Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OPT1 as second LAN interface?

    Scheduled Pinned Locked Moved NAT
    31 Posts 8 Posters 17.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MarkAmations
      last edited by

      Ok, Ill get some screenshots up  :)

      1 Reply Last reply Reply Quote 0
      • M
        MarkAmations
        last edited by

        @Derelict:

        Can you ping the OPT1 interface from something on OPT1?

        Not able to

        1 Reply Last reply Reply Quote 0
        • M
          MarkAmations
          last edited by

          OPT1 Config

          OPT1 Firewall Rules

          Outbound Nat

          OPT1 DHCP Settings

          1 Reply Last reply Reply Quote 0
          • M
            MarkAmations
            last edited by

            @jahonix:

            What do you want to do exactly?

            With "OPT1 as LAN" you mean to have an additional port with the same subnet as LAN (aka bridged) or configure OPT1 as a different subnet?

            I want to the OPT1 interface to act like another lan port, like the deafult LAN interface

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              Kindly read the comment under the IPv4 Upstream Gateway option.

              1 Reply Last reply Reply Quote 0
              • M
                MarkAmations
                last edited by

                @doktornotor:

                Kindly read the comment under the IPv4 Upstream Gateway option.

                Sorry bout that guys ….

                1 Reply Last reply Reply Quote 0
                • M
                  MarkAmations
                  last edited by

                  I removed the gateway from OPT1 but I still cant connect to the internet or ping websites.

                  Any ideas?

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    What's that /23? What's your LAN set up like?

                    1 Reply Last reply Reply Quote 0
                    • M
                      MarkAmations
                      last edited by

                      @doktornotor:

                      What's that /23? What's your LAN set up like?

                      Here is the LAN setup

                      (please note I have never used this software before and am fairly new to the world of computer networking)

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        You cannot have two interfaces on a same subnet (OPT1: 192.168.100.6/23, LAN: 192.168.100.1/24).

                        Go read the docs about bridging: https://doc.pfsense.org/index.php/Interface_Bridges
                        Set both LAN and OPT1 IPv4/IPv6 to None
                        Assign the bridge to LAN and configure the IPs there.

                        1 Reply Last reply Reply Quote 0
                        • M
                          MarkAmations
                          last edited by

                          @doktornotor:

                          You cannot have two interfaces on a same subnet (OPT1: 192.168.100.6/23, LAN: 192.168.100.1/24).

                          Go read the docs about bridging: https://doc.pfsense.org/index.php/Interface_Bridges
                          Set both LAN and OPT1 IPv4/IPv6 to None
                          Assign the bridge to LAN and configure the IPs there.

                          Ok, I shall do that now, thank you for your help :)

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            And instead of bridging router interfaces, just get a switch.  Bridging does not save a port, it wastes a perfectly good router port.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • M
                              MarkAmations
                              last edited by

                              @Derelict:

                              And instead of bridging router interfaces, just get a switch.  Bridging does not save a port, it wastes a perfectly good router port.

                              So I can plug the default LAN straight into the HP ProCurve switch I already have?

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                Sure.

                                Say your ethernet adapter is an em0.  Plug it into an untagged interface on whatever VLAN on the ProCurve you want.  Then plug your hosts into untagged ports on the same VLAN on the switch.  By default all ports are probably on the untagged VLAN 1 so it'll just work.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  yeah what is your lan network, it doesn't overlap with that /23 you have on opt1 does it?

                                  Also you have /23 on opt1 - what do devices on opt1 network have as their mask /23.. Are they pointing to 192.168.100.6 as gateway?  The pfsense opt1 IP you set.  Can they ping the opt1 IP?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    MarkAmations
                                    last edited by

                                    Im going to reset the box and start over, I'll upload the configs in about an hour when I get it back to the point it was at (hopefully)

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      Tiago
                                      last edited by

                                      Hi Mark!

                                      Did you solve your problem?
                                      If yes, what did you do?
                                      I have the same issue here.

                                      Thanks in advance

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by

                                        Your issue is you have overlapping networks??  What are the details of your problem?  Are you trying to bridge interfaces like the OP?

                                        I doubt your having the same issue as this user..  If you are having a problem setting up a OPT1 interface I would suggest you start your own thread and post the details of your setup and what exactly  your trying to do, and what is not working..

                                        The biggest error I see with users adding opt interfaces is they do not put firewall rules on them, since when they first setup pfsense lan gets a default any any, but when you add an opt the firewall has no rules so everything is blocked.  or when they do add the rules they don't add them correctly.

                                        So if you post up your config for your lan interface and config of yoru opt1 and firewall rules and what is not working in another thread - would be happy to help you.  But not much can do with a me too type post..

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          Tiago
                                          last edited by

                                          Hi John,

                                          Thanks for your reply. I am really newbie in pfsense. I tried something in 2010 and stoped. Now I will try to set up it again!

                                          Well, for now I don´t want to set up rules for my network. I have nowadays 2 networks in my company.
                                          One LAN1 (10.0.0.x) and one router conected to one point to that LAN1 and provide another LAN2 network (192.168.1.x).
                                          I installed pfsense 2.1.5 in a machine with 3 network interface.
                                          In the first network I connected the WAN link.
                                          In the other two I am trying to set up 2 independent network.
                                          The first one (LAN) everything is fine.
                                          In the second one (OPT1), DHCP is working but I can´t access the internet.

                                          My configurations screens below (LAN, OPT1 (1), OPT1 (2), OPT1 (3), OPT1 (4)

                                          Lan_1.PNG
                                          Lan_1.PNG_thumb
                                          opt1_1.PNG
                                          opt1_1.PNG_thumb
                                          opt1_2.PNG
                                          opt1_2.PNG_thumb
                                          opt1_3.PNG
                                          opt1_3.PNG_thumb
                                          opt1_4.PNG
                                          opt1_4.PNG_thumb

                                          1 Reply Last reply Reply Quote 0
                                          • D
                                            doktornotor Banned
                                            last edited by

                                            One LAN1 (10.0.0.x) and one router conected to one point to that LAN1 and provide another LAN2 network (192.168.1.x).

                                            That's NOT what's on the screenshots. Which part of "You cannot have two interfaces on a same subnet" is still unclear?

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.