Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Public VLAN routing via pfSense with limited FW rules for selected VLANs?

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 4 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      podilarius
      last edited by

      FTP proxy should probably not used. I am not for my FTP server. But I guess it really depends on the FTP server that you are using. Mine is vsftpd and I have just configured NAT address and a small port range for passive ftp.

      1 Reply Last reply Reply Quote 0
      • G
        Gio
        last edited by

        What I have tried so far:

        • Disabling Packet Filtering (so that I can find out if its a routing issue or FW)
        • Enabled Manual NAT (deleted all automatically created routes)
          – Windows host under VLAN won't get a response from its gateway after that

        it looks like pfSense is not forwarding ip packets? (if its only a router with a default gateway set shouldn't it allow IP forwarding??)

        Thanks in advance. I can't get these hosts to be completely accessible from the internet (even with Packet filtering disabled) any quick and dirty guides to setup pfsense as router only with vlans? I could use that to setup a basic router then move on to packet filtering.

        1 Reply Last reply Reply Quote 0
        • G
          Gio
          last edited by

          I wonder if the reason why I can't get 1:1 outbound NAT to work is because I haven't clicked this checkbox in System > Advanced

          Automatically create outbound NAT rules which assist inbound NAT rules that direct traffic back out to the same subnet it originated from.
          Currently only applies to 1:1 NAT rules. Required for full functionality of NAT Reflection for 1:1 NAT.

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            Reflection is for bouncing the public IP back to the private IP. eg- If I'm at 192.168.1.100 and the webserver for www.company.com is at 192.168.1.50, but I'm trying to go the the public IP, it will bounce the traffic back to 192.168.1.50.
            Your goal is to take the /24 and break off four /29's, assigning each to a separate vlan, then use public IPs on the machines?

            1 Reply Last reply Reply Quote 0
            • G
              Gio
              last edited by

              @dotdash:

              Your goal is to take the /24 and break off four /29's, assigning each to a separate vlan, then use public IPs on the machines?

              This is exactly what I am trying to achieve.

              I am also unsure if I should turn off "LAN" interface since I am doing VLANs for everything. Not sure if this is one of the reasons I'm having trouble achieving what I want. LAN is setup as 172.16.0.1 and /24 DHCP server is on, all untagged traffic (other ports on switch) can get IP from the DHCP scope. VLANs are working as expected though I use STATIC IPs on VLANs no DHCP FYI

              1 Reply Last reply Reply Quote 0
              • G
                Gio
                last edited by

                Let me give you guys some more information about the setup. I will use random public IPs as example to get the idea accross, but same subnet and IP just masking the first 3 octets of my range.

                WAN IP

                • Gateway IP (default route) 199.10.20.97
                • WAN IP config set to static with IP 199.10.20.98 255.255.255.252

                LAN IP em0

                • Static IP 172.16.0.1 /24
                • DHCP server is running on this

                VLAN10 (off em0)

                • Static IP 200.44.32.129 - gateway 200.44.32.129 - netmask 255.255.255.248 (/29)

                VLAN10 client

                • Windows server 2003 - static IP 200.44.32.130 - gateway 200.44.32.129 netmask 255.255.255.248
                1 Reply Last reply Reply Quote 0
                • W
                  wallabybob
                  last edited by

                  I was redirected to this topic from http://forum.pfsense.org/index.php/topic,61013.msg328872.html

                  Actual ping responses are far more informative than "cannot ping". So I don't have to go hunting through other topics on the same problem please provide the output of pfSense shell commands```
                  /etc/rc.banner
                  ifconfig -a
                  netstat -r -n
                  ping -c 5 199.10.20.97    # wan gateway
                  ping -c 5 8.8.8.8

                  
                  And please provide output of following ping commands (after any necessary IP address correction) run on the VLAN10 client:```
                  ping 200.44.32.129
                  ping 199.10.20.98
                  ping 199.10.20.97
                  ping 8.8.8.8
                  
                  1 Reply Last reply Reply Quote 0
                  • G
                    Gio
                    last edited by

                    Screenshot pack 1

                    ![4-11-2013 2-11-31 PM.png](/public/imported_attachments/1/4-11-2013 2-11-31 PM.png)
                    ![4-11-2013 2-11-31 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-11-31 PM.png_thumb)
                    ![4-11-2013 2-13-41 PM.png](/public/imported_attachments/1/4-11-2013 2-13-41 PM.png)
                    ![4-11-2013 2-13-41 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-13-41 PM.png_thumb)
                    ![4-11-2013 2-14-28 PM.png](/public/imported_attachments/1/4-11-2013 2-14-28 PM.png)
                    ![4-11-2013 2-14-28 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-14-28 PM.png_thumb)
                    ![4-11-2013 2-15-44 PM.png](/public/imported_attachments/1/4-11-2013 2-15-44 PM.png)
                    ![4-11-2013 2-15-44 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-15-44 PM.png_thumb)
                    ![4-11-2013 2-16-51 PM.png](/public/imported_attachments/1/4-11-2013 2-16-51 PM.png)
                    ![4-11-2013 2-16-51 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-16-51 PM.png_thumb)
                    ![4-11-2013 2-17-19 PM.png](/public/imported_attachments/1/4-11-2013 2-17-19 PM.png)
                    ![4-11-2013 2-17-19 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-17-19 PM.png_thumb)
                    ![4-11-2013 2-17-34 PM.png](/public/imported_attachments/1/4-11-2013 2-17-34 PM.png)
                    ![4-11-2013 2-17-34 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-17-34 PM.png_thumb)
                    ![4-11-2013 2-18-01 PM.png](/public/imported_attachments/1/4-11-2013 2-18-01 PM.png)
                    ![4-11-2013 2-18-01 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-01 PM.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • G
                      Gio
                      last edited by

                      Screenshot pack 2.

                      Please see my settings - as you can see Packet filtering is on, gateway appears to be setup properly and routes appear to be there. Problem is without any kind of filtering my VLAN with my public /29 should be able to freely have full network access inbound and outbound, this is not working.

                      ![4-11-2013 2-18-29 PM.png](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png)
                      ![4-11-2013 2-18-29 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png_thumb)
                      ![4-11-2013 2-18-29 PM.png](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png)
                      ![4-11-2013 2-18-29 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png_thumb)
                      ![4-11-2013 2-18-50 PM.png](/public/imported_attachments/1/4-11-2013 2-18-50 PM.png)
                      ![4-11-2013 2-18-50 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-50 PM.png_thumb)

                      1 Reply Last reply Reply Quote 0
                      • W
                        wallabybob
                        last edited by

                        If you haven't rebooted the pfSense box since you disabled the firewall I suggest you do so. It has been my experience that some major changes eemed to need a reboot to correctly take effect.

                        The configuration information you posted looks OK. How about the ping output I requested. I want to see what is reported by ping at each stage: nearest pfSense interface, pfSense WAN interface, upstream gateway, google DNS.

                        1 Reply Last reply Reply Quote 0
                        • P
                          podilarius
                          last edited by

                          I noticed that you have the FW off, so no rules are going to apply anyway. This means no NAT, FW, nothing, only routing. Since that is the case, it would seem that you probably have a basic routing problem. Can machines on your VLAN ping the WAN ip of pfSense, then, can they ping the WAN Gateway?

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.