Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ping within same vlan two hops?? (Now it's ->Destination Host Unreachable) HELP!

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 3 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by

      Wireless can not ping each other? Then you prob have isolation on your AP.. This is very common setting, where you do not want wireless clients to talk to each other.  Depending on the maker of your AP it could be called AP Isolation, Station Isolation, Client Isolation or in pfsense if wifi is on it called "Allow intra-BSS communication"

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • P Offline
        PFbest
        last edited by

        @johnpoz:

        Wireless can not ping each other? Then you prob have isolation on your AP.. This is very common setting, where you do not want wireless clients to talk to each other.  Depending on the maker of your AP it could be called AP Isolation, Station Isolation, Client Isolation or in pfsense if wifi is on it called "Allow intra-BSS communication"

        Interesting things is, I just migrated the WLAN vlans from ue1 to ue0, and wireless clients was able to ping each other.
        Nothing changed at AP side.

        :-\ :-\

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Sorry but pfsense has ZERO to do with your wireless clients talking to each other when connected to same AP.  Pfsense doesn't even need to be connected for clients of an AP to talk to each other..  Nor does your switch.. Other than getting dhcp, a gateway or using dns the rest of your network has zero to do with 2 clients connected to the same AP talking to each other.

          Client A pinging B connected to the same wifi with IPs that are in the same network has zero to do with the rest of your network in the drawing.  you sure you didn't mess up and 1 client is vlan 10 and the other is in vlan 12?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • P Offline
            PFbest
            last edited by

            @johnpoz:

            Sorry but pfsense has ZERO to do with your wireless clients talking to each other when connected to same AP.  Pfsense doesn't even need to be connected for clients of an AP to talk to each other..

            Yea, probably I should try reboot the AP, I didn't do that after migrated the vlan to new interface.
            I'll try reboot, see how it goes, also the inter-vlan smb transfer speed is slow as well  :-\

            1 Reply Last reply Reply Quote 0
            • P Offline
              PFbest
              last edited by

              [Solved]

              After changing of settings, vlan, interface etc.
              Reboot Switch, pfsense, AP.

              For ping issue, turn off "Client ARP Caching" in AP, so that ARP request will not be blocked by AP thus passed on to switch/pfsense etc. then ping will work

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                " AP thus passed on to switch/pfsense etc. then ping will work"

                Huh.. Sorry that is not how it works..

                Its not forwarding on to your switch/pfsense

                Your talking a Cisco AP right??

                When ARP caching is disabled, the access point forwards all ARP requests through the radio port to associated clients, and the client to which the ARP request is directed responds. When ARP caching is enabled, the access point responds to ARP requests for associated clients and does not forward requests to clients. When the access point receives an ARP request for an IP address not in the cache, the access point drops the request and does not forward it.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • P Offline
                  PFbest
                  last edited by

                  @johnpoz:

                  " AP thus passed on to switch/pfsense etc. then ping will work"

                  Huh.. Sorry that is not how it works..

                  Its not forwarding on to your switch/pfsense

                  Your talking a Cisco AP right??

                  When ARP caching is disabled, the access point forwards all ARP requests through the radio port to associated clients, and the client to which the ARP request is directed responds. When ARP caching is enabled, the access point responds to ARP requests for associated clients and does not forward requests to clients. When the access point receives an ARP request for an IP address not in the cache, the access point drops the request and does not forward it.

                  Yep, your quote is right.
                  Here's a more visual way to interpret ENABLED/DISABLED/OPTIONAL
                  http://www.my80211.com/cisco-auton-cli-commands/2010/3/12/autonomous-understanding-cisco-ap-arp-caching-disabled-enabl.html

                  And I suspect it's this part "When ARP caching is enabled, the access point responds to ARP requests for associated clients and does not forward requests to clients. When the access point receives an ARP request for an IP address not in the cache, the access point drops the request and does not forward it." was causing the trouble.

                  Don't know why there was no problem at all before migrating the vlan. :o Any ideas?

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Your clients changed IP?  Cache was wrong.. your AP should be able to cache and work just fine..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      PFbest
                      last edited by

                      @johnpoz:

                      Your clients changed IP?  Cache was wrong.. your AP should be able to cache and work just fine..

                      Um, it's weird, those two are both assigned with static IP from DHCP/pfsense, and "ARP Table Static Entry" ticked

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        PFbest
                        last edited by

                        @johnpoz:

                        Your clients changed IP?  Cache was wrong.. your AP should be able to cache and work just fine..

                        Do you know why when copying file from one lan to another vlan (two separate physical nic) speed is around 5-16MB/s
                        But copying from lan to vlan (same single one nic) speed is around 26MB/s

                        I can't figure out why…. :'(

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Is this wifi or wired?

                          26MB is like watching paint dry for any sort of local copy..  So I take it this is wireless?

                          If anything your hairpin should be slower then when using 2 different nics.. But what other traffic is flowing at time of copy on these nics?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            PFbest
                            last edited by

                            @johnpoz:

                            Is this wifi or wired?

                            26MB is like watching paint dry for any sort of local copy..  So I take it this is wireless?

                            If anything your hairpin should be slower then when using 2 different nics.. But what other traffic is flowing at time of copy on these nics?

                            Yep, both situation is server on 1Gbps cable, client on 300Mbps wifi.
                            For cable to cable it will be better.
                            I can accept 26Mbps when on wifi, but 5 - 16Mbps is definitely too slow  :o

                            I mean, for both conditions, gateway is involved, only difference is the first one is on same nic/port, second one involves two nic/ports.
                            But all of them are 1Gbps, and I don't see high CPU usage or high memory usage  :-\ :-\

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.