Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access device connected to 2nd router behind pfsense

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 3 Posters 1.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Drunk3nSlang
      last edited by

      I can access 192.168.0.0 from within that network and I can access 10.0.0.0 from 192.168.0.0 but cannot access 192.168.0.0 from 10.0.0.0 or externally.

      I tried setting up rules between interfaces and that didn't work either

      I have 2 NICS 1-WAN / 1-LAN (each with their own interface) and an OPT1 interface for ExpressVPN

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @Drunk3nSlang
        last edited by

        @Drunk3nSlang said in Access device connected to 2nd router behind pfsense:

        My problem is I can't SSH to a device connected to the router from 10.0.0.0 or my DDNS.

        You will need to add a static route on the device in 10.0.0.0 for the network behind the router pointing to 10.0.0.4.

        As well you need to add a static route to pfSense to get access from outside.

        D 1 Reply Last reply Reply Quote 0
        • D Offline
          Drunk3nSlang @viragomann
          last edited by

          @viragomann could you please elaborate. I've tried every combination I could think of and still can't get it to work.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            I would expect his dd-wrt is doing NAT... So no he wouldn't need to route.. Only if its just routing and not natting would he need to setup any routing or a gateway.

            If that is the case then he is going to run into asymmetrical routing more than likely because his transit this 10.0.0 network has hosts on it.. If you going to use a downstream router then you need a actual transit network.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            D 1 Reply Last reply Reply Quote 0
            • D Offline
              Drunk3nSlang @johnpoz
              last edited by

              @johnpoz yes I have double Nat. I'm running a skyminer behind the second router and want it to be separate from my home network.

              1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann
                last edited by

                And your pfSense has only two network interfaces available and you have no VLAN capable switch?

                D 1 Reply Last reply Reply Quote 0
                • D Offline
                  Drunk3nSlang
                  last edited by

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    Drunk3nSlang @viragomann
                    last edited by

                    @viragomann said in Access device connected to 2nd router behind pfsense:

                    And your pfSense has only two network interfaces available and you have no VLAN capable switch?

                    Yes I wish I would have bought a double nic card. I think I can do VLAN on the ddwrt

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Well if your doublenatting to get to stuff behind the dd-wrt you would need to setup port forwarding on the dd-wrt and hit the wan IP of dd-wrt to get forwarded.. There is zero to do on pfsense for such a setup to work.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      D 2 Replies Last reply Reply Quote 0
                      • D Offline
                        Drunk3nSlang @johnpoz
                        last edited by Drunk3nSlang

                        @johnpoz I tried that. My problem is I have pfsense tunneling the static IP of the ddwrt through expressvpn. Port forwarding works as long as I'm not tunneling. Maybe the VPN is enough to isolate skyminer traffic from my home network and I can just use the ddwrt as a switch?

                        The skyminer acts as it's own VPN that ppl can tunnel through so I need to tunnel its traffic so it's not coming from my ip

                        1 Reply Last reply Reply Quote 0
                        • D Offline
                          Drunk3nSlang @johnpoz
                          last edited by Drunk3nSlang

                          @johnpoz FML thanks for your help. I didn't click the enable check box on the port forward on the wrt.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.