Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple LAN not routing to default gateway

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    12 Posts 3 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      makyan
      last edited by

      Thanks,

      I have check all as suggested and this is the only discrepancy:

      Under diagnostic > routes, it is blank. There is nothing listed here.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        After a few seconds gathering the data, it should show similar to the attachment - and you definitely need a default route (I put a red box around it).
        That is really weird. From the command line try:

        netstat -r
        

        That had better spit out a list of routes the box knows about, or some error as to why you have no routing.

        RoutingTable.png
        RoutingTable.png_thumb

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • M
          makyan
          last edited by

          Hi.

          Sorry my mistake, the default route is appearing there, but still no traffic routing from internal vlana unless I set a policy based 'gateway' routenin the firewall rules

          1 Reply Last reply Reply Quote 0
          • P
            phil.davis
            last edited by

            Hmmm, now I am struggling  :(

            and I have set a "default allow rule" on the firewall.

            Assuming that rule is on the vlana interface, then the traffic will be passed through to the normal routing and should go out the default gateway.
            And I assume the IP address listed for the default route is actually the IP address of the upstream router/ISP on WAN?

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • M
              makyan
              last edited by

              I know, I have been scratching my head all afternoon.

              The rule is from vlana (first lan vlan) to any - allow/pass.

              Correct the IP in the default route is the IP provided by DHCP from the upstream router.

              1 Reply Last reply Reply Quote 0
              • P
                phil.davis
                last edited by

                I think it is time to post the rule/s you have - there might (must?) be some odd rule setting that is causing it not to match traffic.

                As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                1 Reply Last reply Reply Quote 0
                • M
                  makyan
                  last edited by

                  Thanks for your persistence.

                  This is the only rule (attached) that is applied on the VLAN-A (vlana).

                  Regarding the rules on the WAN: It is pass: IPv4 from * to * with no other settings.

                  VLAN-a.JPG
                  VLAN-a.JPG_thumb

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    If by simply applying a gateway (policy based route) to the default LAN rules you can get out to the internet it seems pretty clear that the system routing must be incorrect. When you apply a gateway to override the system routing.

                    @makyan:

                    Sorry my mistake, the default route is appearing there

                    But what is the default route? Is it correct?

                    You never directly answered Phil as to whether there are any gateways on any LAN interface. You should have only one gateway defined and it should be on WAN, as listed in System: Routing: Gateways:

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • M
                      makyan
                      last edited by

                      Sorry - there is no gateway set In the vlan-a.

                      The only gateway listed under system routing gateways is the correct gateway for the wan.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        In fact re-reading this I see you did say you'd checked all of Phils suggestions. Better to double check.  ;)

                        Ok, so the system default gateway is on the correct interface but is it correct? Presumably, since you have only one gateway, when you set the gateway in the LAN rule you only have the one choice: WAN_DHCP. So that would imply the gateway is correct. So what is different when you specify a gateway? One thing that does change is that specifying a gateway negates any static routes you might have entered, do you have any?

                        It would be much easier if you showed us your routing table. Redact anything you deem to be confidential.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.