• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall blocks Nexus 7 in LAN

Scheduled Pinned Locked Moved Firewalling
19 Posts 2 Posters 4.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mrsunfire
    last edited by Aug 31, 2013, 9:01 PM Aug 31, 2013, 8:51 PM

    Hi!

    I'm using my Nexus 7 in LAN, connected via WLAN. If I want to upload files from a PC in LAN using app AirDroid, I also get some errors on firewall logs, see below.
    Normaly, every access from LAN to LAN should be allowed. If I check "Easy rule: pass this traffic" it still won't work and show me an other source port.
    If I'm using the Server who provides my WLAN access point, I can upload everything. Reading from N7 via AirDroid also is working.

    Whats the problem? What can I do, to allow all that traffic?

    EDIT:

    I forgot. I'm routing from my LAN net (192.168.1.0/24) into the WLAN network (192.168.0.0/24 via the server in LAN (192.168.1.10)

    1    <1 ms    <1 ms    <1 ms  pfsense.net [192.168.1.1]
    2    <1 ms    <1 ms    <1 ms  Server.net [192.168.1.10]
    3    42 ms    5 ms    3 ms  tablet.net [192.168.0.9]

    fw1.jpg
    fw1.jpg_thumb

    Netgate 6100 MAX

    1 Reply Last reply Reply Quote 0
    • K
      kathampy
      last edited by Sep 2, 2013, 5:06 AM Sep 2, 2013, 5:03 AM

      If you're routing between LAN and WLAN using something other (192.168.1.10) than the default gateway (192.168.1.1) then you need either:

      1. Static routes on the clients on both LAN and WLAN to each other via 192.168.1.10.

      OR

      2. Static routes on the default gateways of LAN and WLAN to each other via 192.168.1.10.

      If you're using #2, you need appropriate firewall rules on the default gateways. In either case this is bad architecture and you should just use pfSense to route between LAN and WLAN and use pfSense as the default gateway for both.

      1 Reply Last reply Reply Quote 0
      • M
        mrsunfire
        last edited by Sep 2, 2013, 9:43 AM

        Hm yes, I've setup a second gateway (192.168.1.10)
        Maybe I'm blind, but where can I set static routes in pfsense? I don't want to setup them on the clients. Just share the DNS server (pfsense) via DHCP to the clients.

        Netgate 6100 MAX

        1 Reply Last reply Reply Quote 0
        • K
          kathampy
          last edited by Sep 2, 2013, 9:46 AM Sep 2, 2013, 9:45 AM

          You can also send the default gateway and additional static routes to clients using DHCP option 121. If you have two gateways, do this to prevent unnecessary load on pfSense. You must mention the default gateway in addition to any static routes in DHCP option 121.

          Better yet, stop using a separate gateway and use pfSense as a router.

          1 Reply Last reply Reply Quote 0
          • M
            mrsunfire
            last edited by Sep 2, 2013, 11:24 AM

            I know, but the problem is I need the Gateway 192.168.1.10 cause on this server is my access point for private WLAN. So only he knows the clients of his WLAN.

            Its like this:

            WLAN –-----------------------Server --------- pfSense ------------ LAN Clients
            192.168.0.0/24        192.168.1.10        192.168.1.1        192.168.1.0/24

            Netgate 6100 MAX

            1 Reply Last reply Reply Quote 0
            • K
              kathampy
              last edited by Sep 2, 2013, 11:28 AM Sep 2, 2013, 11:25 AM

              Just plug the access point into another interface on pfSense if you really want it on a separate ethernet network.

              1 Reply Last reply Reply Quote 0
              • M
                mrsunfire
                last edited by Sep 2, 2013, 11:49 AM Sep 2, 2013, 11:47 AM

                This might be an idea. But what will it change? The server is the access point, but a server also for http and so on. So I would also need him as gateway becouse pfsense dont know about the WLAN net.
                Dont forget, all other WLAN devices works fine. Its only with the nexus and while uploading files to it with airdroid app.
                What does the firewall blocks say to you? For me there is no reason to block.

                Netgate 6100 MAX

                1 Reply Last reply Reply Quote 0
                • K
                  kathampy
                  last edited by Sep 2, 2013, 11:51 AM Sep 2, 2013, 11:49 AM

                  pfSense will know when you plug the AP into another interface and give it an IP address of 192.168.0.1/24. Then plug the private interface of the server into the AP as well.

                  Android follows network spec more strictly than others (e.g. it breaks if you don't include the default gateway in DHCP option 121). It will break if you setup is invalid, which it is.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mrsunfire
                    last edited by Sep 2, 2013, 11:51 AM

                    I cant, couse AP uses the connection from server and dont has an own one. Pls read the edit of my previous post.

                    Netgate 6100 MAX

                    1 Reply Last reply Reply Quote 0
                    • K
                      kathampy
                      last edited by Sep 2, 2013, 11:52 AM

                      What kind of access point is it?

                      1 Reply Last reply Reply Quote 0
                      • M
                        mrsunfire
                        last edited by Sep 2, 2013, 11:54 AM

                        A asus pci-e wlan network card. If Im right its the PCE-N53.

                        Netgate 6100 MAX

                        1 Reply Last reply Reply Quote 0
                        • K
                          kathampy
                          last edited by Sep 2, 2013, 11:55 AM

                          Plug the AP, server's private interface and a new pfSense interface into a switch. Plug the server's LAN interface, pfSense's LAN interface and LAN clients into another switch. That is all. Use pfSense as the default gateway for everything.

                          1 Reply Last reply Reply Quote 0
                          • K
                            kathampy
                            last edited by Sep 2, 2013, 11:56 AM

                            @mrsunfire:

                            A asus pci-e wlan network card. If Im right its the PCE-N53.

                            Then just plug it into pfSense. Problem solved. You don't need to do anything else other than create firewall rules for the private WLAN.

                            1 Reply Last reply Reply Quote 0
                            • K
                              kathampy
                              last edited by Sep 2, 2013, 11:58 AM

                              You could also enable vLANs on the server and trunk the AP and LAN it to pfSense on separate LAN and WLAN interfaces over the single LAN cable.

                              1 Reply Last reply Reply Quote 0
                              • M
                                mrsunfire
                                last edited by Sep 2, 2013, 11:59 AM

                                I cant. The network card dont has an own network connection. Its usung the connection from the server to pfsense. Thats why I have an other network. Maybe I should buy a network card with RJ45 connection.
                                Dont know if vLan would work on a Windows XP machine.

                                Netgate 6100 MAX

                                1 Reply Last reply Reply Quote 0
                                • K
                                  kathampy
                                  last edited by Sep 2, 2013, 12:01 PM

                                  See my 2nd last post. Plug the wireless card directly into pfSense.

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    mrsunfire
                                    last edited by Sep 2, 2013, 12:05 PM

                                    How, without an ethernetconnection? The card only has PCI-E.
                                    http://www.asus.com/Networking/PCEN53/

                                    Netgate 6100 MAX

                                    1 Reply Last reply Reply Quote 0
                                    • K
                                      kathampy
                                      last edited by Sep 2, 2013, 12:07 PM

                                      Plug the card into pfSense and remove it from the server!

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        mrsunfire
                                        last edited by Sep 2, 2013, 12:09 PM

                                        Ah lol ok, I understood ;). I don't prefere that, becouse there is already my public WLAN (Hotspot) and not enough space.
                                        Maybe it's an idea to install a second networkcard in the server and connect it with pfsense, and bridge that to the WLAN card?!

                                        Netgate 6100 MAX

                                        1 Reply Last reply Reply Quote 0
                                        19 out of 19
                                        • First post
                                          19/19
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                          This community forum collects and processes your personal information.
                                          consent.not_received