Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New to pfsense, cant access web from Lan.

    Scheduled Pinned Locked Moved General pfSense Questions
    19 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      heper
      last edited by

      also (unrelated) your 192.200.0.1/30 isnt a valid rfc1918 address for your transit network

      S 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        If your creating a downstream network.. What are you lan rules, since 192.168.1 is not going to be included in "lan net"

        Also you created the gateway that says to get to 192.168.1/24 talk to 200.0.2 ? Which as mentioned already is not rfc1918.

        Also you didn't mess with outbound nat right? when you create your gateway and route to this 192.168.1 network it will auto adjust your outbound nat for the downstream network. Unless you set it to manual, etc.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        S 1 Reply Last reply Reply Quote 0
        • S
          SimunF @jahonix
          last edited by

          @jahonix 0_1533210039214_Udklip7.PNG
          I have now unchecked this.

          1 Reply Last reply Reply Quote 0
          • S
            SimunF @jahonix
            last edited by

            @jahonix 0_1533210105653_Udklip1.PNG
            Tracert stops at my router.

            1 Reply Last reply Reply Quote 0
            • S
              SimunF @heper
              last edited by

              @heper
              Hello, I have changed my pfsense lan IP to 172.16.0.1/30 and my router wan to 172.16.0.2/30.
              Is this correct?

              1 Reply Last reply Reply Quote 0
              • S
                SimunF @johnpoz
                last edited by

                @johnpoz
                Hello, I have changed my pfsense lan IP to 172.16.0.1/30 and my router wan to 172.16.0.2/30.
                Is this correct?
                0_1533212428482_Udklip8.PNG
                0_1533212440302_Udklip6.PNG
                0_1533212447788_Udklip7.PNG

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  What do you have those rules on your wan? Did you turn off nat on pfsense?
                  Your rule to allow ping to wan net is pointless with that any any rule below it
                  And when ever would source be lan address into lan net?

                  Where are you routes showing how to get to 192.168.1/24 and your gateway setup to it?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  S 2 Replies Last reply Reply Quote 0
                  • S
                    SimunF @johnpoz
                    last edited by

                    @johnpoz
                    Hello John, I appreciate your help, I would like you to know that.
                    I have deleted wan rules created by me.
                    I have now turned off nat on PfSense.
                    I think I now understand the ping rule and the any rule :-)
                    I dont get line 3, lan into lan?
                    I have poked around and cant find the routes/gateway you mention.

                    1 Reply Last reply Reply Quote 0
                    • S
                      SimunF @johnpoz
                      last edited by

                      @johnpoz
                      Is this what you want from me?
                      0_1533214391739_Udklip10.PNG
                      0_1533214398857_Udklip9.PNG

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        @simunf said in New to pfsense, cant access web from Lan.:

                        I have now turned off nat on PfSense.

                        NO... I didn't tell you to do that - I asked if you had because that would be the only reason for such rules on your wan.

                        Rules are evaluated as traffic enters and interface from the network, how would lan address EVER be a source of traffic entering the lan interface?

                        Did you create your gateway to your downstream router in
                        System / Routing / Gateways

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          SimunF @johnpoz
                          last edited by

                          @johnpoz
                          I have found these. I have reenabled auto nat (as it was before)
                          2_1533216107622_Udklip12.PNG 1_1533216107622_Udklip11.PNG 0_1533216107620_Udklip10.PNG
                          Thanks in advance. My workday is over for now.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            And you have no gateway setup, so how is pfsense going to know to send traffic for 192.168.1/24 to your cisco? It will just send traffic with that dest out its wan..

                            WTF is the route for 192.168.1.0/32 doing in there?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            S 1 Reply Last reply Reply Quote 0
                            • S
                              SimunF @johnpoz
                              last edited by

                              @johnpoz
                              Good morning from Denmark :-)
                              I have removed the route you mentioned. and created this gateway.0_1533277253861_Udklip13.PNG
                              I'm sorry for the inconvenience.

                              1 Reply Last reply Reply Quote 0
                              • S
                                SimunF
                                last edited by

                                I have now removed the Cisco Router, changed the pfsense lan IP to 192.168.1.254/24.
                                And now I have net on all machines...
                                It is not the setup I wanted, but for now it is the setup that works.

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz

                                  So the cisco is 172.16.0.1? Or is that pfsense itself?

                                  Where is the route?

                                  Seems basic routing is beyond your current skill set - so why you would want to complicate it with a downstream router is beyond me.

                                  Cisco 2800 switch VLAN2 192.168.1.253, every used port is in no shutdown mode

                                  Also you sway every port? The port connected to pfsense, ie your transit network wold not be the same layer 2 network as your 192.168.1 network..

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.