Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't ping OPT2 gateway from OPT2 interface

    Scheduled Pinned Locked Moved Routing and Multi WAN
    14 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      And

      OPT2_GW:
      x.y.38.1

      is a typo as well? Because it overlaps your first WAN (which you ingeniously call LAN - with x.y.38.0/28; that ends with x.y.38.14; x.y.38.0 being network and  x.y.38.15 being broadcast).

      1 Reply Last reply Reply Quote 0
      • T
        Tubal
        last edited by

        No that is what my settings are.  I was thinking that might be the issue, but I wasn't sure what netmask to give my interface.

        My ISP gave me a block of 16 static IP's.

        Typically I'll get a gateway IP outside of my IP block, but this time I didn't so I'm a little unsure what to do.

        2.png
        2.png_thumb

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          I honestly fail to see what you are trying to do there. Why are you setting dual WAN when you have one line from your ISP?

          1 Reply Last reply Reply Quote 0
          • T
            Tubal
            last edited by

            I have 1 line from this ISP (Integra), and one line through a 2nd ISP (Comcast).

            My Comcast line is my primary WAN and is working as expected.

            I'm adding this 2nd WAN for redundancy.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              Well you cannot have LAN and WAN on the same subnet. You can

              • either use 1:1 NAT
              • or bridge OPT2 to your second WAN if you want public IPs directly on hosts that are on OPT2 (and let them use x.y.38.1 as gateway.) Note that in this kind of setup, hosts on OPT2 won't be able to reach your other local interfaces.
              1 Reply Last reply Reply Quote 0
              • T
                Tubal
                last edited by

                Sorry for the confusion.

                The LAN in the earlier post was called LAN because that's what the ISP listed on their sheet.  That's not the LAN interface on my pfSense box.

                Here is my setup:

                WAN1 (Comcast): a.b.182.152/29 (5 usable static IP's)
                WAN2 (Integra): x.y.38.0/28 (13 usable static IP's)
                LAN: 10.7.0.0/24

                Each of those interfaces carry their own distinct subnet.

                I'm trying to get the Integra WAN set up, and you were saying that my gateway IP (x.y.38.1) was inside my interface subnet (x.y.38.0/28) and that would cause problems.  So that is most likely the issue (though I have other locations with a setup like this).

                The setup I got from my ISP is in the attached image.  So I'm assuming I have set up the interface/gateway incorrectly for my Integra WAN.

                2.png
                2.png_thumb

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  But you still cannot have OPT2 on the same subnet like WAN2. OPT2 just cannot be x.y.38.2/28 when that's already your WAN2! Read my previous post. Describe the desired setup here, like how should the WANs be used (failover, load balancing) and what you intend to do with those IPs remaining from your /28. Also, that /28 could be used much more easily if you managed to get additional /30 to be used for your WAN2 only.

                  1 Reply Last reply Reply Quote 0
                  • T
                    Tubal
                    last edited by

                    OPT2 is WAN2 is Integra.  There is only one interface with x.y.38.2/28.

                    WAN1 (Comcast) is the primary WAN.  This is working and is what is typically used for internet access.
                    WAN2 (Integra) is the backup WAN.  This is what I am attempting to set up now.  They will use this if WAN1 goes down.
                    LAN is the local network.  I'm using 10.7.0.0/24.

                    I will set up gateway groups with failover later, but right now I just want to get WAN2 so that I can access the internet.  At this point I can't even ping the WAN2 GW (x.y.38.1) from the WAN2 interface, so obviously I've set something up wrong.

                    At this point, the only WAN2 IP I will be using is the Interface IP assigned to the pfSense box (currently x.y.38.2).  So right now I only need the WAN2 GW and the WAN2 interface IP working.

                    Sorry for all the confusion and I appreciate any help.

                    Phil

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      Enough of this mess… Why on earth is your WAN configured with allow any rule?! And why the heck are you assigning some gateway there in the firewall rules?! It's WAN, not LAN!!!

                      1 Reply Last reply Reply Quote 0
                      • T
                        Tubal
                        last edited by

                        I will figure it out.

                        Sorry for ruining your day.

                        1 Reply Last reply Reply Quote 0
                        • D
                          doktornotor Banned
                          last edited by

                          Please, start with this: https://doc.pfsense.org/index.php/Multi-WAN

                          What you are doing there makes no sense. You need a gateway group set up for failover and use that GW group on your LAN(s). NOT WAN(s)!!! Remove the INT_GW from INTEGRA and nuke the allow any rule, your firewall is nonexistant at the moment!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.