Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't ping or access router on OPT1 interface

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 5 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cubiche
      last edited by

      Thank you bjaffe for the input, yes the computer at 192.168.4.55 is behind the WNDR3800 plugged into a separate LAN port. That computer can access the GUI and it's the only computer on the WNDR3800. I also have a Insteon hub connected.

      1 Reply Last reply Reply Quote 0
      • B
        bjaffe
        last edited by

        Your router at 192.168.4.2 can be accessed from inside the subnet, but not outside. Does it have a default gateway set? If it has the option, it needs to be set to 192.168.4.1 (OPT1 address of pfSense). If not, the requests will make it to the router but it'll send the replies to a black hole.

        1 Reply Last reply Reply Quote 0
        • C
          cubiche
          last edited by

          is the default gateway setting on the WNDR3800? I have WAN\internet set to DHCP(wired) right now and there is no option for Gateway. If i set it to Static (Wired) I get the option for GATEWAY. that is the way I used to have it set but, decided to change it because OPT1 is set to static 192.168.4.1.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Consumer routers generally do not have the facility for a default gateway on the LAN side.

            You might be able to create a static route for 0.0.0.0/0 with a destination of the firewall interface.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • C
              cubiche
              last edited by

              do I setup the static route on the Netgear router. If so, how?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Don't know, man. This is not a netgear forum.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • C
                  cubiche
                  last edited by

                  Derelict, Thank you for reply.
                  I set it up like this: Destination-192.168.4.0/24 Interface-WAN Gateway-192.168.4.1 Is this correct?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    No. 0.0.0.0/0 dest 192.168.4.1

                    If probably does not support a default route - you're trying to use gear for something it is not designed to do - but it's worth a try.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Your other option when dealing with a device that does not allow routes, default route/gateway on its interface is to source nat it..  So now your traffic coming from your lan, pfsense would nat that to look like it came from pfsense IP In opt network, just like when you nat to the public internet.  So in that case your netgear just sees someone talking to it from its own network..

                      While this works, to be honest just get a real AP ;) hehe  Can you put 3rd party firmware on that wifi router.. Something like dd-wrt, openwrt, tomato all allow putting a default gateway on the lan interface so you can access the gui from another network.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • C
                        cubiche
                        last edited by

                        The router is flashed with Gargoyle which I think is Openwrt. I did setup the static route on the netgear like derelict suggested but, that didn't help. I still can't access the router from LAN on 1.1 iP range. I would also like to access folders on the computer connected to the router.

                        I'll try source nating. Can you provide a quick how-to?

                        Thanks johnpoz

                        1 Reply Last reply Reply Quote 0
                        • C
                          cubiche
                          last edited by

                          please check out the attached pics. is this where i setup routing and are those entries okay?

                          ![gargoyle routing.png_thumb](/public/imported_attachments/1/gargoyle routing.png_thumb)
                          ![gargoyle routing.png](/public/imported_attachments/1/gargoyle routing.png)
                          ![gargoyle basic.png_thumb](/public/imported_attachments/1/gargoyle basic.png_thumb)
                          ![gargoyle basic.png](/public/imported_attachments/1/gargoyle basic.png)

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            your not using it as a gateway any more, change it to a wireless bridge/repeater mode - now it might allow you to set default route on your lan interface..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              Yes, that thing should be set up as a dumb bridge, certainly not router/gateway.

                              1 Reply Last reply Reply Quote 0
                              • C
                                cubiche
                                last edited by

                                Ok, I set the router to wireless bridge/repeater and now  I can ping the bridge IP (192.168.4.2), the Gateway IP (192.168.4.1),
                                and Insteon hub at 192.168.4.51 all from the LAN but, i can't ping the computer. is this a pfsense issue or window/antivirus?

                                Thank you all for the help.

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  Out of box windows firewall will block pings from anything other its lock network u can change it to allow

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    cubiche
                                    last edited by

                                    Got it, Thanks. Am I bridging to the OPT1 (192.168.4.1) interface? also is OPT1 handing out DHCP?

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      Your running your wifi router as ap yes that is bride ypur opt1 could be dhcp unless u have other dhcp on that network typical would be dhcp on pfsense

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • C
                                        cubiche
                                        last edited by

                                        you're right again, OPT1 is setup as DHCP server.

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.