pfsense test bed on zimaboard behind main pfsense router
-
@mr-singh said in pfsense test bed on zimaboard behind main pfsense router:
my main pfsense is on 10.2.1.1/24 subnet and thr test bed pfsense is on 192.168.1.1
In that case : install pfSense with the one golden rule : use the keyword ones, when you define your password. And stop there using your keyboard. Don't change anything else. Don't add or change DNS related stuff. It's a plug and play experience.
Forget about my story above : plugin in WAN, plugin in LAN, and done.
@mr-singh said in pfsense test bed on zimaboard behind main pfsense router:
The laptop which is a mac is connected using a usbc 2.5gb dongle
If this works on your main bed pfSense router, it will work on any other router (as long as DHCP is active).
-
On the Zimaboard you need to run the alternative Realtek module to avoid watchdog timeout isues. That wouldn't stop it connecting completely though.
-
@stephenw10 I have 2 x4 nics that I would try with.
Keeping pfsense zimboard wan port on a vlan aware lan port would make any difference?
-
i have pflbocker on the main pfsense router
-
@mr-singh said in pfsense test bed on zimaboard behind main pfsense router:
Keeping pfsense zimboard wan port on a vlan aware lan port would make any difference?
Probably not. The WAN connection is working as expected as I understand it? You can ping out OK from pfSense itself.
It's clients behind it that are failing to connect? Are those clients even getting a DHCP lease from pfSense?
-
@stephenw10 yes they are.
Any subnet changes I do on the test bed pfsense, are reflected on the client side
-
OK. So DNS is failing on the clients, what are they using for DNS? They should be being passed the pfSense LAN interface address to use.
Can clients ping out by IP address directly?
-
@stephenw10 client can't ping out
-
Ok so cant resolve or ping external sites. Can clients ping the pfSense LAN address?
If they get DHCP leases but can't ping anything (even locally) that sounds like a missing or bad firewall rule. However on LAN that should be passed by default.
-
@stephenw10 pfsense ui ping, traceroute and dns lookup can connect to external hosts
But devices on the lan can't ping or do nslookup on any site.
-
But can they connect to the pfSense GUI or ping it's local IP address?