Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help?! No internet from LAN unless using a vpn client?

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kejianshi
      last edited by

      I think your connectivity is probably fine but your DNS is not fine.

      From a computer on the lan, like a desktop or laptop console, type:

      pink 8.8.8.8

      What happens?

      1 Reply Last reply Reply Quote 0
      • G
        gibbzy2k1
        last edited by

        Yes I can ping 8.8.8.8 from my laptop.

        I currently have Cisco/openDNS set as the DNS on pfsense. I have just tried ticking to allow DNS to be overridden by dhcp. Still the same issue.

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          Its your DNS, so focus there.  Also look for firewall rules that would block DNS.

          1 Reply Last reply Reply Quote 0
          • G
            gibbzy2k1
            last edited by

            That's what I am thinking. But nothing changes when I change the DNS settings. The FW wasn't touched over the weekend, but something obviously happened for it to suddenly stop working yesterday.

            I have attached a shot of the nat rules and LAN rules. if it helps. Again, none of these have changed though.

            ![firewall rules.PNG](/public/imported_attachments/1/firewall rules.PNG)
            ![firewall rules.PNG_thumb](/public/imported_attachments/1/firewall rules.PNG_thumb)
            ![nat rules.PNG](/public/imported_attachments/1/nat rules.PNG)
            ![nat rules.PNG_thumb](/public/imported_attachments/1/nat rules.PNG_thumb)

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              Add a rule, which you can delete later on the Lan to allow any to any.  See what happens.

              1 Reply Last reply Reply Quote 0
              • G
                gibbzy2k1
                last edited by

                I created a new LAN rule to allow any to any and put it just under the anti-lockout rule. No difference.

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  "I currently have Cisco/openDNS"

                  Could you try resolver and see if it works?

                  1 Reply Last reply Reply Quote 0
                  • G
                    gibbzy2k1
                    last edited by

                    Sorry, what do you mean try resolver? DNS resolver is enable on the fw if that's what you mean?

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      I'm confused now…  I though you were using an external Cisco/openDNS for DNS?

                      1 Reply Last reply Reply Quote 0
                      • G
                        gibbzy2k1
                        last edited by

                        Sorry I should have explained better. When I set up the fw I put openDNS server IPs into the DNS server under the general setup. 208.67.222.222 and 208.67.220.220, both of which I am able to ping.

                        I have also tried replacing with google DNS IPs and enabling the over ride with DHCP/PPP on WAN.

                        All with no luck.

                        1 Reply Last reply Reply Quote 0
                        • K
                          kejianshi
                          last edited by

                          Yes - But in your services TAB…

                          Do you have resolver or forwarder activated?

                          1 Reply Last reply Reply Quote 0
                          • G
                            gibbzy2k1
                            last edited by

                            sorry resolver is enabled, forwarder is not.

                            1 Reply Last reply Reply Quote 0
                            • K
                              kejianshi
                              last edited by

                              If you are trying to get your DNS served from another place, turn off resolver and turn on forwarder.

                              1 Reply Last reply Reply Quote 0
                              • G
                                gibbzy2k1
                                last edited by

                                Thanks. I have tried that to no avail. I'll have to keep looking tomorrow and try to work out what has changed over the weekend.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.