Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why can't this vlan get internet?

    Firewalling
    4
    16
    7.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stevebarnhart
      last edited by

      Hi all. I appareciate any help in advance, as I am new to pfsense and really networking in general and am now using it as a home firewall to try and learn about all of this. I was able to get one vlan internet access, but have tried like every rule to get this other vlan (calling it DMZ) to get internet, including even giving it an allow all rule and still no go. Any help is appreciated…the dns itself is getting blocked still!




      1 Reply Last reply Reply Quote 0
      • P
        podilarius
        last edited by

        Try restarting, specialy if you have made multiple changes. Are you using advanced outbound nat?

        1 Reply Last reply Reply Quote 0
        • M
          megamania
          last edited by

          Have the same issue and even restarted dont acess internet on my vlan…

          1 Reply Last reply Reply Quote 0
          • S
            stevebarnhart
            last edited by

            Restarting did end up fixing it for me.

            1 Reply Last reply Reply Quote 0
            • P
              podilarius
              last edited by

              @megamania:

              Have the same issue and even restarted dont acess internet on my vlan…

              Do have the VIP, rules, and NAT setup correctly? Could you give a bit more information?

              1 Reply Last reply Reply Quote 0
              • M
                megamania
                last edited by

                then tried to do but could not do the vlan vlan work with the rules and enabling dhcp on vlan, vlan has some tutorial?

                1 Reply Last reply Reply Quote 0
                • P
                  podilarius
                  last edited by

                  Yes … in the book and there used to be some at docs.pfsense.org.

                  1 Reply Last reply Reply Quote 0
                  • M
                    megamania
                    last edited by

                    and

                    1 Reply Last reply Reply Quote 0
                    • P
                      podilarius
                      last edited by

                      The rules and interface look good. What about your advanced outbound NAT?

                      1 Reply Last reply Reply Quote 0
                      • M
                        megamania
                        last edited by

                        I do not know how to make outbound nat can you help me?

                        1 Reply Last reply Reply Quote 0
                        • P
                          podilarius
                          last edited by

                          There are docs at http://doc.pfsense.org on how to get that done. Auto might work, but I always wanted to be sure with manually added outbound NAT.

                          1 Reply Last reply Reply Quote 0
                          • M
                            megamania
                            last edited by

                            this is how i make que outbound nat:

                            1 Reply Last reply Reply Quote 0
                            • P
                              podilarius
                              last edited by

                              You are going to need a rule for each interface and virtual interface aside from VPN and WAN to make sure that everything is working.

                              1 Reply Last reply Reply Quote 0
                              • M
                                megamania
                                last edited by

                                i need to make more 2 rules to WAN's and 1 LAN?
                                equal i have to vlan?

                                1 Reply Last reply Reply Quote 0
                                • P
                                  podilarius
                                  last edited by

                                  The interface is all WAN … it is the subnets that change. The subnets will match your VLANs and LAN.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    cmb
                                    last edited by

                                    You don't have anything there that appears to need manual outbound NAT, best to keep to automatic as it'll take care of the proper rules for you (and what you showed in the last screenshots is very wrong). With automatic outbound NAT and the firewall rule shown, you're set as long as the VLAN in general functions and is setup correctly on your switch(es). Make sure you can ping the firewall IP on that VLAN. See if DNS resolution works.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.