Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing OPT1 to WAN/LAN

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 3 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      So what are you using as AP?  Did you set a gateway on the AP?  While pfsense routes your traffic to the AP.. If the AP has no gateway how does it know to this 192.168.1 network??  By talking to pfsense IP at 10.10.10.1 ???

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • Z
        zMaliz
        last edited by

        Thanks for the reply.
        I think this is the issue.

        The AP (BT HH5) doesn't have any option for configuring a default gateway or static route.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well I wouldn't really call that a AP, its a wifi router your trying to use as just an AP.. Yeah native firmware on these things is normally pretty freaking crappy.

          So I think you have 2 choices, I doubt those home hubs allow for 3rd party that would allow you to add a gateway.

          1 get a real AP.. That would be my suggetion.
          2 source nat your connections from your lan to the opt network so that your BT HH5 thinks its just talking to something on its own network.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • Z
            zMaliz
            last edited by

            Thanks for the advise.

            I'm, looking into an AP (although I could use my Asus RT68U as an AP)

            For now if I decided to go for option 2. "2 source nat your connections from your lan to the opt network so that your BT HH5 thinks its just talking to something on its own network."

            How would I do this ?

            Thanks

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              So go to your outbound nat tab.. Change over to hybrid mode so you have automatic and any special outbounds you create..

              Vs selecting the wan, you select the opt interface that your AP is on.. Mine is called wlan, and create you nat with the source you want, and the destination you want if you want to limit what can talk to your AP.

              So you see pinging from my workstation on my lan at 192.168.9.100 to box on my wlan network.. I sniffed on the pfsense wlan interface any see it shows 192.168.9.100 ping 192.168.2.11

              I then created my outbound nat using the wlan interface and source of my 192.168.9.100 and dest of 192.168.2.11 with wlan address as the nat.  Now when I sniff and ping it shows that the pfsense interface on wlan 192.168.2.253 is pinging 192.168.2.11

              Hope that helps

              sourcenat.png
              sourcenat.png_thumb

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • Z
                zMaliz
                last edited by

                Thanks for the detailed reply.
                It didn't seem to work for me.

                For now I'll add the wireless device I have to the LAN so it will work.

                I'll also look at setting the Asus to be an Access Point, hopefully it will allow me to set routes correctly.

                Thanks again.

                1 Reply Last reply Reply Quote 0
                • Z
                  zMaliz
                  last edited by

                  Hi

                  Quick follow-up advice needed!

                  I plan to try my Asus in AP mode.
                  OPT1 has the address 10.10.10.1, I plan to set the Asus with 10.10.10.254/24 and the default gateway as 10.10.10.1

                  So daft question time..

                  Should that allow any device connecting on a 10.10.10.x address via wireless access out via my pfsense box ? Or will other routing be needed on the Asus ?

                  And do I set the WiFi devices to use .254 as there default gateway or .1 ?
                  Thanks

                  1 Reply Last reply Reply Quote 0
                  • Z
                    zMaliz
                    last edited by

                    I've set this up and it appears to be working for the wireless clients :)

                    Thanks for the help

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      "Should that allow any device connecting on a 10.10.10.x address via wireless access out via my pfsense box ? Or will other routing be needed on the Asus ?"

                      I think your not getting what an AP is…

                      "It didn't seem to work for me."

                      Well then you did it wrong ;) hehehe  That is how you source nat.. If done correctly then it would be no different then if you were on that opt network..

                      But if you got your wifi router to be able to setup a gateway, so you can manage it remotely from another network then you don't need to source nat.  Source natting like that is work around, not the correct setup.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • Z
                        zMaliz
                        last edited by

                        The ASUS can be setup and configured as a Wireless Access Point.
                        This is now in and connected to OPT1.

                        The ASUS is doing MAC filtering and is configured to use the 10.10.10.1 as it's default gateway.
                        All devices are being given DHCP addresses and network config from the OPT1 interface.

                        This all appears to be working fine. By default I've blocked all devices from the AP/OPT1 to the LAN but have allowed a small 'approved list'

                        So far so good. Thanks for the help and advice.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.