Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No internet access from LAN side

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 5 Posters 6.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      trex13
      last edited by

      Here are the screenshots:
      i've done factory reset of pfsense before that but it didn't help.

      lanrules.JPG
      lanrules.JPG_thumb
      gws.JPG
      gws.JPG_thumb
      intfs.JPG
      intfs.JPG_thumb
      dnslookup.JPG
      dnslookup.JPG_thumb
      routes.JPG
      routes.JPG_thumb
      nat.JPG
      nat.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • pttP Offline
        ptt Rebel Alliance
        last edited by

        You don't need/want a GW on LAN, please remove it ;)

        1 Reply Last reply Reply Quote 0
        • P Offline
          phil.davis
          last edited by

          Somehow people are feeling the urge to specify a gateway on LAN. pfSense understands gateways to be the way out to the rest of the internet (or at least some other networks), and a gateway set on an interface is assumed to be a general way out to "everywhere". One of the gateways has to be the default gateway, and if you specify a gateway on LAN and it is the default gateway then packets are going to spin around somewhere inside LAN and never get out.
          After removing that LAN gateway, make sure that you have a WAN gateway that points to a real upstream router that gets to the internet, and set that as the default gateway.
          I wonder if the words describing this in the initial setup scripts can be enhanced in some way so that people do not feel the urge to put a gateway on LAN?

          As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
          If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            yeah it is becoming a very recurring issue – maybe we need to create BIG FLASHING RED letters that say do not put a GW on this LAN interface unless you fully understand what that means.  And then rethink it and then don't do it!! ;)

            Can we just remove the option all together, if you you classify it as LAN interface there is NO option to put a GW on it at all.. ;)  Is this connection used as WAN/INTERNET sort of check mark, and if not checked no GW option is even available?  I am almost positive that the wizard of setup clearly skips over asking the question even - doesn't it??

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • T Offline
              trex13
              last edited by

              @ptt:

              You don't need/want a GW on LAN, please remove it ;)

              There is none selected under LAN interface "gateway" but in "status" there are 2 gateways shown(see screenshots).
              Did pfsense restart and nothing changed.

              ![GW status.jpg](/public/imported_attachments/1/GW status.jpg)
              ![GW status.jpg_thumb](/public/imported_attachments/1/GW status.jpg_thumb)
              LAN_GW.jpg
              LAN_GW.jpg_thumb
              ![trcrt LAN.jpg](/public/imported_attachments/1/trcrt LAN.jpg)
              ![trcrt LAN.jpg_thumb](/public/imported_attachments/1/trcrt LAN.jpg_thumb)
              ![trcrt wan.jpg](/public/imported_attachments/1/trcrt wan.jpg)
              ![trcrt wan.jpg_thumb](/public/imported_attachments/1/trcrt wan.jpg_thumb)

              1 Reply Last reply Reply Quote 0
              • pttP Offline
                ptt Rebel Alliance
                last edited by

                Please Remove/Delete the "GW_LAN" you Don't Need It !

                The ONLY GW that a "pfSense default install" (with 2 interfaces, WAN & LAN) Need to work "OK" is the WAN GW

                pf_WAN_GW.png
                pf_WAN_GW.png_thumb

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  3 levels of nats?  Your 3rd hop in your trace is 172.29 which is private as well..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    trex13
                    last edited by

                    @ptt:

                    Please Remove/Delete the "GW_LAN" you Don't Need It !

                    The ONLY GW that a "pfSense default install" (with 2 interfaces, WAN & LAN) Need to work "OK" is the WAN GW

                    Finally it works! Problem was that i didn't know how to delete LAN gateway because it's under "System>routing" and i tried to remove it under "interfaces>LAN(gateway)". Once i saw your SS i start opening all sub menus under "system" and found "gateways" menu.

                    Thank you and thank you johnpoz, too.

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      trex13
                      last edited by

                      @johnpoz:

                      3 levels of nats?  Your 3rd hop in your trace is 172.29 which is private as well..

                      I don't know what address is that and to whom it belongs to. I think it belongs to ISP. Can it be? My router's private LAN address is 192.168.1.1 which is first hop.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        172.29 doesn't really belong to anyone its private address space - just like your 192.168, it rfc1918 address space and clearly needed for you to have multiple boxes behind an actual public.  That is what your adsl gateway should be doing.. But your showing 2 hops past that still private??

                        I would think you have a hard time doing any sort of unsolicited inbound traffic? Port Forwards.  Shoot I would guess your clients behind pfsense are 4 nats deep, unless your ISP just routing the privates then your only 3 ;)  isp to public, your adsl to pfsense and then pfsense to your lan clients behind pfsense ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          trex13
                          last edited by

                          @johnpoz:

                          I would think you have a hard time doing any sort of unsolicited inbound traffic? Port Forwards.  Shoot I would guess your clients behind pfsense are 4 nats deep, unless your ISP just routing the privates then your only 3 ;)  isp to public, your adsl to pfsense and then pfsense to your lan clients behind pfsense ;)

                          I don't have any need for unsolicited inbound traffic on LAN interface of pfsense. I run pfsense only to have hotspot(tickets/captive portal - that's next step) for web surfing. On WAN side (192.168.1.x - 5-6 clients) I have few open ports on main router(192.168.1.1) and all unsolicited inbound traffic passes through main router fine.

                          1 Reply Last reply Reply Quote 0
                          • U Offline
                            unexpectedly
                            last edited by

                            @johnpoz:

                            yeah it is becoming a very recurring issue – maybe we need to create BIG FLASHING RED letters that say do not put a GW on this LAN interface unless you fully understand what that means.  And then rethink it and then don't do it!! ;)

                            Can we just remove the option all together, if you you classify it as LAN interface there is NO option to put a GW on it at all.. ;)  Is this connection used as WAN/INTERNET sort of check mark, and if not checked no GW option is even available?  I am almost positive that the wizard of setup clearly skips over asking the question even - doesn't it??

                            THIS.

                            Argh. I've been working on getting VLANs to work and part of that was moving DHCP off the pfsense box so I could configure the subnetting correctly. I didn't notice this put a gateway on pfsense's LAN side. And until this thread, didn't realize that was why the internet just turned off. :(

                            Thanks though! I hate having my business behind store bought wifi routers.
                            Chris

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.