Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Cannot access 2 switches on LAN from VLAN.

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 5 Posters 1.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pfrickrollP Offline
      pfrickroll
      last edited by pfrickroll

      I want to be able to log into switches on LAN:
      192.168.18.2 and 192.168.18.3
      I can access PFsense just fine but not the switches.
      What prevents it?
      Capture.PNG

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        forcing the traffic out your dualwan is kind of hard to get to another network that is directly attached.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • dotdashD Offline
          dotdash
          last edited by

          As johnpoz noted, you should leave the gateway at default unless the traffic is Internet bound.

          1 Reply Last reply Reply Quote 0
          • pfrickrollP Offline
            pfrickroll
            last edited by

            I have 2 ISPs for failover.
            I usually use teamviewer to remote on of the computers on VLAN31 and do my work because LAN computers are occupied most of the time.

            GrimsonG 1 Reply Last reply Reply Quote 0
            • GrimsonG Offline
              Grimson Banned @pfrickroll
              last edited by

              @pfrickroll said in Cannot access 2 switches on LAN from VLAN.:

              I have 2 ISPs for failover.
              I usually use teamviewer to remote on of the computers on VLAN31 and do my work because LAN computers are occupied most of the time.

              None of this has anything to do with accessing one LAN from the other. Again, don't force internal traffic out of a WAN gateway.

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Remove the gateway from the two rules that pass traffic to 192.168.18.2 and 192.168.18.3. You don't want that traffic to go out the WANs do you?

                Probably the one sending traffic to the firewall too.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                pfrickrollP 1 Reply Last reply Reply Quote 1
                • pfrickrollP Offline
                  pfrickroll @Derelict
                  last edited by pfrickroll

                  @Derelict said in Cannot access 2 switches on LAN from VLAN.:

                  Remove the gateway from the two rules that pass traffic to 192.168.18.2 and 192.168.18.3. You don't want that traffic to go out the WANs do you?

                  Probably the one sending traffic to the firewall too.

                  The "default" gateway is LAN gateway 192.168.18.1 (pfSsense?)
                  Capture.PNG

                  GrimsonG 1 Reply Last reply Reply Quote 0
                  • GrimsonG Offline
                    Grimson Banned @pfrickroll
                    last edited by

                    @pfrickroll said in Cannot access 2 switches on LAN from VLAN.:

                    The "default" gateway is LAN gateway 192.168.18.1 (pfSsense?)
                    Capture.PNG

                    I hope you didn't add a useless gateway to your LAN. As for what "default" means in the rule settings, it's written right there.

                    Leave as 'default' to use the system routing table.

                    You just need to actually read it.

                    pfrickrollP 1 Reply Last reply Reply Quote 1
                    • pfrickrollP Offline
                      pfrickroll @Grimson
                      last edited by

                      @Grimson

                      What do you mean by useless? pfsense gateway is 192.168.18.1
                      I am not an expert in terms of a lot networking concepts there are some details or terms I have yet to fully grasp.

                      GrimsonG 1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        You have a gateway set on your firewall rules, man. That completely bypasses the routing table, including the default gateway.

                        https://www.netgate.com/docs/pfsense/routing/bypassing-policy-routing.html

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        pfrickrollP 1 Reply Last reply Reply Quote 1
                        • pfrickrollP Offline
                          pfrickroll @Derelict
                          last edited by

                          @Derelict said in Cannot access 2 switches on LAN from VLAN.:

                          You have a gateway set on your firewall rules, man. That completely bypasses the routing table, including the default gateway.

                          https://www.netgate.com/docs/pfsense/routing/bypassing-policy-routing.html

                          Ok, it makes sense to me but how it applies if I am blocking?
                          Like i have those 3 rules set, should gateway also be "default?

                          1 Reply Last reply Reply Quote 0
                          • DerelictD Offline
                            Derelict LAYER 8 Netgate
                            last edited by

                            What? You are passing not blocking. Block rules don't forward traffic anywhere.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • GrimsonG Offline
                              Grimson Banned @pfrickroll
                              last edited by

                              @pfrickroll said in Cannot access 2 switches on LAN from VLAN.:

                              I am not an expert in terms of a lot networking concepts there are some details or terms I have yet to fully grasp.

                              Then learn them, routing is a basic topic when it comes to networking.

                              Here: https://forum.netgate.com/topic/138695/how-would-you-go-about-managing-24-pfsense-boxes it seems you are tasked with managing the network of multiple sites for a company. If you want to do this you need to know the basics in and out or you are the wrong person for a job like this.

                              1 Reply Last reply Reply Quote 0
                              • pfrickrollP Offline
                                pfrickroll
                                last edited by

                                So, Block rules don't care what gateway is there, all traffic is blocked no matter what?

                                DerelictD 1 Reply Last reply Reply Quote 0
                                • DerelictD Offline
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  Screen Shot 2019-03-26 at 1.30.02 PM.png

                                  You are forcing that traffic out your WANs.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD Offline
                                    Derelict LAYER 8 Netgate @pfrickroll
                                    last edited by

                                    @pfrickroll Setting a gateway on a block rule is nonsense. The traffic is blocked so there is nothing to forward.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • pfrickrollP Offline
                                      pfrickroll
                                      last edited by

                                      Capture.PNG

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD Offline
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        Great. Now you can access your switches.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 1
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.