Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What am i doing wrong ?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    30 Posts 7 Posters 6.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Azoic
      last edited by

      @wallabybob:

      I second Phil's request for a network diagram. Please include interface IP addresses and network masks.

      PERHAPS your WAN interface is set to "Block Private Networks". (It shouldn't be in your case.) See Interfaces -> WAN and scroll down to the Private networks section.

      Thanks for the replies guys. I tried to be clear on my description in my 1st post, but it seems i wasnt very good.
      The Block private networks checkbox is not selected, Bogan networks IS selected, i got caught by that one on the first install of pfSense to this box, and made sure i didnt get caught again…but thanks for the suggestion

      The setup at this point in time is :

      Internet -- Modem (10.1.1.1 with DHCP for 5 Addresses only) -- WGR614 Wireless Router (WAN  IP 10.1.1.3 - LAN IP 192.168.1.1  DHCP range 192.168.1.50 -192.168.1.75 ) -- LAN connections from wireless router are single cable to one PC, and single cable to 10/100 Switch for 4 more PC's in another room.

      Modem subnet is 255.0.0.0 all other PC's and devices inline are 255.255.255.0

      At the moment this all works fine, no issues are found.

      The problem arises when i insert the pf box between the modem and the Wireless Router. The pf box gets a WAN IP of 10.1.1.5 and it should see the outside world, it's LAN IP has been changed to 192.168.1.45 as the default is already used by the wireless.

      I CANT alter the wireless LAN IP as everytime i do, it locks me out of the entire GUI and needs a reset to default. Being a Netgear device this is no surprise, it has been this way since the day i bought it, and it even stumped my brother who is an IT Project manager and has forgotten more about computers than i will ever know.

      I tried removing the Wireless Router entirely and connected the modem to the WAN NIC of the pf box, it got an IP of 10.1.1.5 as expected, i connected my cable to the LAN NIC and via my switch i could access the pf Dashboard and all settings no worries, i can also use pUTTY to access the shell. But the outside world is just not there, on the Dashboard page, pf tries to check for updates, but cant access the Internet.

      This leads me to believe its an issue in the modem. It has its firewall turned on, but i can browse fine with the setup i have now, so adding pfSense box should work fine, i would have thought.

      Any thoughts ??

      Thanks Again

      p.s: NEVER BUY NETGEAR.....they are nothing but a headache, and have no support at all from the company....their Tech Support dont want to know anythng if you have an issue to resolve. ABSOLUTELY NO HELP AT ALL

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        You probably have a private IP on your WAN and that is blocked by default.  You need to unblock it in interfaces > WAN > bottom of page.
        Uncheck Block private networks.

        If that is not the problem, I suspect either bad DNS setup or firewall rules on the LAN are not correct.

        1 Reply Last reply Reply Quote 0
        • P
          phil.davis
          last edited by

          Have a look at Status-Interfaces for your WAN. It needs to have something good for the DNS servers, which should have come along with the 10.1.1.5 DHCP lease. If not, then put a DNS server or 2 in System-General Setup (e.g. the Google DNS Servers 8.8.8.8 and 8.8.4.4)
          Can you "ping 8.8.8.8" from the shell - that would show that IP connectivity works, and therefore the problem is likely just in translating names with DNS.

          As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
          If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

          1 Reply Last reply Reply Quote 0
          • A
            Azoic
            last edited by

            @phil.davis:

            Have a look at Status-Interfaces for your WAN. It needs to have something good for the DNS servers, which should have come along with the 10.1.1.5 DHCP lease. If not, then put a DNS server or 2 in System-General Setup (e.g. the Google DNS Servers 8.8.8.8 and 8.8.4.4)
            Can you "ping 8.8.8.8" from the shell - that would show that IP connectivity works, and therefore the problem is likely just in translating names with DNS.

            Did all this and more, thought i had it working at one point, as i could ping and traceroute from the pf box to various IP's, and the update manager changed from cannot check for update to running the latest version, but still no browsing.
            I rebooted the pf box and my pc 3-4 times each and reset the network adapter in my pc 10 times or more. Each time it came up as pfsense network, showed both local and internet connection, but still no browse. Added my ISP's supplied DNS server IP and the two google ones, nothing helped.
            And all i get now is the network comes up local and internet, then drops out, in under 30 seconds, to local only in the Network and Sharing window on my pc.
            I just can't work it out, nothing i try seems to fix it.

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              Please post a pic of your firewall rules for LAN and WAN, your DHCP settings for LAN and WAN, your general settings page and the gateway status page.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                What do you mean insert pfsense?

                So you now have this

                internet - NAT Router (not modem modems do NOT NAT) - pfsense - netgear - switch - pc

                And your pfsense of lan is on 192.168.1.0/24 and so is lan of netgear?

                Do not connect your netgear using is wan, connect it via is lan to pfsense and TURN off the netear dhcp server..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  192.168.1.45 is still in the 192.168.1.1/24 subnet that your wifi router is probably using. Each segment needs to be a different subnet, try changing the pfSense LAN to 192.168.100.1 for example.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    Please, get some system info what you are doing. Basically you want

                    • modem as a bridge
                    • pfsense with the WAN IP assigned directly
                    • AP somewhere on LAN with everything disabled, incl. the WAN, DHCP and whatever. Totally dumbed AP.
                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      ^ exactly!  This would be normal common setup..

                      If your "modem" (isp connection device) does not support bridge mode and you have to double nat - then ok, but you sure and the hell do not want to add a triple nat to the mix.  Your netgear should be used as just a Access Point.

                      Then put wan of pfsense into the dmz of your isp device, and control your forwards at pfsense.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • A
                        Azoic
                        last edited by

                        Thanks, i am aware of how it's supposed to be, it's just not playing fair with me.
                        I know it's a simple thing i have missed and am missing, but it's driving me around the bend….

                        I wish i could have the WAP as a standalone, but even following the Netgear instructions on how to set it as one fails....this bloody thing will be the death of me.
                        I'm sure i will figure it out one day, but right now it's beginning to piss me off.

                        1 Reply Last reply Reply Quote 0
                        • K
                          kejianshi
                          last edited by

                          Well - Do things in baby steps.

                          Put the wireless router aside.  Get yourself a cat 5 cable.  Connect that to the LAN of pfsense and your computer. Directly connect your pfsesne WAN to the modem also.  Get that working.

                          If you intend to have an OPT1 interface, create that and test it directly connected to your computer.  Get that working.

                          Then when modem > pfsense is working perfectly, then add the wireless AP to the picture.

                          In my opinion, currently, you can't know what is and is not working.

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            And as for Netgear AP, there are tons of alternative much better firmwares, such as DD-WRT, Tomato or OpenWRT. Sadly, for your prehistoric model, the only way is to solder something better than the crappy 1MB chip on the board. Best dumped, frankly. Not worth the waste of time.

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              Yeah its not worth time and effort dicking with older wireless routers if you ask me.  I just picked up a tp-link dual band wdr3600 I believe is the model number for $42 to my door.

                              Took all of 30 seconds to put dd-wrt on it.. And now got nice stable N both 2.4 and 5ghz AP – my old reliable wrt54gL was still working - but it was about time I moved to N.. only thing left that was g is my sons old laptop everything else is N.

                              As to getting it to work as AP - what do they have you doing.. The thing already has a 192.168.1.1 address right, leave it at that change pfsense to say .254 and turn off netgear dhcp server = bing bang zoom accesspoint.  Just connect it to your switch or pfsense via the netgears LAN port..  Put some tape over the wan port on the netgear you have no use for it if using it as AP.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                If you have all three routers in line they must have different subnets between them. Did you try my earlier suggestion?

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • A
                                  Azoic
                                  last edited by

                                  @stephenw10:

                                  If you have all three routers in line they must have different subnets between them. Did you try my earlier suggestion?

                                  Steve

                                  Im not sure if i tried all the things everyone suggested so far, i haven't had time in the last couple of days to do much.
                                  I've had family issues come up , and have had no time for network tinkering, especially when my server 2003 box died and i had to
                                  spend time getting that fixed.
                                  I haven't given up, i'm still tinkering, just a few minutes a day instead of the few hours i would normally have.

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Azoic
                                    last edited by

                                    @doktornotor:

                                    And as for Netgear AP, there are tons of alternative much better firmwares, such as DD-WRT, Tomato or OpenWRT. Sadly, for your prehistoric model, the only way is to solder something better than the crappy 1MB chip on the board. Best dumped, frankly. Not worth the waste of time.

                                    I know it's old, but once it's set-up. it is stable and does what i need, i rarely use the wireless, it's mainly inline to use it as a second switching device.
                                    I will be buying a real switch soon, and an dedicated WAP device to replace the Netgear, but each time i save the money for it, something comes up that eats up the savings…
                                    It's hard to save any cash with the house, car and 5 kids , especially as i'm on a pension.

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      How long does it take to turn off the dhcp server?  That is ALL you have to do to turn that router into a accesspoint, and not use its wan/internet port to connect it to your network.

                                      You have to uncheck 1 box, and connect it to your network via one of its lan ports vs its wan/internet and shazam its an AP

                                      uncheckthis.png
                                      uncheckthis.png_thumb

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • A
                                        Azoic
                                        last edited by

                                        @johnpoz:

                                        How long does it take to turn off the dhcp server?  That is ALL you have to do to turn that router into a accesspoint, and not use its wan/internet port to connect it to your network.

                                        You have to uncheck 1 box, and connect it to your network via one of its lan ports vs its wan/internet and shazam its an AP

                                        I thank you for the post, but seriously, this thing is not a simple matter of unchecking a radio button….its a f**king nightmare this bloody thing, from day one it's been a son of a bitch.....i change one thing in it i can't access it...and have to reset to default...it's a feckin' nightmare....i swear.....but like i said, when i have the time to tinker i will, i have far more important things to think about this week, i have a funeral to organise now, and now a 16 month old grandchild just diagnosed with a hole in her heart. Damn firewall can wait.

                                        The only reason i have replied to this post is to show i have read all, and am appreciating the assistance...when i can i will get back to the issue, but for now, it's of no importance.

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          Dude I have no idea what you have done in the past - but I am telling you to turn ANY wireless router into an access point is simple disable of dhcp on the wireless router, and connect it via LAN port.  That is it.

                                          I looked on your routers web ui via emulator and to disable dhcp all that is required is uncheck the enable box and click save..

                                          I have done this on hundreds of wireless routers.. No matter the make, no matter the brand.  In your setup you don't even have to change the wireless routers lan IP..  Since its on the default network pfsense lan network defaults too.. All you have to do is change pfsense lan IP to not be 192.168.1.1 - make it 192.168.1.254 for example.  As long as you don't have something else already using 192.168.1.254 your ready to go.  Just connect in your wireless router via its LAN PORT to your pfsense lan inteface or a switch connected to your pfsense lan port already.  And you done!

                                          If this takes you more than 30 seconds then your doing something wrong!

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          1 Reply Last reply Reply Quote 0
                                          • A
                                            Azoic
                                            last edited by

                                            @johnpoz:

                                            Dude I have no idea what you have done in the past - but I am telling you to turn ANY wireless router into an access point is simple disable of dhcp on the wireless router, and connect it via LAN port.  That is it.

                                            I looked on your routers web ui via emulator and to disable dhcp all that is required is uncheck the enable box and click save..

                                            I have done this on hundreds of wireless routers.. No matter the make, no matter the brand.  In your setup you don't even have to change the wireless routers lan IP..  Since its on the default network pfsense lan network defaults too.. All you have to do is change pfsense lan IP to not be 192.168.1.1 - make it 192.168.1.254 for example.  As long as you don't have something else already using 192.168.1.254 your ready to go.  Just connect in your wireless router via its LAN PORT to your pfsense lan inteface or a switch connected to your pfsense lan port already.  And you done!

                                            If this takes you more than 30 seconds then your doing something wrong!

                                            I did that already and it did nothing, but somehow, its working now, i reset it to default, and suddenly it came up working.
                                            Stupid thing is, i had done this a dozen or more times already.

                                            Thanks to all who offered suggestions, everything is working now.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.