Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Hepl with 1wan 2 lan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rolg
      last edited by

      sorry i miss this info too:
      from my pc with route added
      (traceroute to the local router)
      traceroute 10.10.6.1
      traceroute to 10.10.6.1 (10.10.6.1), 30 hops max, 60 byte packets
      1  10.10.1.120 (10.10.1.120)  0.368 ms  0.352 ms  0.342 ms
      2  10.10.6.1 (10.10.6.1)  1.050 ms  1.229 ms  1.401 ms

      (traceroute to the remote router)
      traceroute 10.10.6.9
      traceroute to 10.10.6.9 (10.10.6.9), 30 hops max, 60 byte packets
      1  10.10.1.120 (10.10.1.120)  0.265 ms  0.230 ms  0.342 ms
      2  * * *
      3  * * *
      4  * * *
      5  * * *
      6  * * *
      7  * * *
      8  * * *
      9  * * *

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Figure out your subnetting.

        10.10.6.4 is also in 10.10.1.120/16.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • R Offline
          rolg
          last edited by

          yes it is
          and i know that's the problem
          i can split my lan into subnets like 10.10.1.0/24, 10.10.2.0/24…. i use from 10.10.1 to 10.10.5.
          the thing is to not to do the spliting thing
          i wanna know if this is possible, and how to do it.

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            You can't have two interfaces on conflicting subnets.  If you want to supernet, say, 10.10.0.0/16 and ROUTE THAT to another router that takes the networks and subnets it to interfaces like 10.10.1.0/24, 10.10.2.0/24, etc, you can do that but you can't assign the /16 to an interface.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • R Offline
              rolg
              last edited by

              10.10.0.0/16 its my lan prefix so if i add interfaces to my pfsense box to cover all the ranges of may lan (lets say 10.10.1.0-10.10.5.255) with prefix /24 then i can route the remote lan (10.10.6.0)?
              sorry i'm not quite understand u, i have ever do that
              thansk for answering

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                You cannot do that.  You need to understand basic IP subnetting.  Many, many sources for this information are already out there.

                Get rid of the /16 or, for the other networks, use a prefix other than 10.10.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • R Offline
                  rolg
                  last edited by

                  thanks for the tip
                  so, if i reduce my /16 to /22 then the 10.10.6… subnet gets out of my lan net so every request to that network will be managed by the gateway, its like that?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    http://www.ircbeginner.com/ircinfo/Routing_Article.pdf

                    https://www.google.com/search?q=ip+subnetting

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • R Offline
                      rolg
                      last edited by

                      thanx im reading the articles
                      as u can see i have changed some rules (marked in yellow)

                      now adding a route in my pc i can reach the remote network
                      but from inside pfsense i can't (im missing something)
                      i'll will lplay with rules in order to reach the remote network from inside pfsense, when i achieve this i'll post it

                      and when i end studying the supernetting thing i will change my lan mask and let u know how it works
                      thanks 4 all

                      nreglas.png
                      nreglas.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        Your problem is more than just rules, it's interface addresses and subnets.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.