Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Looking for help re-arranging my network

    Problems Installing or Upgrading pfSense Software
    5
    46
    12.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      "DD-WRT switch's IP is 192.168.1.2"

      So why would you need to ask how to access its configuration page if you set its IP??  How do you think you would access it??  How were you accessing them/it before??

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        DDWRT will just sit there like a big dumb SH$% if it doesn't get its IP from pfsense.  Is it getting an IP?  Can you access the pfsense menu to check?
        (This has turned into more of a DDWRT issue than pfsense issue, so not best site to get that answer.  But I know the answer so I'll answer)
        Technically bad form though I suppose.

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          "I can't ping it either".  Makes me think SPI firewall is still running.  I've never actually tried to ping mine but I'll give it a shot. 
          Also, incase you handled the deactivation and allocation of the wan port wrong on DDWRT, put all cables on only the "LAN" ports.  And try.

          Ping works for me…  And Web GUIs

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Its a LAN PORT, that can be a dhcp server it sure an the hell is not using dhcp to get an IP address.. If you set it up to 192.168.1.2 then that is what you would access it on.  If you can not ping it, it has nothing to do with the firewall - since that is from the wan side you would have to enable it to answer ping.  Lan answers ping out of the box.

            Your firewall is not going to be doing anything on dd-wrt because it only works between the lan/wlan bridge and the internet - it does not do anything between wlan/lan - so you might as well just disable it to save resources, etc.

            If you set it IP correctly, and are connected to its lan ports with correct IP on that same network then if you can not ping it - you setup its IP wrong, you have a bad cable or your box your using is not correct ip, etc..  Or port is bad on dd-wrt lan or our pc..

            Troubleshoot layer 1, then 2 then 3 – its really easy ;)  is your cable good..  Do you see mac?  etc..

            Setting up a router as ap is like a 2 min thing.. You assign it an IP, disable its dhcp server - connect to its IP and setup wlan..  If you spend more than 5 minutes tops you got something major wrong!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              Yeah - I can sympathize…  Even knowing exactly how something should be, I've been baffled by some pretty stupid stuff before.  Soooo simple like "why the hell did I plug my WAN cable into my LAN port...  When did I do this?".  Stuff that makes me want to slap myself.

              Oh - And yesterday my wife upon learning that my laptop screen "turns and swivels" turned it 720 degrees...  Trashed it.

              That must have taken some serious stubborn twisting.

              $4000 Laptop...  My GOD must I explain the definition of "swivel"?

              1 Reply Last reply Reply Quote 0
              • T
                TheBetterSort
                last edited by

                I can confirm that I turned the SPI firewall off and set it's IP to 192.168.1.2, and that I set the WAN port to Switch.

                I really don't know what's going on. Wireless still doesn't work either.

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  Well - I'm not there so I can't do it personally.  I promise you, some setting is wrong.  Maybe try doing a hard 30/30/30 reset and start from fresh.
                  I'm going to read that link you sent and make sure their directions are correct.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    so you set wan to switch - so your using wan?  Us a actual LAN port!!

                    Again there is nothing too this, if your having issue than a HARD reset might be in order..  Just reset your dd-wrt router..  Change its IP to your 192.168.1.2, turn off its dhcp server, connect it to your network via one of its lan ports =  shazam is a AP..  that is all there is too it!  Its at best 2 minutes..

                    You can tweak and play with other setting later like turning of spi, moving wan port to lan, etc.

                    connect your pc to its lan port nothing else - if after you change its IP to 192.168.1.2/24 and your pc is on 192.168.1.0/24 and you can not ping it - then you didn't change its IP right ;)

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • T
                      TheBetterSort
                      last edited by

                      Also, I set it's IP to static 192.168.1.2 so how would pfSense give it an IP?

                      But it's not showing up in the pfSense DHCP leases, I guess with good reason.
                      I REALLY don't want to do a reset. Like REALLY. With a  passion.

                      Is there a way to check ALL clients connected to pfSense (not just DHCP)

                      @johnpoz:

                      so you set wan to switch - so your using wan?  Us a actual LAN port!!

                      I am. I just included that bit of information because I'm sure I did. but everything is connected to actual LAN ports.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        So your Pc is connected to lan port of dd-wrt router, your pfsense is connect to different lan port on dd-wrt router.  Your PC got an IP from pfsense dhcp??

                        On 192.168.1.0/24 and you can ping pfsense lan port..  But you can not access dd-wrt on 192.168.1.2??

                        Then you did not correctly set its IP..  Or you have a mac address issue, or dd-wrt is broken ;)  since its switch ports are currently working any your cables are good if you can talk to pfsense through your dd-wrt lan ports.

                        Why are you apposed to hard reset?  It takes 2 minutes to set it up as AP from default..

                        and this just confuses the shit out of me
                        "Also, I set it's IP to static 192.168.1.2 so how would pfSense give it an IP?"

                        So you think pfsense should be giving your dd-wrt router an IP??  What??  I am confused at this statement I can not tell if your just not getting the basics or what?  As to checking devices that pfsense can see - just ping from pfsense if you want…  But no pfsense is not going to list every device on the network..

                        edit: did you muck around with any other dd-wrt configs like putting ports in vlans or anything like that?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • T
                          TheBetterSort
                          last edited by

                          @johnpoz:

                          So your Pc is connected to lan port of dd-wrt router, your pfsense is connect to different lan port on dd-wrt router.  Your PC got an IP from pfsense dhcp??

                          On 192.168.1.0/24 and you can ping pfsense lan port..  But you can not access dd-wrt on 192.168.1.2??

                          Then you did not correctly set its IP..  Or you have a mac address issue, or dd-wrt is broken ;)  since its switch ports are currently working any your cables are good if you can talk to pfsense through your dd-wrt lan ports.

                          Why are you apposed to hard reset?  It takes 2 minutes to set it up as AP from default..

                          That's exactly what's happening. Both on the same subnet. PC got served an IP from pfSense through DD-WRT Lan port.

                          Ughh. I'll do a hard reset then.

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi
                            last edited by

                            Short answer is yes. You could continue without a reset.
                            However if there is a typo or something in there, you would end up wasting hours or days vs minutes on the reset.

                            Other advice.  In that DDWRT document.  Use the long version.

                            Also:

                            Instep 3:  All the so-called optional stuff is mandatory and turn off NTP in DDWRT

                            Open the Setup -> Basic Setup tab

                            WAN Connection Type : Disabled
                                Local IP Address: 192.168.1.2 (i.e. different from primary router and out of primary router's DHCP pool)
                                Subnet Mask: 255.255.255.0 (i.e. same as primary router)
                                DHCP Server: Disable (also uncheck DNSmasq options)
                                (Recommended) Gateway/Local DNS: Make sure you use 192.168.1.1 here if thats what you set as pfsense LAN!!!!!!
                                (Optional) Assign WAN Port to Switch (visible only with WAN Connection Type set to disabled): Enable this if you want to use WAN port as a switch port
                                (Optional) NTP Client: Enable/Disable (if Enabled, specify Gateway/Local DNS above)

                            in step 7, none of that is optional.  Its mandatory.

                            Open the Services -> Services tab

                            (Optional) DNSMasq: Disable (enable if you use additional DNSMasq settings)
                                (Optional) ttraff Daemon: Disable
                                Save

                            in step 9, all those recommended settings are not recommended.  They are mandatory.

                            Open the Administration -> Management tab

                            (Recommended) Info Site Password Protection: Enable
                                (Recommended) Routing: Disabled (enable if you need to route between interfaces)
                                Apply Settings and connect Ethernet cable to main router via LAN-to-LAN uplink*
                                Reboot router to be sure all settings have been applied.
                                You may have to reboot your own PC or do "ipconfig /release" + "ipconfig /renew" from the Windows command line.

                            If you were to follow this guide, omitting the "optional" settings, it wouldn't work for you.

                            1 Reply Last reply Reply Quote 0
                            • K
                              kejianshi
                              last edited by

                              Look up at my setting I added in previous comment also.

                              (Recommended) Gateway/Local DNS: Make sure you use 192.168.1.1 here if thats what you set as pfsense LAN!!!!!!

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by

                                "They are mandatory."

                                BS – sorry but you sure an the hell do not need to put wan port into your switch ports, nor do you have to setup gateway or dns on your lan..  In what case does the web ui or dd-wrt need to know how to get off its network to be a AP??

                                And you sure and the hell do not need to disable routing -- your not using it, but does not mean it can not be ON...

                                Those settings are all tweaks and not "mandatory" that is for damn sure -- Give it an IP you can access is not even really required!!  the only thing required is turn off its freaking dhcp server or your going to have problems!!!  But it really does not need an IP on the current network if your wireless is setup how you want it all ready.. Or you don't mind putting a pc on its network to access the gui, etc..

                                Not sure where your getting mandatory anything from those settings - your just trying to confuse him or make it seem more complicated??

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                1 Reply Last reply Reply Quote 0
                                • T
                                  TheBetterSort
                                  last edited by

                                  Also, No, I do understand how these things work. I know pfSense won't be giving the router an IP.
                                  I just said that in response to someone asking.

                                  @kejianshi:

                                  Short answer is yes. You could continue without a reset.
                                  However if there is a typo or something in there, you would end up wasting hours or days vs minutes on the reset.

                                  Other advice.  In that DDWRT document.  Use the long version.

                                  Also:

                                  Instep 3:  All the so-called optional stuff is mandatory and turn off NTP in DDWRT

                                  Open the Setup -> Basic Setup tab

                                  WAN Connection Type : Disabled
                                     Local IP Address: 192.168.1.2 (i.e. different from primary router and out of primary router's DHCP pool)
                                     Subnet Mask: 255.255.255.0 (i.e. same as primary router)
                                     DHCP Server: Disable (also uncheck DNSmasq options)
                                     (Recommended) Gateway/Local DNS: Make sure you use 192.168.1.1 here if thats what you set as pfsense LAN!!!!!!
                                     (Optional) Assign WAN Port to Switch (visible only with WAN Connection Type set to disabled): Enable this if you want to use WAN port as a switch port
                                     (Optional) NTP Client: Enable/Disable (if Enabled, specify Gateway/Local DNS above)

                                  in step 7, none of that is optional.  Its mandatory.

                                  Open the Services -> Services tab

                                  (Optional) DNSMasq: Disable (enable if you use additional DNSMasq settings)
                                     (Optional) ttraff Daemon: Disable
                                     Save

                                  in step 9, all those recommended settings are not recommended.  They are mandatory.

                                  Open the Administration -> Management tab

                                  (Recommended) Info Site Password Protection: Enable
                                     (Recommended) Routing: Disabled (enable if you need to route between interfaces)
                                     Apply Settings and connect Ethernet cable to main router via LAN-to-LAN uplink*
                                     Reboot router to be sure all settings have been applied.
                                     You may have to reboot your own PC or do "ipconfig /release" + "ipconfig /renew" from the Windows command line.

                                  If you were to follow this guide, omitting the "optional" settings, it wouldn't work for you.

                                  Thank you very much for all your time. This seems to have worked. I also put the hostname I specified in pfSense into DD-WRT this time. Everything seems to be working now.

                                  I'll reboot both "routers" and see if it keeps working. Then I'll report back.

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    kejianshi
                                    last edited by

                                    I'm glad its all good…

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      TheBetterSort
                                      last edited by

                                      I'm back. I had a small issue with the 5GHz radio in DD-WRT, but restarting it again solved it.
                                      Everything it working great.

                                      Thank you, all.
                                      Is there a thanking or rep system on this forum I could use to show my gratitude?

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kejianshi
                                        last edited by

                                        Yes - I have a Bank Routing Number and Account Number for expressing appreciation…

                                        (kidding - I don't think there is anything like that on this site)

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          TheBetterSort
                                          last edited by

                                          @kejianshi:

                                          Yes - I have a Bank Routing Number and Account Number for expressing appreciation…

                                          (kidding - I don't think there is anything like that on this site)

                                          LOL  ;D
                                          Well, thanks again.

                                          1 Reply Last reply Reply Quote 0
                                          • D
                                            doktornotor Banned
                                            last edited by

                                            @kejianshi:

                                            Yes - I have a Bank Routing Number and Account Number for expressing appreciation…

                                            I only take beer… so, if you manage to set up beer-over-ip tunnel, I'll be happy to be your guest. :D

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.