Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't access internet

    Scheduled Pinned Locked Moved Routing and Multi WAN
    14 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jmarc
      last edited by

      The lan rules ar the basic ones
      Anti-lockout rule
      Default allow LAN to any rule
      Tried to go to google's IP 216.58.208.202 with the browser and the log shows as pass, but i can't reach the site.

      Selection_046a.jpg
      Selection_046a.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        You must not check "Block private networks" on WAN interface if you have a private subnet on WAN!

        1 Reply Last reply Reply Quote 0
        • J Offline
          jmarc
          last edited by

          I've removed the "block private networks" and checked "Disable hardware checksum offload"
          Still no access, but new fwall log that shows blocks

          Selection_047b.jpg
          Selection_047b.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            The two blocks on LAN are IPv6. Maybe you've disabled IPv6.
            You can display the appropriate rule in the log by activate this in the log setting (Where to show rule descriptions).

            There are allowed access shown in the log to a private network. I don't know if this is on WAN or another internal one.

            Is your outbound NAT configured correctly?

            1 Reply Last reply Reply Quote 0
            • J Offline
              jmarc
              last edited by

              I do indeed block IPv6
              My outbound NAT is set to automatic.
              The Wan network range is 192.168.170.1/24 That's the ISP router internal network.

              1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann
                last edited by

                The last log in your screenshot shows permitted https access to the internet. So if that doesn't work, I assume that responses do not come back to the source host.

                If your outbound NAT is set to automatic packets source address should be translated to WAN address and everything should work properly.

                Ensure that your WAN subnet is configured correctly at pfSense and your router. Check the mask.
                For troubleshooting do a packet capture (Diagnostic menu) on WAN and LAN while you try to attempt a public site.

                1 Reply Last reply Reply Quote 0
                • J Offline
                  jmarc
                  last edited by

                  The mask for the 192.168.170.0 network is 255.255.255.0
                  The one setup in the wan gateway is 192.168.170.1/24
                  Attaching the capture file

                  [185.31 log.txt](/public/imported_attachments/1/185.31 log.txt)

                  1 Reply Last reply Reply Quote 0
                  • V Offline
                    viragomann
                    last edited by

                    For evaluating the packet capture, it's necessary to know on which interface it is taken.
                    If this is from LAN it's okay, if it's from WAN your outbound NAT doesn't work.

                    If you do again a capture, please select IPv4 address family and TCP protocol for more clarity.

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jmarc
                      last edited by

                      Here's a new capture
                      Interface: lan
                      address family:ipv4
                      protocol tcp

                      Thanks

                      [185.31 log.txt](/public/imported_attachments/1/185.31 log.txt)

                      1 Reply Last reply Reply Quote 0
                      • V Offline
                        viragomann
                        last edited by

                        As said above, for LAN the former capture was okay anyway. It depends on WAN.

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          jmarc
                          last edited by

                          Did another test.
                          From the pfsense console i was able to download a file with curl.
                          Tried from a std ubuntu server and it fails.
                          So there's really a block from lan to wan.  :'(

                          1 Reply Last reply Reply Quote 0
                          • V Offline
                            viragomann
                            last edited by

                            A misconfigured outbound NAT could cause the same effect.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.