Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Strange sudden firewall behavior: Can no longer access LAN -> OPT1

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 4 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mlanner
      last edited by

      The weirdest thing just happened to my pfSense setup. I have made no changes to the firewall rules whatsoever, or to any other part of my pfSense for that matter.

      Two days ago I could access machines on my OPT1 subnet from my LAN subnet. Suddenly I can't get to them from my LAN. I can't even ping them. However, from the pfSense itself I can ping the machines in the OPT1 subnet just fine.

      I promise I haven't made any modifications to my rules. :S  This is really bizarre to me. Can anyone explain what could've happened?

      1 Reply Last reply Reply Quote 0
      • B Offline
        blak111
        last edited by

        Has the default gateway on the machines you are trying to hit been changed?

        1 Reply Last reply Reply Quote 0
        • M Offline
          mlanner
          last edited by

          No, nothing at all has changed. It just stopped working. Like I said, I didn't change anything on the pfSense or anything on any of the machines in the OPT1 LAN. I can still VPN to the LAN on OPT1. I get an IP address, just like you'd expect, but then nothing. I can't ping any of the machines in the OPT1 LAN.

          1 Reply Last reply Reply Quote 0
          • B Offline
            blak111
            last edited by

            Can you ping the Opt1 interface from the clients on the opt1 network? If you can, what are the rules you have set up and are you doing any advanced NAT?

            1 Reply Last reply Reply Quote 0
            • M Offline
              mlanner
              last edited by

              Yes, I can ping the gateway. I assume that's what you meant by the "OPT1 interface"? I can ping anything on the Internet too. I can't ping anything on my "regular" LAN, but that's the way it should be, because that's how I want it and set the policy.

              1 Reply Last reply Reply Quote 0
              • C Offline
                cmb
                last edited by

                anything in your firewall logs?

                1 Reply Last reply Reply Quote 0
                • GruensFroeschliG Offline
                  GruensFroeschli
                  last edited by

                  Could it be that you enabled the Captive Portal?

                  I just searched my network for about 4 hours for faults, without noticing that the CP was active…....

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.