Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cant access router when connected via PPTP

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 3 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      luke240778
      last edited by

      Sorry, i dont really understand how i can do that? my laptop gets .4 when i connect via PPTP, but if i run a ping from the webgui arent i running it from that machine, which is the .1 ip?

      How do i capture packets from my laptop to .2?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        On the pfSense gui, go to Diagnostics > Packet capture. Run a capture there, on LAN, filtered on .4.

        Then ping the router from the PPTP-connected system, then stop the capture, and see what you got.

        Don't ping from the firewall's GUI

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • L Offline
          luke240778
          last edited by

          Ok thanks. I first pinged 192.168.10.1 and 10.235 as i know these i can access, then i did 10.2, which i believe shows nothing in the packet capture:

          21:22:21.146768 IP 192.168.10.4 > 192.168.10.235: ICMP echo request, id 1, seq 31, length 40
          21:22:24.712641 ARP, Request who-has 192.168.10.4 tell 192.168.10.235, length 46
          21:22:24.712659 ARP, Reply 192.168.10.4 is-at c8:3a:35:d2:53:cf, length 28
          21:22:25.683589 ARP, Request who-has 192.168.10.4 tell 192.168.10.235, length 46
          21:22:25.683607 ARP, Reply 192.168.10.4 is-at c8:3a:35:d2:53:cf, length 28
          21:22:25.841092 IP 192.168.10.4 > 192.168.10.235: ICMP echo request, id 1, seq 32, length 40
          21:22:26.683659 ARP, Request who-has 192.168.10.4 tell 192.168.10.235, length 46
          21:22:26.683677 ARP, Reply 192.168.10.4 is-at c8:3a:35:d2:53:cf, length 28
          21:22:29.351288 IP 192.168.10.235 > 192.168.10.4: ICMP echo reply, id 1, seq 32, length 40
          21:22:29.354802 IP 192.168.10.235 > 192.168.10.4: ICMP echo reply, id 1, seq 32, length 40
          21:22:29.371934 IP 192.168.10.235 > 192.168.10.4: ICMP echo reply, id 1, seq 32, length 40
          21:22:29.675635 IP 192.168.10.4 > 192.168.10.235: ICMP echo request, id 1, seq 33, length 40
          21:22:31.450664 IP 192.168.10.235 > 192.168.10.4: ICMP echo reply, id 1, seq 33, length 40
          21:22:31.818773 IP 192.168.10.4 > 192.168.10.235: ICMP echo request, id 1, seq 34, length 40
          21:22:32.597950 IP 192.168.10.235 > 192.168.10.4: ICMP echo reply, id 1, seq 34, length 40

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            If you never see the ping for .2 in the capture, that means it never left LAN. Either it never left the laptop, or it was blocked/misrouted somewhere along the way. Double check your firewall rules for pptp, firewall logs, etc.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • L Offline
              luke240778
              last edited by

              when i tried to ping .2 it just "request timed out"

              I have no idea how to setup firewall rules.. shouldnt it just work seeing i can access the other devices on the same subnet? the antennas for example.. they are all in Wireless ISP mode, they are basically routers also

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                That depends on your rulesโ€ฆ For all we know, since you haven't said, there is a block rule on there or an incorrect rule to pass to it. Show a screenshot of your PPTP rules.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • L Offline
                  luke240778
                  last edited by

                  Ok, here it is

                  pptprules.png
                  pptprules.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • jimpJ Offline
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    That should be fine then. Though just for giggles, change the source to 'any' and see what happens.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • L Offline
                      luke240778
                      last edited by

                      Definately would have been nice if it was that simple!! but unfortunately that didnt work.. :)

                      Should i change it back to PPTP or is any how it should be?

                      I have no idea why i cant get to this stupid router!ย  Its GUI is https, thats not an issue is it?

                      1 Reply Last reply Reply Quote 0
                      • jimpJ Offline
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Only would be an issue if you can't access any other https items across the vpn, but a ping isn't going either.

                        Somehow you need to determine if it's ever leaving the laptop and even trying to go over pptp. Try a traceroute to it.

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • M Offline
                          Metu69salemi
                          last edited by

                          Is this .2 in the same lan, so it's for sure in correct switch.
                          is switch configs correct
                          is the switch port functioning at all, even those can break down

                          1 Reply Last reply Reply Quote 0
                          • L Offline
                            luke240778
                            last edited by

                            Yes it is, and from within the office i can get to it, just cant when connected via PPTP from my home.

                            I also found out lastnight that i can't access it when i connect to another server via Teamviewer from home.. same problem.. all other devices with Webgui on the 192.168.10.0 subnet i can access.. just not this one in particular..

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.