Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static routes seemed that don't work if CP is active… why?

    Captive Portal
    2
    7
    3.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kolomalo
      last edited by

      This is the problem.

      • CP+Radius working 100%
      • I add static routes.
      • I login into CP and Internet is fully functional
      • Static routes don't work. ping hosts on the others subnets don't work

      then

      • I turn off CP
      • Internet is fully functional and ping host on the others subnets works!! so static routes works!!

      why???  :-[  :'(

      sorry about my poor english  :P

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Can you provide a traceroute when cp is turned off and when cp is turned on from a client behind the cp interface to such a host? Also please provide some networdiagram (can be in ascii) about the interfaces of the pfSense and the static route and so on?

        1 Reply Last reply Reply Quote 0
        • K
          kolomalo
          last edited by

          Of course!!!

          Static routes:
          wan  10.4.0.0/16     10.100.0.4  (ISP VPN router)   I change it to LAN and does the same
          wan  172.20.0.0/16  10.100.0.3  (ISP VPN router)   I change it to LAN and does the same

          ifconfig:
          lan ip    10.1.3.254/16
          wan ip  10.100.0.254/16

          Tracert is ok when CP is off (10.1.3.254, 10.100.0.254, 10.100.0.4,…,10.4.0.1) but when is on, the packets dont cross to 10.100.0.254, only to 10.1.3.254
          No rules on firewall, only defaults

          10.100.0.1 (Internet)  10.100.0.2 (ISP VPN VoIP)  10.100.0.3 (ISP VPN)  10.100.0.4 (ISP VPN)
                           |                                  |                                   |                             |
                           |                                  |                                   |                             |
                           -------------------------------------|------------------------------------
                                                                               |
                                                                         10.100.0.254
                                                                            pfSense
                                                                          10.1.3.254
                                                                                |
                                                                                |
                                                                     LAN 10.1.0.0/16

          thanks a lot ;)

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            Can you try a traceroute from the webgui? I guess that one will work regardless of the cp being enabled? It only fails when behind the cp enabled interface, right?

            1 Reply Last reply Reply Quote 0
            • K
              kolomalo
              last edited by

              Yes! it's work from the webgui. Only hosts on the LAN don't work…

              1 Reply Last reply Reply Quote 0
              • K
                kolomalo
                last edited by

                :'( :'( :'( :'( :'( :'( :'( :'( :'( :'( :'(

                1 Reply Last reply Reply Quote 0
                • K
                  kolomalo
                  last edited by

                  no solution?? :(

                  So, I can't use CP…

                  Anyone have the same problem???

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.