Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't access networks from LAN to OPT1

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by

      @beppo said in Can't access networks from LAN to OPT1:

      accesspoint

      Is it a router with Wi-Fi or an actual access-point ?

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 1
      • B
        beppo
        last edited by

        It is an accesspoint. The webinterface is accessible from WLAN network, wired or via radio.

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @beppo
          last edited by

          @beppo

          I only asked as some people use a home router with Wi-Fi and connect it via the WAN port.

          It should route as the networks are directly attached, are there any other devices or could you pop a laptop where the access-point is connected and try that.

          It sort of smacks of the access-point not having a default route.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 1
          • B
            beppo
            last edited by beppo

            If I connect a laptop to the switch, where the accespoint is connected, I can connect to the webinterface. But the problem cannot be the accesspoint.

            As I did write, I have a small server running. If I connect the server to the switch with the access point, the server is not accessible anymore from LAN network.

            I totally agree with you, pfsense should route as the networks are directly connected.

            All devices are configured via the dhcp server of the LAN and WLAN interfaces.

            1_1536670410690_dhcp_server_wlan.png 0_1536670410690_dhcp_server_lan.png

            I don't know why icmp is working and the rest is not.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by

              Diagnostics -> Test Port

              Tried the above from the router using the WLAN as a source ?

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • B
                beppo
                last edited by beppo

                Is working from WLAN and also from LAN.
                1_1536672109073_testport_80_wlan.png 0_1536672109073_testport_80_lan.png

                Did you have a look at the firewall log? It seams like the tcp connection cannot be establish for whatever reasons.

                0_1536672152846_firewall_log_http_lan_to_wlan_accesspoint.png

                1 Reply Last reply Reply Quote 0
                • B
                  beppo
                  last edited by

                  Update:

                  Changed both switches, problem still persists.

                  Scenario 1: Server is connected to LAN network
                  Ping and TCP/UDP connection (e. g. http, https or ssh) from WAN network to server on LAN network is possible

                  Scenario 2: Server is connected to OPT1 network
                  Ping from LAN network to OPT1 is working, TCP/UDP connection (e. g. http, https or ssh) is not working

                  I really don't know why. The firewall rules are equivalent on both interfaces and allow each interface to any with protocol any.

                  I would really appreciate if anyone could give me some hints.

                  Thanks and regards
                  Alex

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    @beppo said in Can't access networks from LAN to OPT1:

                    13:44:59.746014 IP 10.0.1.200.37296 > 10.0.2.2.80: tcp 0
                    13:44:59.746320 IP 10.0.2.2.80 > 10.0.1.200.37296: tcp 0

                    That sure looks like your AP aswered.. But maybe it answered back with RST.. Ie F off sort of thing because a remote network is not allowed to access its web gui..

                    Open that sniff up on wireshark... What does it tell you?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • B
                      beppo
                      last edited by

                      @johnpoz I think you are correct. I tried ssh to a server connected to OPT1 from LAN network once again and it worked. I seemed to have made a mistake on the ssh try in the first run.

                      Seams to be some ACL of the access point, although I did not find something in the webinterface.

                      0_1536787271620_10.0.2.2.png

                      So it's not a pfsense issue. Thx for your help @NogBadTheBad and @johnpoz .

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Many an accesspoint/wifirouter will not allow remote admin. When your not from the local network you would be "remote" so you would have to enable remote admin.

                        What is the make and model of this AP?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.