Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Strange Routing Issue

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 4 Posters 845 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • patient0P Offline
      patient0 @ahole4sure
      last edited by

      @ahole4sure traceroute may or may not work (the devices on the way to the target may not support it). I'd say a ping is preferred for a quick test.

      What are you referring to by '... able to reach certain websites'? Do some open when you access them in the web browser? And others not, and if not what error do you get?

      I have a static IP (for my ATT modem)

      How did you have pfSense configured, static IP and gateway (information you got from ATT?)? What DNS server have you set to be used?

      And I'd think you have a good chance searching the forum for ATT, maybe someone else had a similar issue with this ISP.

      1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @ahole4sure
        last edited by

        @ahole4sure This is a cellular connection?

        Does the firewall on your remote endpoint allow ICMP?

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          Mmm, I can't ping that either so it looks like it's blocking at least some sources.

          1 Reply Last reply Reply Quote 0
          • A Offline
            ahole4sure
            last edited by

            @stephenw10
            @patient0
            @SteveITS

            THANKS for trying to help.
            My head is spinning because I have too many isssues., lol
            (they may be partly realted , maybe not completely)

            The first thing that I have done more investigation is that there is for sure an issue with my ATT wireless modem
            The way ATT has you to accomplish the static IP - is to give you a particular APN - and if you enter that data APN in the modem and it matches your SIM card it will give you access to your static IP address.
            So to test things - (when I remove it from the pfsense situation and connect it directly to my Mac) and then enter or use the specific APN - then I get the weird issues where none of my normally hosted servers can be reached (if by web browser it just has no response - just locks page ) -- XXX.mydomain.com (DNS by cloudfare and access to my network only on 443 with haproxy - no open ports)

            If I remove the specific APN and just use the normal Broadband APN then I can access my sites just fine.
            So I concluded that my main issue is with ATT

            What I am trying to accomplish is to set up Site to Site Wireguard VPN's so that the work is mostly done before I travel 5hrs to deploy for my daughter.
            With the ATT modem set in the normal mode I can put it in IP Passthrough mode - but it is acting weird (I guess CGNAT ?) in that IP that the WAN is getting by DHCP on the status page reports as 10.168.25.44 - , but if I do what is my ip from a web browser and if I set up DDNS on pfsense - it reports IP as - 166.199.150.73
            I have VPN pass through checked on my wireless modem - but I assume that is just not going to work for trying to setup a Site to Site -- I never a get a handshake from EITHER side

            Is there a workaround to test and setup a Site to Site when you only have one internet source (or the second one is a cellular modem that I assume wont work becasue of CGNAT) ??

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              ahole4sure @ahole4sure
              last edited by

              @patient0
              @stephenw10
              @SteveITS

              I was initally able to do my modified Site to Site using Tailscale and things were accesible -- but that isn't as reliable or fast as setting up a Site to Site Wireguard

              With that said I have 2 site to sites setup with 2 of our locations -- there ahouldn't be a problem with creating a third as long as I seperate all subnets -- correct?

              S 1 Reply Last reply Reply Quote 0
              • S Offline
                SteveITS Rebel Alliance @ahole4sure
                last edited by

                Yeah CGNAT breaks the inbound. If the other end has a public IP you can connect out to that, though. Do you get IPv6?

                You could use a third device as a VPN server and connect both ends to that.

                Somewhere recently I thought I saw something saying customers could not use 10.0.0.0/8 internally, and I think it was from AT&T. 20+ years ago we had a T1 ISP that used that for their network but still routed public IPs to the customer.

                Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                Upvote 👍 helpful posts!

                A 1 Reply Last reply Reply Quote 0
                • A Offline
                  ahole4sure @SteveITS
                  last edited by

                  @SteveITS

                  So in my existing I have site to site from A to B

                  Could I set up my new test to connect to site B (server) and have access from site A to the new test ???

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Unclear what you're asking. You should be able to establish the tunnel from the cell modem side as long as the other end has a known public IP it can listen on. Once the tunnel is up you can access things across it either way.

                    A 1 Reply Last reply Reply Quote 0
                    • A Offline
                      ahole4sure @stephenw10
                      last edited by

                      @stephenw10
                      OK. thank you - I know stupid question - but why do a site to site in the first place then if all can be accomplished the other way?

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        What other way do you mean? Using Tailscale? No reason if that works for you. As you said it may be faster with a direct WG tunnel. But you may not need that additional bandwidth.

                        A 1 Reply Last reply Reply Quote 0
                        • A Offline
                          ahole4sure @stephenw10
                          last edited by ahole4sure

                          @stephenw10
                          No I meant that I didn't know I could establish a peer to site with the peer being behind CGNAT (in pfsense). -- is that what you are saying that I should be able to do that ?
                          But does that allow access from the non CGNAT site into the network of the CGNAT site ??

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S Offline
                            stephenw10 Netgate Administrator
                            last edited by

                            It's still site to site it's just that the tunnel can only be established from the side behind CGNAT. But, yes, once the tunnel is established connections can be opened across it both ways.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.