Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't access internet

    Scheduled Pinned Locked Moved Routing and Multi WAN
    14 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      blcrazzy
      last edited by

      You didn't mentioned your firewall rules. Please verify that all is configured as desired.
      Also, please have a look on your firewall logs and check if you see you web traffic passing or blocked. Make sure that you marked the "Log packets…" on each of your firewall rules.

      1 Reply Last reply Reply Quote 0
      • J Offline
        jmarc
        last edited by

        The lan rules ar the basic ones
        Anti-lockout rule
        Default allow LAN to any rule
        Tried to go to google's IP 216.58.208.202 with the browser and the log shows as pass, but i can't reach the site.

        Selection_046a.jpg
        Selection_046a.jpg_thumb

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann
          last edited by

          You must not check "Block private networks" on WAN interface if you have a private subnet on WAN!

          1 Reply Last reply Reply Quote 0
          • J Offline
            jmarc
            last edited by

            I've removed the "block private networks" and checked "Disable hardware checksum offload"
            Still no access, but new fwall log that shows blocks

            Selection_047b.jpg
            Selection_047b.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann
              last edited by

              The two blocks on LAN are IPv6. Maybe you've disabled IPv6.
              You can display the appropriate rule in the log by activate this in the log setting (Where to show rule descriptions).

              There are allowed access shown in the log to a private network. I don't know if this is on WAN or another internal one.

              Is your outbound NAT configured correctly?

              1 Reply Last reply Reply Quote 0
              • J Offline
                jmarc
                last edited by

                I do indeed block IPv6
                My outbound NAT is set to automatic.
                The Wan network range is 192.168.170.1/24 That's the ISP router internal network.

                1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann
                  last edited by

                  The last log in your screenshot shows permitted https access to the internet. So if that doesn't work, I assume that responses do not come back to the source host.

                  If your outbound NAT is set to automatic packets source address should be translated to WAN address and everything should work properly.

                  Ensure that your WAN subnet is configured correctly at pfSense and your router. Check the mask.
                  For troubleshooting do a packet capture (Diagnostic menu) on WAN and LAN while you try to attempt a public site.

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    jmarc
                    last edited by

                    The mask for the 192.168.170.0 network is 255.255.255.0
                    The one setup in the wan gateway is 192.168.170.1/24
                    Attaching the capture file

                    [185.31 log.txt](/public/imported_attachments/1/185.31 log.txt)

                    1 Reply Last reply Reply Quote 0
                    • V Offline
                      viragomann
                      last edited by

                      For evaluating the packet capture, it's necessary to know on which interface it is taken.
                      If this is from LAN it's okay, if it's from WAN your outbound NAT doesn't work.

                      If you do again a capture, please select IPv4 address family and TCP protocol for more clarity.

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        jmarc
                        last edited by

                        Here's a new capture
                        Interface: lan
                        address family:ipv4
                        protocol tcp

                        Thanks

                        [185.31 log.txt](/public/imported_attachments/1/185.31 log.txt)

                        1 Reply Last reply Reply Quote 0
                        • V Offline
                          viragomann
                          last edited by

                          As said above, for LAN the former capture was okay anyway. It depends on WAN.

                          1 Reply Last reply Reply Quote 0
                          • J Offline
                            jmarc
                            last edited by

                            Did another test.
                            From the pfsense console i was able to download a file with curl.
                            Tried from a std ubuntu server and it fails.
                            So there's really a block from lan to wan.  :'(

                            1 Reply Last reply Reply Quote 0
                            • V Offline
                              viragomann
                              last edited by

                              A misconfigured outbound NAT could cause the same effect.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.