Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't ping OPT2 gateway from OPT2 interface

    Scheduled Pinned Locked Moved Routing and Multi WAN
    14 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tubal
      last edited by

      Sorry about that.  That was a typo on my part.

      The firewall rule is IPV4 *

      Once I get it working I will tighten down the firewall rules.

      1.png
      1.png_thumb

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        And

        OPT2_GW:
        x.y.38.1

        is a typo as well? Because it overlaps your first WAN (which you ingeniously call LAN - with x.y.38.0/28; that ends with x.y.38.14; x.y.38.0 being network and  x.y.38.15 being broadcast).

        1 Reply Last reply Reply Quote 0
        • T
          Tubal
          last edited by

          No that is what my settings are.  I was thinking that might be the issue, but I wasn't sure what netmask to give my interface.

          My ISP gave me a block of 16 static IP's.

          Typically I'll get a gateway IP outside of my IP block, but this time I didn't so I'm a little unsure what to do.

          2.png
          2.png_thumb

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            I honestly fail to see what you are trying to do there. Why are you setting dual WAN when you have one line from your ISP?

            1 Reply Last reply Reply Quote 0
            • T
              Tubal
              last edited by

              I have 1 line from this ISP (Integra), and one line through a 2nd ISP (Comcast).

              My Comcast line is my primary WAN and is working as expected.

              I'm adding this 2nd WAN for redundancy.

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                Well you cannot have LAN and WAN on the same subnet. You can

                • either use 1:1 NAT
                • or bridge OPT2 to your second WAN if you want public IPs directly on hosts that are on OPT2 (and let them use x.y.38.1 as gateway.) Note that in this kind of setup, hosts on OPT2 won't be able to reach your other local interfaces.
                1 Reply Last reply Reply Quote 0
                • T
                  Tubal
                  last edited by

                  Sorry for the confusion.

                  The LAN in the earlier post was called LAN because that's what the ISP listed on their sheet.  That's not the LAN interface on my pfSense box.

                  Here is my setup:

                  WAN1 (Comcast): a.b.182.152/29 (5 usable static IP's)
                  WAN2 (Integra): x.y.38.0/28 (13 usable static IP's)
                  LAN: 10.7.0.0/24

                  Each of those interfaces carry their own distinct subnet.

                  I'm trying to get the Integra WAN set up, and you were saying that my gateway IP (x.y.38.1) was inside my interface subnet (x.y.38.0/28) and that would cause problems.  So that is most likely the issue (though I have other locations with a setup like this).

                  The setup I got from my ISP is in the attached image.  So I'm assuming I have set up the interface/gateway incorrectly for my Integra WAN.

                  2.png
                  2.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    But you still cannot have OPT2 on the same subnet like WAN2. OPT2 just cannot be x.y.38.2/28 when that's already your WAN2! Read my previous post. Describe the desired setup here, like how should the WANs be used (failover, load balancing) and what you intend to do with those IPs remaining from your /28. Also, that /28 could be used much more easily if you managed to get additional /30 to be used for your WAN2 only.

                    1 Reply Last reply Reply Quote 0
                    • T
                      Tubal
                      last edited by

                      OPT2 is WAN2 is Integra.  There is only one interface with x.y.38.2/28.

                      WAN1 (Comcast) is the primary WAN.  This is working and is what is typically used for internet access.
                      WAN2 (Integra) is the backup WAN.  This is what I am attempting to set up now.  They will use this if WAN1 goes down.
                      LAN is the local network.  I'm using 10.7.0.0/24.

                      I will set up gateway groups with failover later, but right now I just want to get WAN2 so that I can access the internet.  At this point I can't even ping the WAN2 GW (x.y.38.1) from the WAN2 interface, so obviously I've set something up wrong.

                      At this point, the only WAN2 IP I will be using is the Interface IP assigned to the pfSense box (currently x.y.38.2).  So right now I only need the WAN2 GW and the WAN2 interface IP working.

                      Sorry for all the confusion and I appreciate any help.

                      Phil

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        Enough of this mess… Why on earth is your WAN configured with allow any rule?! And why the heck are you assigning some gateway there in the firewall rules?! It's WAN, not LAN!!!

                        1 Reply Last reply Reply Quote 0
                        • T
                          Tubal
                          last edited by

                          I will figure it out.

                          Sorry for ruining your day.

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            Please, start with this: https://doc.pfsense.org/index.php/Multi-WAN

                            What you are doing there makes no sense. You need a gateway group set up for failover and use that GW group on your LAN(s). NOT WAN(s)!!! Remove the INT_GW from INTEGRA and nuke the allow any rule, your firewall is nonexistant at the moment!

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.