. Localhost WAS IN MY EXAMPLE FOR MY SETTINGS, FOR AVOID PROBLEM FIRST SET TO DEFAULT IN NETWORK INTERFACE AND OUTGOING INTERFACE.

                                    pfSense plus 24.11 on Topton mini PC
                                    CPU: Intel N100
                                    NIC: Intel i-226v 4 pcs
                                    RAM : 16 GB DDR5
                                    Disk: 128 GB NVMe
                                    Brgds, Archi

                                    M 1 Reply Last reply Reply Quote 0
                                    • M
                                      marcel1988 @Antibiotic
                                      last edited by

                                      @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

                                      @marcel1988
                                      Idk how configured your Adguard server, looks like problem with a port listening. Localhost WAS IN MY EXAMPLE FOR MY SETTINGS, FOR AVOID PROBLEM FIRST SET TO DEFAULT IN NETWORK INTERFACE AND OUTGOING INTERFACE.

                                      Exactly like this toturial: Tutorial Adguard Home

                                      A 2 Replies Last reply Reply Quote 0
                                      • A
                                        Antibiotic @marcel1988
                                        last edited by Antibiotic

                                        @marcel1988
                                        I did not read all, but this tutorial from 2020.Are you download this version v0.104.0-beta2? Did you try this command than dig @192.168.5.1 google.com.
                                        Because last one is https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.108.0-b.55

                                        pfSense plus 24.11 on Topton mini PC
                                        CPU: Intel N100
                                        NIC: Intel i-226v 4 pcs
                                        RAM : 16 GB DDR5
                                        Disk: 128 GB NVMe
                                        Brgds, Archi

                                        1 Reply Last reply Reply Quote 0
                                        • A
                                          Antibiotic @marcel1988
                                          last edited by

                                          @marcel1988 As I know this tutorial working
                                          (https://bobcares.com/blog/adguard-pfsense/), if you want to use package not present in pfsense repo. But install packages outside of pfsense repo can lead to errors, incapability and potential security risks!

                                          pfSense plus 24.11 on Topton mini PC
                                          CPU: Intel N100
                                          NIC: Intel i-226v 4 pcs
                                          RAM : 16 GB DDR5
                                          Disk: 128 GB NVMe
                                          Brgds, Archi

                                          M 1 Reply Last reply Reply Quote 0
                                          • M
                                            marcel1988 @Antibiotic
                                            last edited by marcel1988

                                            @Antibiotic

                                            With this install script, i can only see that "localhost" is doing the dns reqeusts. So there is no way anymore to block specific rules on specific users. 😕

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.