Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No internet access on multiple NIC's

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    28 Posts 4 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      Koval88
      last edited by

      I didn't go with default configuration, I passed all the traffic through other interfaces like the LAN but still no internet connectivity. I can provide screenshots if that would be useful to tell what could possibly cause the issue.

      So far only my LAN works, nothing else gets internet access. Could be some misconfiguration, I did't configure pfsense with multi NIC's before, only done WAN and LAN.
      I uploaded screenshot of my Firewall rules on the NIC that has no internet access.

      Edit:
      Now my LAN stopped getting internet access. I still however able to access WebConfig page as I'm on the LAN. The LAN is the router that is bridged. Gets IP Address, default gateway, DNS but does not get internet access.

      ![Screen Shot 2015-03-14 at 12.01.54 AM.png](/public/imported_attachments/1/Screen Shot 2015-03-14 at 12.01.54 AM.png)
      ![Screen Shot 2015-03-14 at 12.01.54 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-03-14 at 12.01.54 AM.png_thumb)

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        Bridge…  I wonder what was bridged to what and how?

        1 Reply Last reply Reply Quote 0
        • K
          Koval88
          last edited by

          My router is in the bridge mode therefore acts like an AP. The  pfSense is being used as DHCP server on the LAN NIC. I've used DHCP on the AP to obtain IP Addresses.
          LAN IP/Default Gateway - 192.168.1.1/24
          DHCP Lease Range - .200 - .254.
          Then my ESXI is directly plugged into AP as that's the only way I can access ESXI server on LAN due to no Internet access and don't have a switch.
          I'll eventually move it to separate NIC once I figure to get network access and make devices on different networks/NICS communicate with each other.

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            There is something (maybe alot) I'm missing here.

            Maybe draw me a picture of this network and put here.  Network diagram.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              @Koval88:

              Now my LAN stopped getting internet access. I still however able to access WebConfig page as I'm on the LAN. The LAN is the router that is bridged. Gets IP Address, default gateway, DNS but does not get internet access.

              The first 3 rules are completely useless. The DNS one is broken is addition, since you don't allow UDP or anything else, just TCP. Ditto for the last two ones. You won't have working DNS with this, in the first place. Also, IPv6 does not work properly with ICMP blocked.

              1 Reply Last reply Reply Quote 0
              • K
                Koval88
                last edited by

                @kejianshi:

                There is something (maybe alot) I'm missing here.

                Maybe draw me a picture of this network and put here.  Network diagram.

                I'll draw it tomorrow in the morning. Current or the one I'm trying to accomplish with all Nic's?
                Ill do two just in case.

                Thanks!

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  Did you delete your default TCP + UDP pass all rule on the LAN?

                  Thats a problem as doctornotor said.

                  1 Reply Last reply Reply Quote 0
                  • K
                    Koval88
                    last edited by

                    @doktornotor:

                    @Koval88:

                    Now my LAN stopped getting internet access. I still however able to access WebConfig page as I'm on the LAN. The LAN is the router that is bridged. Gets IP Address, default gateway, DNS but does not get internet access.

                    The first 3 rules are completely useless. The DNS one is broken is addition, since you don't allow UDP or anything else, just TCP. Ditto for the last two ones. You won't have working DNS with this, in the first place. Also, IPv6 does not work properly with ICMP blocked.

                    So if I understood it correctly, get rid of first three and add one for UDP? I'll disable IPv6 as I'm not using it. Anything else I'm missing?

                    Thanks!

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      make your last rule TCP and UDP

                      Then get rid of your first 3 rules.

                      Yeah - I totally missed that your last rule didn't include UDP.  My bad.

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        @Koval88:

                        So if I understood it correctly, get rid of first three and add one for UDP? I'll disable IPv6 as I'm not using it. Anything else I'm missing?

                        Do you have some reason to block something? If not, what's wrong with ANY as protocol? At minimum, you DO want ICMP/ICMPv6, in addition to TCP/UDP.

                        1 Reply Last reply Reply Quote 0
                        • K
                          Koval88
                          last edited by

                          Technicly you're right I have no reason to block anything internally in LAN, that's what I'll have my second firewall for and will place my VM's inside NAT on the Virtual pfSense.
                          I did what you guys have told me but still unable to ping even with specific interface sites lily Google and 8.8.8.8.

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            You will never be able to ping anything with ICMP not allowed…

                            1 Reply Last reply Reply Quote 0
                            • K
                              Koval88
                              last edited by

                              Internally yes but external hosts/sites I should be able to right? At least I was able to when it was working. Still have no internet access on the bridged LAN. I'll draw a map in few hours of my network once I'll get home.
                              Thanks!

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Sigh. Allow ICMP if you want ping to work…

                                1 Reply Last reply Reply Quote 0
                                • K
                                  kejianshi
                                  last edited by

                                  Wow - Thats twice doctornotor said to be sure to allow ICMP and he was uncharacteristically polite about it….  I'd try allowing ICMP.

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    Koval88
                                    last edited by

                                    I have uploaded my network diagram. Right now all I'm trying to accomplish is to just get internet access working then I'll start planning on the virtual network.
                                    I still do not have internet access, not sure what I am doing wrong. Interfaces are in up status but no internet access from either one. I've rebooted pfsense multiple times still same issue. Thanks!

                                    ![Plan A.jpg](/public/imported_attachments/1/Plan A.jpg)
                                    ![Plan A.jpg_thumb](/public/imported_attachments/1/Plan A.jpg_thumb)
                                    ![Plan B ESXi Internally.jpg](/public/imported_attachments/1/Plan B ESXi Internally.jpg)
                                    ![Plan B ESXi Internally.jpg_thumb](/public/imported_attachments/1/Plan B ESXi Internally.jpg_thumb)

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      Which of those are you currently trying to get working?  How many 10.129.0.1 interfaces are you planning on putting on one network?

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        Koval88
                                        last edited by

                                        I'm trying to get both working. 192.168.1.1 and 10.129.0.1 network. Hoth have same configurations but no internet access. I do not know what's blocking it.

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          I meant which diagram.  Start piece by piece, one interface and function at a time until you're done.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • K
                                            Koval88
                                            last edited by

                                            Plan A, first pfsense firewall. I'm not worrying about firewall inside the ESXi server yet, moving one at a time.
                                            Thanks!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.