• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

can't access to internet from LAN side

Scheduled Pinned Locked Moved General pfSense Questions
10 Posts 3 Posters 721 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    Kerzhain
    last edited by Nov 30, 2018, 10:39 AM

    Hello veryone,
    I'm a noob in networking and in pfsense and I try to create a small infrastructure in virtualbox :
    infra

    Currently I can't access to the internet from my vm windows 7 and I don't know what to do ?

    I opened all ports on the firewall to test :
    firewall

    this is my LAN interface :
    LAN

    I also tried to add NAT unbound rules :
    NAT
    NAT

    I can access to my WAN branch from my windows7 VM :
    wan branch

    and I can ping google from pfsense :
    ping google

    someone knows what I'm doing wrong ? it will help me a lot

    Thanks

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by Nov 30, 2018, 11:08 AM

      Clear the gateway in the LAN interface settings.

      1 Reply Last reply Reply Quote 0
      • K
        Kerzhain
        last edited by Nov 30, 2018, 11:13 AM

        Thanks for your answer , i just did it and I still can't have access to the internet form my VM

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by Nov 30, 2018, 11:27 AM

          Check if you can ping Google from the W7 machine by using the IP address.
          You don't allow UDP on LAN which is needed for DNS.

          1 Reply Last reply Reply Quote 0
          • K
            Kerzhain
            last edited by Kerzhain Nov 30, 2018, 12:05 PM Nov 30, 2018, 12:04 PM

            I tried to ping 8.8.8.8 and it doesnt work from my vm,
            it's working from pfsense command line interface , DNS also ( I can ping google.com from pfsense command line interface)

            1 Reply Last reply Reply Quote 0
            • V
              viragomann
              last edited by Nov 30, 2018, 12:16 PM

              Check the network configuration on the W7 vm.

              What gives "tracert 8.8.8.8" on that machine?

              1 Reply Last reply Reply Quote 0
              • K
                Kerzhain
                last edited by Kerzhain Nov 30, 2018, 2:59 PM Nov 30, 2018, 1:57 PM

                I launched a tracert , it stopped at my LAN branch of my router ( first step )
                alt text

                1 Reply Last reply Reply Quote 0
                • K
                  Kerzhain
                  last edited by Dec 1, 2018, 9:20 AM

                  I have now access to internet from my VM windows7,
                  the issue was the firewall rules "Block Logon Network" blocking local IP to pass WAN side ,and so access to my physical router ( DOUBLE NAT )

                  Now I can even ping my phisical computer from my VM , but I still can't access to my VM from my physical computer event if all is open in my firewall.

                  Any idea?

                  1 Reply Last reply Reply Quote 0
                  • V
                    viragomann
                    last edited by Dec 1, 2018, 11:26 AM

                    If WAN is facing to the internet, WAN rules should not affect access from the VM behind pfSense.

                    Your computers in the network in front of pfSense need a static route for the network behind pointing to pfSense.

                    1 Reply Last reply Reply Quote 0
                    • S
                      stephenw10 Netgate Administrator
                      last edited by Dec 1, 2018, 1:24 PM

                      If you have removed the gateway from the LAN you should switch outbound NAT rules back to automatic.
                      The rule you have there currently has source 'any' which is almost always wrong. It will NAT even traffic from the firewall itself which can cause all sorts of odd issues.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      9 out of 10
                      • First post
                        9/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received