Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Connecting 2 sites

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 4 Posters 1.4k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      deheugden
      last edited by

      Ok, am still stuck. I got 3 interfaces, LAN, Opt1, WAN. Wan is connected to my ISP through NAT, Opt1 and Lan are conencted to my virtual servers. The Opt1 doesnt work, i cant ping from my virual server in the same segment to the ipaddres i created for the Opt1 interface. Internet traffice doesnt work.

      Anyone who can help? It should look like the picture in the attachment.

      pfsenseconfig.jpg
      pfsenseconfig.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        You need to add a filter rule to OPT1 to allow access from that network. Firewall > Rules
        On LAN there is set an allow any to any rule by default. You may copy this by hitting the icon at the right, edit the copy and change the interface to OPT1.

        1 Reply Last reply Reply Quote 0
        • D Offline
          deheugden
          last edited by

          Many thanks for the reply. I never did something like that and google isnt that helpful today. is it possible for you to explain how to do this?

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            I think, I had already explained that.

            It's just as simple. Go to Firewall > Rules, select the LAN tab. It should looks like the picture below.

            The second rule is the IPv4 default rule, the last that one for IPv6. At the right of each you can find a copy button. Hit this, then you get a copy underneath, open this by hitting the Edit button, go to Interface and select your OPT1 from the dropdown. Save the settings by click at the save button at the bottom.
            Do the same with the IPv6 rule.

            pfseneLANrules.png
            pfseneLANrules.png_thumb

            1 Reply Last reply Reply Quote 0
            • D Offline
              deheugden
              last edited by

              First of all, let me apologize for the time it took to reply. We had some problems here. Becauseof that, i havent had the time to play with pfsense.

              About adding the rules, is it possible to do that through the commandline and not through the gui?

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Possible, perhaps by editing the config file, but no there isn't a CLI that can do that.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                D 1 Reply Last reply Reply Quote 0
                • D Offline
                  deheugden @Derelict
                  last edited by

                  @derelict 0_1528625202465_2018-06-10_12-06-29.jpg

                  strangest thing is, to get things working in OPT1 , i had to change the source from LAN NET into *

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    lan net would never be a source of traffic on opt1 net, should change it to opt1 net vs lan net, all interfaces will have a built in alias of their address and their network. To use for source and destinations, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    D 1 Reply Last reply Reply Quote 0
                    • D Offline
                      deheugden @johnpoz
                      last edited by deheugden

                      @johnpoz many thanks for replying. When copying the default firewallrules for opts1(from lan) i do get the lannet by default0_1528636778803_pfseneLANrules.png

                      and without changing the lannet into *, the routing doesnt work

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        well yeah its simple copy there is no magic saying oh your copy me from lan net to opt net need to change the source..

                        Correct yourself. Change it to optX net or whatever you rename that opt net to be... I always change mine to something that makes sense to me. wlan net, dmz net, dtv net, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.