Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access to the internet

    Scheduled Pinned Locked Moved Routing and Multi WAN
    26 Posts 4 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      1. For internet access the destination should be any.

      You should also be passing IPv4 any protocol, not just TCP.

      2. You don't need any rules on WAN1 or WAN2 unless you want to pass connections FROM the internet INTO pfSense (you are running servers that internet users need to access).

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • L
        lfreez
        last edited by

        @Derelict:

        1. For internet access the destination should be any.

        You should also be passing IPv4 any protocol, not just TCP.

        2. You don't need any rules on WAN1 or WAN2 unless you want to pass connections FROM the internet INTO pfSense (you are running servers that internet users need to access).

        thanks Derelict for your quick response.. now I changed like you said but still both networks using same gateway for access to the internet

        what about floating rules is that necessary??

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          No.

          Firewall–> Rules-->LAN

          1.added 2 rules for my 2 networks

          Eg-  LAN 1
          Action            - pass
          Interface          - LAN
          Protocol          - TCP
          Source            - type    - network
                                  address  - 10.238.56.0/24
          destination      - type    - single host or alias/network/wan1 net/wan1 address/wan2 net/wan2 address
                                  address  -
          advance features --> Gateway - WAN1

          Eg-  LAN 2 same as above

          Can you do screenshots of both Firewall > Rules pages for both LAN interfaces?  Both System > Routing > Gateways?

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • L
            lfreez
            last edited by

            yes I can

            1 Reply Last reply Reply Quote 0
            • L
              lfreez
              last edited by

              here are that screenshots -

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Might be just me but those are mostly too low-resolution to read.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • L
                  lfreez
                  last edited by

                  sorry

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    What's LANGW, a gateway group?

                    1 Reply Last reply Reply Quote 0
                    • L
                      lfreez
                      last edited by

                      @KOM:

                      What's LANGW, a gateway group?

                      you mean….  System: Gateways --> LANGW

                      that is my LAN

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Yeah those images aren't any good either.  Just attach the images using the attachment tool in the forum posting form.  Works great.  Not sure why people insist on doing something else.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Nope.  Still just thumbnails for me.  Dont have time to deal with why multiple browsers don't display postimg correctly.  Post them so people can see them.

                          ![Screen Shot 2015-08-30 at 12.33.21 AM.png](/public/imported_attachments/1/Screen Shot 2015-08-30 at 12.33.21 AM.png)
                          ![Screen Shot 2015-08-30 at 12.33.21 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-08-30 at 12.33.21 AM.png_thumb)

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            Not for me they're not.  Even after clearing cache 4 of 5 are still thumbnails.

                            ![Screen Shot 2015-08-30 at 12.43.51 AM.png](/public/imported_attachments/1/Screen Shot 2015-08-30 at 12.43.51 AM.png)
                            ![Screen Shot 2015-08-30 at 12.43.51 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-08-30 at 12.43.51 AM.png_thumb)

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Current Firefox, Current Safari, Current Chrome.  Dude needs to post so people can read it.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                No proxies, bro.  (IE11 in a Windows 7 VM for good measure.  Same result.  Images 1,3,4,5 thumbnails.  2 is legible.)

                                Unless it's ISP shenanigans but that would be a first here.

                                Same results on Firefox and IE on Windows 7 VM in a datacenter on a completely different ISP.  Maybe it's you who needs to force-reload.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • D
                                  doktornotor Banned
                                  last edited by

                                  Are you having your days, or what? Get some sanitary products, perhaps, and go vent those issues elsewhere. Images re-attached for convenience of Mr. Derelict Asshole.

                                  LAN.jpg
                                  LAN.jpg_thumb
                                  WAN1.jpg
                                  WAN1.jpg_thumb
                                  WAN2.jpg
                                  WAN2.jpg_thumb
                                  Gateways.jpg
                                  Gateways.jpg_thumb
                                  Routes.jpg
                                  Routes.jpg_thumb

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    I'll be sure to include quotes next time so you can't delete the context when you're proven to be going off in your typical abrasive fashion but are totally wrong.

                                    NOTHING pisses me off more than being told I'm wrong by some nonsensical blowhard when I know (and can prove) I'm right.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      Ugh.  So OP is trying to MultiWAN by using two different IP subnets on the same LAN segment.  Instead of laying into me why don't you lay into that in your usual manner.

                                      Or is there an L3 switch/downstream router we weren't told about?

                                      OP what is LANGW?

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • L
                                        lfreez
                                        last edited by

                                        @Derelict:

                                        Ugh.  So OP is trying to MultiWAN by using two different IP subnets on the same LAN segment.  Instead of laying into me why don't you lay into that in your usual manner.

                                        Or is there an L3 switch/downstream router we weren't told about?

                                        OP what is LANGW?

                                        yes there is L3 switch and routing between these networks are working fine.
                                        10.238.81.0  network that pfsense server exist
                                        10.238.56.0  users VLAN1
                                        10.238.59.0  users VLAN2

                                        LANGW is LAN  network (10.238.81.0) that pfsense server exist

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.