Help a noob out for simple setup
-
Please provide a simple network diagram showing how you have this connected.
Edit: Seems like you have a double NAT issue with your ISP modem.
Your WAN is 192.168.1.199 and gateway 192.168.1.1
You should put the ISP modem into bridge mode and allow pfSense to handle routing.How are you connected when trying to access the pfSense (with WAN cable plugged in and NOT plugged in)?
Are you connected to ISP modem/router? -
Thanks for your reply bartkowski!
It's actually a super simple setup for now.
Yes, I was afraid it is a double NAT issue. Just keep wondering why my Asus router did not have an issue with it...
Sadly, I cannot put the ISP modem into bridge mode as I do not have access to it, since it is the landlord's property.
-
@mkkl Can you get to pfSense using 172.16.10.1?
Haha, I didn't read far enough to see you couldn't modify the upstream equipment.
-
Interestingly, this more complicated setup works..
-
@bartkowski yes i can reach pfSense using 172.16.10.1 :)
-
and it gives me this traceroute:
-
@mkkl Hmm, does the ISP/dorm use some ACL, allowing the ASUS but not SG-3100. Try copying the ASUS' mac.
To recap, the issue is that you cannot get to the internet and NOT the fact that Zyxel responds to 192.168.1.1? -
@bartkowski You're the best!!!
Entering a mac address in the mac address field of the WAN interface fixed it!!
That's 6 hours of my life I'll never get back. But once again, thanks!
-
Also, I noticed that Asus shows a 10.x IP on WAN, but SG gets a 192.x on WAN - all while connected to the same cable coming from ISP[?] - why?
-
@mkkl Glad that helped! Perhaps you should reach out to the dorm IT with the SG-3100's MAC.
-
@bartkowski That is a very good observation and something that I've also pondered on. I have no clue why that is, but now my sg-3100 also gets 10.x WAN ip as the asus did when it worked.
As a matter of fact, it turned out that entering any MAC address would fixed the problem, not just the mac of the asus device.
-
@mkkl said in Help a noob out for simple setup:
any MAC address
Your WAN interface has - or had - it's own MAC : that was the only one being refused ?
And if it was refused, you wouldn't even get an IP (and gateway, and DNS) using DHCP from the upstream router, the Zyxel device used by the tenant, or, you did. -
Yeah I would put money on one of your neighbours having connected their router incorrectly and it's handing out 192.168.1.X IPs. Whoever is admin on that network should be looking for them with a big stick but...
Steve