Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1 wan 2 lan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    26 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @pellle87
      last edited by NogBadTheBad

      @pellle87

      Repost your rules.

      A bit larger this time ;)

      Also are you currently using an AP in LAN2 or connecting direct via copper?

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      P 1 Reply Last reply Reply Quote 0
      • P
        pellle87 @NogBadTheBad
        last edited by

        @nogbadthebad i posted on imgur: https://imgur.com/a/48pYs5M

        Right now the AP is not connected, i have just connected a wire between lan2 port and a computer

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @pellle87
          last edited by NogBadTheBad

          @pellle87

          Delete your LAN2 rules and copy the rules from the LAN interface and change the interface to LAN2.

          Does it then work ?

          Are you using a PC to test, if so what does an ipconfig /all say ?

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          P 1 Reply Last reply Reply Quote 0
          • P
            pellle87 @NogBadTheBad
            last edited by pellle87

            @nogbadthebad you my sir are my hero! really big thanks for clarifying and helping me :) i gotta read up abit more about networking... again. Thanks!

            edit: copying the rules did the trick

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @pellle87
              last edited by

              @pellle87

              Now just work on blocking access from LAN2 to LAN now you know it's working :)

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              P 2 Replies Last reply Reply Quote 0
              • P
                pellle87 @NogBadTheBad
                last edited by

                @nogbadthebad yea... that will be interesting figuring out atleast internet is up now

                1 Reply Last reply Reply Quote 0
                • P
                  pellle87 @NogBadTheBad
                  last edited by

                  @nogbadthebad shouldnt theese rules do the trick?
                  alt text or do i missunderstand the invert option?

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • F
                    free4 Rebel Alliance @NogBadTheBad
                    last edited by free4

                    @pellle87 said in 1 wan 2 lan:

                    I have setup a second lan on my install that im planning of plugging my AP into to separate the wlan from the rest of the lan.

                    LAN: 10.10.10.1 - 10.10.10.200 Gateway: 10.10.10.1
                    LAN2: 11.11.1 - 11.11.11.200 Gateway: 111.11.11.1
                    Any help is appriciated

                    • 11.11.11.x does belong to the United States Department of Defense. (the DOD owns 11.0.0.0/8)
                    • 111.11.x.x is part of the Chinese firewall (this IP range seems to be used by China Mobile for PGW/Mobile phone gateway for internet, for the area surrounding Dezhou)

                    0_1548714433329_2s9j4x.jpg

                    Well, trolling aside, these rules should normally do the trick.
                    If it doesn't, you could create a "block" rule specifically matching your LAN net above your two "allow" rules ?

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      pellle87 @free4
                      last edited by

                      @free4 hahah :D the invert did not work atlest...
                      Tried also a rule like this above the 2 allow rules:

                      alt text

                      it dont seem to work..

                      1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @pellle87
                        last edited by NogBadTheBad

                        @pellle87

                        People don’t tend to like the use of the invert.

                        Has to be said that I use it, on my guest network.

                        Does DHCP. DNS & NTP work with your rules, I bet it doesn’t.

                        Also you could delete the IPv6 rule and change the IPv4 rule to IPv4/IPv6.

                        If you don’t use IPv6 just delete the rule.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        P 1 Reply Last reply Reply Quote 0
                        • P
                          pellle87 @NogBadTheBad
                          last edited by pellle87

                          @nogbadthebad oh dear, now im confused :) the digging continues....

                          when i access a share from the blocked network to the lan1 network the "states" is increasing so i guess im somewhat right but not in some way

                          alt text

                          NogBadTheBadN 1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN
                            NogBadTheBad @pellle87
                            last edited by

                            @pellle87

                            Change your rule to log, then look in the firewall logs to see what’s being blocked or just copy the rules in my screenshot.

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Pass traffic on LAN2 for things they need (like DNS)
                              Reject traffic to things you want to keep them from accessing (LAN net, RFC1918, This firewall)
                              Pass any (the internet)

                              That is the only correct way to do it.

                              Passing to ! LAN Net and expecting that to function as a block rule to LAN net is no way to roll.

                              If you care about security, block the traffic you want to block and pass the rest.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.