Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to Browse Internet

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 4 Posters 1.5k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      @johnpoz said in Unable to Browse Internet:

      under 1 ms to your isp device.. That is pretty freaking good..

      Suspiciously so. It's monitoring something very close which will not show packet loss upstream of that.
      You might want to change the monitoring target to some other public IP that responds to ping. 8.8.8.8 is a common choice.

      Steve

      W 1 Reply Last reply Reply Quote 0
      • W Offline
        wiinc1 @stephenw10
        last edited by

        @stephenw10 said in Unable to Browse Internet:

        You might want to change the monitoring target to some other public IP that responds to ping. 8.8.8.8 is a common choice.

        Where you I change the monitoring target?

        Now one of the gateways shows "pending" - not sure if this is indicative of an issue or not.

        75e5b33a-3f3c-452c-a06c-eddd16e50e93-image.png

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          You can set a custom target by editing the gateway in System > Routing.

          The v6 gateway was monitoring the link local address so that was not showing anything upstream. It should still be doing so though unless you disabled IPv6 somewhere.

          Steve

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            See all those hops with 10.x.x.x those are odd as shit... That is rfc1918 space, and doesn't route on the internet - the only way you would see such address that many hops in if you were on a really bad carrier grade nat, etc.

            And why is your first hop 192.168.43??? Thought pfsense was 192.168.100.1 ?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • W Offline
              wiinc1
              last edited by

              @stephenw10
              IPv6 Gateway Setup - To me it looks like it is the default. Let me know if you see something that doesn't look right.954b6969-b56b-4153-9bae-87edc043c08b-image.png

              The change after inputing 8.8.8.8 for the gateways:

              e91a7ef7-cc29-4a12-a994-48cde07a0395-image.png

              @johnpoz - The only thing I can think of is that the ATT Fiber modem (PACE) is the older version. I have never came close to the 1GB speeds, not even half that since I have been on the service.

              I have no idea why the first hop is to any other IP besides 192.168.100.1. since this is the setup at this moment. I'd trust your opinion over mine though.

              e6d51364-55d8-47e0-928f-31934851633c-image.png

              1 Reply Last reply Reply Quote 0
              • W Offline
                wiinc1 @BogusException
                last edited by

                @BogusException

                I appreciate the help and suggestions.

                I'll be honest, the pfSense logs don't to alot for me as I'm not sure what I am looking for.

                I'm not able to make heads or tails of the following logs:

                2d711a95-9e5b-40b5-a823-e1f25fcdffaf-image.png

                38a17cff-207c-4413-86ed-a34eff932bb8-image.png

                58fdcdb1-46d0-412a-afed-377c3810d2f8-image.png

                I probably will call ATT, but trying to make sure I don't yell at a customer service / technical support rep as they didn't create the problem :)

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Dude if your first hop is not 192.168.100.1, then your NOT talking to pfsense. You sure your not connected to someone else.

                  You show us your pfsense IP of 192.168.100.1, then a trace showing your hitting 192.168.43. - and then a bunch of 10.x address... Not sure what that has to do with pfsense...

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Yeah, you have something weird there. You might not necessarily see 192.168.100.1 in the traceroute but if you do it will be the first hop.

                    Unless maybe you are behind another router? Maybe acting as an access point but still NATing?

                    That still wouldn't explain the string if private IPs in the output.
                    Seems more likely you are connecting over a VPN or maybe a 3G/4G device somehow.

                    How does that compare with the sane traceroute run from the pfSense CLI?

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • W Offline
                      wiinc1
                      last edited by

                      @johnpoz & @stephenw10 - Based on your comments and feedback, I went back and did the following:

                      • Walked through the steps / video to put the PACE 5268AC modem into bridge mode.

                      • After that, I ran the tracert -d netflix.com again.

                      Below are the results (the first hop was to what you expect - 192.169.100.1)

                      59d2b262-2fe8-45e7-81dd-7463115982ea-image.png

                      Even with something that you would expect, I'm not able to pull up sites like youtube.com, linuxmint.com, or getfedora.org via the browser on a laptop connected to the switch via Ethernet.

                      Does this traceroute look better?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        You could of turned the modem off, that would have zero to do with clients talking to pfsense... What is on your wan has ZERO to do with what pfsense lan IP, and its dhcp clients.

                        How exactly do you have all this stuff connected together?

                        That is not a modem, that is a gateway, and runs wireless.. Are you clients connecting to it for wireless?

                        So see 2nd hop, your past pfsense - stuff not working once that has happened has zero to do with pfsense.. Call your isp.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Netflix is not a great target for traceroute though. It times out for me too.

                          At least you're seeing what looks like the correct route. It seems highly suspicious that you were seeing a different gateway device previously. I'd suggest you have a rogue DHCP server or some unknown connection somewhere.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Doesn't matter about the rest of the traceroute.. What matters is showing past pfsense.. Its rare these days to be able to get a clean trace all the way to the dest without some timeouts, freaking idiots not answering them along the way.

                            If he having issues getting somewhere and pfsense passes on the traffic - and stuff isn't working he needs to call his isp..

                            A sniff on pfsense might give you more insight.. With his client saying connection was "closed" maybe RST are being sent back from the ISP.. No idea - but if he routes past pfsense to his isp, and stuff not working its not pfsense issue... Which makes sense since he says he didn't change anything with pfsense..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • W Offline
                              wiinc1
                              last edited by

                              I appreciate everyone's help in troubleshooting the experience I was having. ATT provided a new modem and has resolved the connectivity issue.

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.