• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Strange behavior on LAN

L2/Switching/VLANs
4
10
984
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    DraNick
    last edited by Nov 29, 2018, 12:52 PM

    Hello,

    I have the LAN NIC (192.xx.xx.xx) connected to a switch for multiple devices connections.

    If I connect a computer to the LAN NIC directly I can ping the router's LAN IP but as soon as I connect the router LAN to the switch I lose connectivity to the router (can't ping the router's LAN IP anymore).

    In short, with a direct connection to the pfSense's LAN NIC I can ping it; if I try to connect to it via a switch it doesn't work anymore.

    If I leave a ping from a PC connected to the switch, unplug the network cable from the pfSense's LAN NIC and plug it back in the PC starts to ping.

    I should mention that if I connect a different router (different manufacturer) to the same switch everything works.

    Please help.

    Thank you.

    1 Reply Last reply Reply Quote 0
    • H
      heper
      last edited by Nov 29, 2018, 1:33 PM

      an ip-conflict comes to mind ( multiple devices with the same ip-address )

      unplugging/plugging the lan cable might trigger an update/overwrite of the clients arp table

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Nov 29, 2018, 1:37 PM

        @dranick said in Strange behavior on LAN:

        I have the LAN NIC (192.xx.xx.xx)

        Why are you hiding rfc1918 space?

        Concur its prob some sort of IP/ARP conflict.. Where your other router is using a different IP than pfsense.

        Why don't you unplug everything else from the switch and just have your PC and Pfsense connected to the switch.. What are their IPs? Lets say 192.168.0.1 for pfsense and 192.168.0.2 for the PC... Can the PC then ping pfsense - what is in the arp table for the PC and Pfsense should show these 2 IPs with the correct mac address.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        H 1 Reply Last reply Nov 29, 2018, 1:38 PM Reply Quote 0
        • H
          heper @johnpoz
          last edited by Nov 29, 2018, 1:38 PM

          @johnpoz said in Strange behavior on LAN:

          Why don't you unplug everything else from the switch and just have your PC and Pfsense connected to the switch.. What are their IPs? Lets say 192.168.0.1 for pfsense and 192.168.0.2 for the PC... Can the PC then ping pfsense - what is in the arp table for the PC and Pfsense should show these 2 IPs with the correct mac address.

          the switch itself could also hold an ip .... some brands give their switches a default 192.168.1.1 .....

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Nov 29, 2018, 1:40 PM

            Yup very true - but I assumed maybe wrong that someone that could not troubleshoot such a basic issue is not using a smart switch just some dumb switch ;)

            But you are correct it could be a switch IP conflict with pfsense..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • D
              DraNick
              last edited by DraNick Nov 29, 2018, 1:58 PM Nov 29, 2018, 1:52 PM

              The network configuration is as follows (for clarification):

              main router: 192.168.1.1/24
              pfSense WAN: 192.168.1.11/24
              pfSense LAN: 192.168.10.1/24
              pfSense DHCP: 192.168.10.150 - 192.168.10.254
              PC static DHCP on pfSense: 192.168.10.4
              If I directly connect the PC to pfSense it gets the correct IP and can ping 192.168.10.1.
              If I connect pfSense to the office network (thus going through the switches and patch panel) and the PC to one of the network outlets I cannot ping 192.168.10.1 anymore unless I leave the ping running on the PC, disconnect the pfSense cable and reconnect it (the network outlet works ok as I can ping other machines on the network with a different router connected on the network).

              I should also specify my pfSense model: Super Micro XG-1537

              I have unplugged all switches except one and made sure the only network connected PC is the one I'm using for testing, to no avail.

              Thank you.

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz Nov 29, 2018, 2:16 PM Nov 29, 2018, 2:14 PM

                As already stated check your machines arp table.. Check you switches arp table.. If you have a conflict its possible the arp table on the switch has it on a different port, etc. etc..

                Change pfsense IP to something you are sure is not used on this 192.168.10 network..

                Do a simple sniff on pfsense - if pfsense does not see the ping it sure can not answer said ping.. Maybe it is and its getting lost in your switching environment

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by Nov 29, 2018, 5:52 PM

                  What kind of switch? Managed or unmanaged? New or old?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • D
                    DraNick
                    last edited by Nov 29, 2018, 7:47 PM

                    Coming back with an update, one of the network switches was a managed switch (Zyxel GS1900) which failed to update the arp table (this is what happens when you let the cable guys add managed hardware when unmanaged was requested).

                    I've force-cleared the MAC and arp tables and the network lit up like a Christmas tree (as Christmas is close anyway).

                    Thank you guys for getting involved and for your time!

                    All the best!

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Nov 29, 2018, 8:02 PM

                      @dranick said in Strange behavior on LAN:

                      unmanaged was requested

                      Why would you ever request that?? And pretty much any managed switch I have ever seen comes out of the box dumb.. With everything in vlan 1... Only thing that might be a problem is the default IP of the switch - but most of then not they will auto grab an IP off dhcp if running, etc..

                      You should never request a unmanaged switch...

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      6 out of 10
                      • First post
                        6/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.