Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to access internet from AP

    Scheduled Pinned Locked Moved Wireless
    17 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Your firewall rules should first block things you don't want your wi-fi clients to be able to access then pass from source BLUE net to dest any, not WAN net.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • R
        renatohtpc
        last edited by

        Thanks for the quick reply.

        Do I still need to block traffic for the blue network given that it is on its own subnet?

        Sorry for the trivial questions but I am very new to this.

        Renato

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          You need to block the traffic you want to block or it will be allowed by the pass destination any.

          Maybe it would help if you describe what you're doing and what you want wi-fi users to NOT be able to access.

          Nevermind.  I see.

          Yeah.  Below the DNS rule you want something like:

          reject IPv4 any source BLUE net dest ORANGE net
          reject IPv4 any source BLUE net dest LAN net
          reject IPv4 any Source BLUE net dest This Firewall (self)

          then your pass IPv4 source BLUE net dest any

          And you probably want to make your DNS rule TCP/UDP.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • R
            renatohtpc
            last edited by

            Like this?

            Thanks again for your help.

            Renato

            Snap10.png
            Snap10.png_thumb

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Looks good.  It really doesn't matter, but you might want to be consistent for consistency's sake on the source addresses.  Either from BLUE net or from any.  For me, I like rules that do the same thing to look the same.

              That should be working pretty well for you.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • R
                renatohtpc
                last edited by

                Derelict

                Thanks for your help. Now I have the AP working.

                Here is another question. I clearly must not understand firewall rules!

                I am trying to access the AP from the LAN network. I have the following rule on the lan.  I would have thought that these rules could allow any device on the LAN to connect to any of the other Interfaces including the BLUE interface.

                If I try and go to http://192.168.2.2 I should be able to see the netgear page. I get nothing, "The connection was reset".

                What am I missing?

                Thanks
                Renato

                Snap17.png
                Snap17.png_thumb

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Is the AP set on 192.168.2.2?  Does the AP have the proper netmask?  Can you set a default gateway on the LAN interface (that can be trouble). If not can you set static routes in the AP?  It needs to know to send traffic for anything but its own subnet (192.168.2.0/24) to pfSense for routing.  Maybe set a static route for 192.168.0.0 255.255.0.0 with a gateway of pfSense's address on that segment.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • R
                    renatohtpc
                    last edited by

                    Derelict

                    Here is a screenshot from the AP.

                    Thanks
                    Renato

                    Snap18.png
                    Snap18.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Hmm.  What happens with https?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • H
                        hda
                        last edited by

                        Does it matter/help if you give the AP a Static, outside the pool, i.s.o. a Dynamic. ?
                        I use a Zyxel 3205v2 wired to pfSense. Clients of this AP get the dynamic IP from the pfSense DHCP-server.

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          There should be no DHCP server on the AP.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • R
                            renatohtpc
                            last edited by

                            Trying to access the AP thru the https, it fails as well.

                            I have setup DHCP (192.168.2.100 -> 192.168.2.130) and a list of allowed MAC addresses on the Blue Interface.  Both the AP and my wireless devices are listed as allowed MAC addresses.

                            Right now I am only enforcing MAC addresses to control who connects to the blue Interface.

                            The AP gets a fixed IP address 192.168.2.2 and my ipad gets an address from the DHCP. The AP has the DHCP disabled as it is being handled by the Blue interface.

                            The ipad connects to the AP and is able to access the internet in addition to the Netgear web page.

                            My laptop connected to the LAN still cannot.

                            I am at a loss!

                            Renato

                            Snap20.png
                            Snap19.png
                            Snap20.png_thumb
                            Snap19.png_thumb

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Why are get address/dns dynamically both checked?

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • R
                                renatohtpc
                                last edited by

                                That's how I had it setup with IpCop.  So that the AP would get the information from the IPCOP DHCP.

                                Renato

                                1 Reply Last reply Reply Quote 0
                                • DerelictD
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  Then look in your DHCP leases for the APs MAC address and see what address your AP got and try to connect to that.

                                  I have no idea what sort of cockamamie schemes your AP manufacturer concocted.  I would give it a static.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    hda
                                    last edited by

                                    @renatohtpc:

                                    …
                                    The AP gets a fixed IP address 192.168.2.2
                                    ...

                                    W.r.t. screenshot of your post #8. First within the AP-box you should set the Static addressing and DNS to pfSense-server. So not a double entry in pfSense DHCP-leases due to dynamic & static. Do not allow the AP address as a dynamic. Secondly set the AP static in pfSense DHCP-server, of course with the correct MAC.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.