Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Cannot access 2 switches on LAN from VLAN.

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 5 Posters 1.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pfrickrollP Offline
      pfrickroll @Grimson
      last edited by

      @Grimson

      What do you mean by useless? pfsense gateway is 192.168.18.1
      I am not an expert in terms of a lot networking concepts there are some details or terms I have yet to fully grasp.

      GrimsonG 1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        You have a gateway set on your firewall rules, man. That completely bypasses the routing table, including the default gateway.

        https://www.netgate.com/docs/pfsense/routing/bypassing-policy-routing.html

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        pfrickrollP 1 Reply Last reply Reply Quote 1
        • pfrickrollP Offline
          pfrickroll @Derelict
          last edited by

          @Derelict said in Cannot access 2 switches on LAN from VLAN.:

          You have a gateway set on your firewall rules, man. That completely bypasses the routing table, including the default gateway.

          https://www.netgate.com/docs/pfsense/routing/bypassing-policy-routing.html

          Ok, it makes sense to me but how it applies if I am blocking?
          Like i have those 3 rules set, should gateway also be "default?

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            What? You are passing not blocking. Block rules don't forward traffic anywhere.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • GrimsonG Offline
              Grimson Banned @pfrickroll
              last edited by

              @pfrickroll said in Cannot access 2 switches on LAN from VLAN.:

              I am not an expert in terms of a lot networking concepts there are some details or terms I have yet to fully grasp.

              Then learn them, routing is a basic topic when it comes to networking.

              Here: https://forum.netgate.com/topic/138695/how-would-you-go-about-managing-24-pfsense-boxes it seems you are tasked with managing the network of multiple sites for a company. If you want to do this you need to know the basics in and out or you are the wrong person for a job like this.

              1 Reply Last reply Reply Quote 0
              • pfrickrollP Offline
                pfrickroll
                last edited by

                So, Block rules don't care what gateway is there, all traffic is blocked no matter what?

                DerelictD 1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  Screen Shot 2019-03-26 at 1.30.02 PM.png

                  You are forcing that traffic out your WANs.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate @pfrickroll
                    last edited by

                    @pfrickroll Setting a gateway on a block rule is nonsense. The traffic is blocked so there is nothing to forward.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • pfrickrollP Offline
                      pfrickroll
                      last edited by

                      Capture.PNG

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        Great. Now you can access your switches.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.