Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No internetwith bridge interface

    Scheduled Pinned Locked Moved Routing and Multi WAN
    6 Posts 2 Posters 956 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      d4sId
      last edited by

      Hi

      I have here a problem with a bridged interface. I have two WAN ports (WAN1/WAN2) in a WAN group (WANGW), two LAN ports (LAN1/LAN2) configured as a bridge (LAN), a DMZ and a SYNC interface.
      The bridge is configured as described at https://www.infotechwerx.com/blog/Creating-a-Simple-pfSense-Bridge and https://forum.pfsense.org/index.php?topic=48947.0
      Now when i send a ping at the firewall trough LAN, it's not working. When i ping trough LAN1 or LAN2 it is working.
      Any suggestions why it isn't working?

      Below the network plan and some screenshots.

      
                WAN1          WAN2 (not connected)
                 :             :
                 : 		 :
                 :             :
             .---+---.     .---+---.
             | Modem |     | Modem |
             '---+---'     '---+---'
                 |             |  
                 |             |
       WAN1(DHCP)|             |WAN2(DHCP)
            .----+-------------+-----.
            |			       +-----CARP (SYNC)------
            |        pfSense         |
            |			       +-----DMZ--------------
            '----+-------------+-----'
               LAN1|           |LAN2
      	     |	Bridge   |
      	     |		 |	
      	     +----LAN----+ 192.168.10.12
      	           |
      	           |
                         |      
      	      .---------.
                    | Switch  |
                    '---------'
                         |
                 ...-----+-----...
                 (Clients/Servers)
      
      

      Best regards
      ![Interface Assignments.png](/public/imported_attachments/1/Interface Assignments.png)
      ![Interface Assignments.png_thumb](/public/imported_attachments/1/Interface Assignments.png_thumb)
      ![Interfaces_ LAN.png](/public/imported_attachments/1/Interfaces_ LAN.png)
      ![Interfaces_ LAN.png_thumb](/public/imported_attachments/1/Interfaces_ LAN.png_thumb)
      ![Firewall_ Rules_ LAN.png](/public/imported_attachments/1/Firewall_ Rules_ LAN.png)
      ![Firewall_ Rules_ LAN.png_thumb](/public/imported_attachments/1/Firewall_ Rules_ LAN.png_thumb)
      ![Ping on LAN.png](/public/imported_attachments/1/Ping on LAN.png)
      ![Ping on LAN.png_thumb](/public/imported_attachments/1/Ping on LAN.png_thumb)

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        What's the SYNC interface for? CARP/HA are incompatible with bridges.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D Offline
          d4sId
          last edited by

          Hi Derelict

          The SYNC interface is a seperate interface only for CARP.
          What do you mean incompatible? Even if the interface is not in the bridge?

          Best regards

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            SYNC interfaces generally have nothing to do with CARP.

            Please let us know what it is you are actually doing.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • D Offline
              d4sId
              last edited by

              Hi Derelict

              I have an interfaced named SYNC for CARP. This interface ist just for the HA to the second pfsense.

              I try actually to get a connection to the internet trough the LAN bridge. The firewall itself has internet, but at the LAN port there is no internet. If i make a ping from the interface LAN1 or LAN2 it works, but not from bridge self (LAN). The network plan is in the first post, also the screenshots. The second WAN is not connected at the moment.

              Best regards

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                It doesn't sound like you actually understand what CARP is so I still have no idea what you are doing.

                Running CARP VIPs and HA with a pfSense bridge interface is not compatible.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.