Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Confused behind pfsense.

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • kiokomanK
      kiokoman LAYER 8
      last edited by

      it is open only from the lan network side to the internet
      for speednet test to check your latency you need to permit icmp to your wan
      but that is not mandatory to surf the web

      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
      Please do not use chat/PM to ask for help
      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

      R 1 Reply Last reply Reply Quote 1
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Looks like pfSense itself is able to connect, it claims to be on the latest update, but you should make sure it can see and download packages.

        You should be able to connect from a LAN side client by default. The most common reason you cannot is if the subnets conflict. They look OK here unless the WAN is actually a /23 or larger.

        Also check for a default route in Diag > Routes.

        Steve

        1 Reply Last reply Reply Quote 1
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Your graphs show your moving quite a bit of data.. You running p2p on that connection? 300-500kbps looks like.. 5ms to your local router seems pretty high..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          R 1 Reply Last reply Reply Quote 0
          • R
            rEGiLAyt @kiokoman
            last edited by

            @kiokoman said in Confused behind pfsense.:

            permit icmp to your wan

            Thank you @kiokoman, I added a rule to WAN and it allowed speed test to run. Is there a reason that I should not have this rule setup?

            https://www.speedtest.net/result/8601630880.png

            1 Reply Last reply Reply Quote 0
            • R
              rEGiLAyt @johnpoz
              last edited by

              @johnpoz I am not running any p2p. The pc I have connected to this firewall currently for testing is my main desktop, that has all of my IP security cameras streaming to it for DVR. I am looking to test this for a bit first, and then once I am happy with it it will run as an appliance between my main inbound feed, and the rest of the house. Currently I have it connected to a switch with a few odd and end devices.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                You would not need a rule on your WAN to allow speedtest to run? You mean it was pinging your IP? And that was stopping the test from running.. I find that hard to believe to be honest.. For starters your behind a double nat.. So you would of never pinging your pfsense actual IP anyway.

                I disabled my wan ping, and speedtest.net still works.

                You mean you created a rule on your lan side to allow ping outbound?

                Are those graphs in kb or kB?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                R 1 Reply Last reply Reply Quote 0
                • R
                  rEGiLAyt @johnpoz
                  last edited by

                  @johnpoz I followed what the other user had mentioned and it worked correctly. When I said I could ping speedtest.net I went into diagnostics, ping, and used the host name, and could ping speedtest.net. However when I would open it I could click Go, and it would never initialize, it would go into the latency error. I have added the rule I created below, and now the speedtest.net works fine. Thank you for your help.

                  0d8f96b4-3527-41fc-82e6-72f5b48c97ab-image.png

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    That did not fix your problem, the speedtest site does not ping your IP.. And your behind a double nat anyway.. So it couldn't actually ping pfsense anyway..

                    Notice that rules has ZERO hits.. notice the 0/0

                    Here is ping on wan that shows a hit on the rule.
                    rulehits.png

                    Not sure why it started working for you, but that rule has ZERO to do with it.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    R 1 Reply Last reply Reply Quote 1
                    • R
                      rEGiLAyt @johnpoz
                      last edited by

                      @johnpoz Sir, you are correct. I disabled the rule and tried speedtest, and it worked. I then deleted the rule, and it still works. I am not sure why it took over 24 hours to start working, but it is working correctly now. Thank you again for your assistance. I am a noob when it comes to pfSence.

                      Thanks again.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        So internet in general was working, you had no issues resolving anything.. Just speed test was failing? And you had tried just changing the servers you were doing the test too?

                        changeserver.png

                        That latency error you were getting seems to just point to one of there servers being down
                        https://support.speedtest.net/hc/en-us/articles/203845540-What-does-Latency-Test-Error-mean-
                        "Latency Test Error" typically occurs when the server has gone temporarily down. We have a server watchdog that will periodically contact servers to verify they're working properly, but there may be a slight delay before we automatically recognize the server is down. Please let us know by filing a support ticket specifically identifying which server caused the error, and try testing to a different server.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.