Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cant See or Ping Local LAN Clients

    Scheduled Pinned Locked Moved Firewalling
    25 Posts 6 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      Harvy66
      last edited by

      I'll assume you're using Windows. If you connect to a "new network" and you tell it "public" or in some cases, it will assume a network is public, Windows will assume local clients are hostile and will block pings and multi-casts.

      I had this issue when I attempted to VPN to my PFSense box, only to find out my wife could not ping my computer and SMB was not working. Turned out Windows assumed the network was public and was blocking everything. Once I found out how to change that setting, SMB and ping started working.

      1 Reply Last reply Reply Quote 0
      • D Offline
        DoyleChris
        last edited by

        But from a android Tablet PFsense is not letting wireless items talk to each other.

        1 Reply Last reply Reply Quote 0
        • G Offline
          georgeman
          last edited by

          Go to Interfaces –> WLAN
          Enable the option "Allow intra-BSS communication"

          Some discovery services need this. I can recall a problem with Chromecast devices for example, unless this is checked they wouldn't work.

          Best regards!

          If it ain't broke, you haven't tampered enough with it

          1 Reply Last reply Reply Quote 0
          • D Offline
            DoyleChris
            last edited by

            That is enabled.

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              You mention router - are you talking about pfsense as your router, or do you have some other router?

              I don't even see where you say that pfsense is providing your wireless, other then when asked if intra-BSS is on you say it is, so assume pfsense has a wireless card in it.  You have no other wireless routers running wireless that your devices are connected to?

              Can you draw up your network, on a napkin if that is all you have and take a picture of it with your phone if need be to post it.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • D Offline
                DoyleChris
                last edited by

                Well here is the Layout

                Internet <> Cable Modem <> WAN (DC0) <> Pfsense <> [Bridge {LAN (Bridge) <> OPT1 (DC1)}] <> WIFI (RAL0)

                Network.jpg
                Network.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  "[Bridge {LAN (Bridge) <> OPT1 (DC1)}]"

                  So your bridge has 1 interface in it?  DC1 - if it was a bridge between your wireless and your wired it would have both interfaces in..  What is the point of a bridge with 1 interface?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    DoyleChris
                    last edited by

                    thats what everybody told me to do i will post a picture of the setup.

                    Interfaces.JPG
                    Interfaces.JPG_thumb

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Show your bridge setup please - I would think that should show both interfaces.

                      See how added test bridge see how it has 2 interfaces in it.

                      bridge.png
                      bridge.png_thumb
                      examplebridge.png
                      examplebridge.png_thumb

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        DoyleChris
                        last edited by

                        Here it is.

                        Bridge.jpg
                        Bridge.jpg_thumb

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Ok what IPs do you have setup on these interfaces, and the bridge interface - and what firewall rules do you have setup?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • DerelictD Offline
                            Derelict LAYER 8 Netgate
                            last edited by

                            Ok what IPs do you have setup on these interfaces, and the bridge interface - and what firewall rules do you have setup?

                            I think that needs to be flipped around a little…

                            Ok what IP do you have setup on BRIDGE0 (WIFI and OPT2 should have none), and what firewall rules do you have setup on BRIDGE0, WIFI, and OPT2?

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              I agree they should have none - which should be his answer..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • D Offline
                                DoyleChris
                                last edited by

                                wifi and opt 2 have no IP.

                                As for rules they will be below in pictures.

                                In the lan rules dont mind the Andy Stuff.

                                ![Lan Rules.JPG](/public/imported_attachments/1/Lan Rules.JPG)
                                ![Opt 2.JPG_thumb](/public/imported_attachments/1/Opt 2.JPG_thumb)
                                ![Opt 2.JPG](/public/imported_attachments/1/Opt 2.JPG)
                                ![Lan Rules.JPG_thumb](/public/imported_attachments/1/Lan Rules.JPG_thumb)
                                ![Wifi Rules.JPG](/public/imported_attachments/1/Wifi Rules.JPG)
                                ![Wifi Rules.JPG_thumb](/public/imported_attachments/1/Wifi Rules.JPG_thumb)

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ Offline
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  What does Andy IP resolve too - I am curious to what you think those rules will accomplish?  With that one rule source IP being andy IP, if that is a local IP you could be blocking all kinds of stuff outbound from lan, like normal web traffic.  Source ports could be pretty much anything above 1024 with normal traffic.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD Offline
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    Just so I'm clear, LAN is assigned to BRIDGE0 right?

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • D Offline
                                      DoyleChris
                                      last edited by

                                      Andy's ip covers his wired and wireless IP 192.168.103, 192.168.1.113.
                                      Wel he was using Bittorrent and i told him not to and he still did it.  It blocks the ports for Bittorrent and opens up the others for web surfing and things.

                                      Yes LAN is the BRIDGE0 and all my ips are static to keep track of who is on.

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD Offline
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        Sorry - now I see your interface assignment screen cap in post #9.

                                        @DoyleChris:

                                        Andy's ip covers his wired and wireless IP 192.168.103, 192.168.1.113.

                                        Why two different subnets?  The point of bridging the two (OPT2/WIFI) is to get them on the same subnet/broadcast domain.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • D Offline
                                          DoyleChris
                                          last edited by

                                          My Mistake its 192.168.1.103 wired and 192.168.1.113 wireless sorry.

                                          1 Reply Last reply Reply Quote 0
                                          • DerelictD Offline
                                            Derelict LAYER 8 Netgate
                                            last edited by

                                            Then it should be working.  Check the software firewalls/LAN modes (public,work,etc) on the devices that can't talk to each other.  Are they getting ARP for each other?

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.