Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't ping from LAN to pfSense / WAN

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      roguewave
      last edited by

      Wasn't sure where to put this topic, but I'm fairly certain it's a routing issue - so I'm putting it here.

      Network:
      -pfSense 2.2.2 on Netgate m0n0wall
        Since this build isn't yet complete, the WAN is connected to a LAN port on the production network (192.168.0.0/24). Yes I've unchecked the box to ban private networks.
      -Ubiquiti Edgerouter
      -Cisco SG300-20 (L3)

      -I can ping downstream from firewall to a host, but tracert from host to FW stops at the router's switch-connected inbound interface.
      -Static routes set at switch, router, and FW
      -Default routes set from switch to router and router to FW

      Problems:
      -For some reason, I can access pfSense web configurator from inside a switch VLAN, but I can't ping the FW interface (??)
      -The router can ping out to the internet. For some reason, the point to point between the router and firewall is (or isnt??) getting advertised to the switch VLANs. Not sure why I can access the pfSense portal but not ping it, and do I have to add a NAT / FW rule to advertise the WAN down to the VLANs?

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Not sure why I can access the pfSense portal but not ping it

        Firewall rule on pfSense interface allowing only TCP and not any?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.