Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Great pfsense start

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    22 Posts 5 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @kappclark
      last edited by

      @kappclark

      If you are using 192.168.1.0/24 on your LAN interface configure an unused pfSense interface as 192.168.2.0/24.

      Set up the DHCP scope on the new interface.

      Create a new alias to include all your IP subnets and pop firewall rules on the guest interface like this:-

      Screenshot 2020-02-11 at 15.42.40.png

      Configure the old wifi router to have an IP address in the 192.168.2.0/24 range and connect the old wifi routers LAN port to pfSense.

      No need for dhcp relay.

      1 Reply Last reply Reply Quote 0
      • kappclarkK
        kappclark
        last edited by

        Thanks so much -- I have already started on this and will let you know how it goes ..

        your reply is very helpful

        1 Reply Last reply Reply Quote 0
        • kappclarkK
          kappclark
          last edited by

          SO - the router was reset as an AP - now has static address 192.168.2.254 - changed the password and SSID

          I can connect and authenticate to this wireless with my phone....

          But - I cannot obtain an IP address..seems DHCP is not working correctly..I have checked that it is enabled ..

          I have created a scope on the GUESTOPT1 interface going from 192.168.2.100 - 192.168.2.150.

          The address of the ethernet interface on the pfsense is 192.168.2.211

          I am sure I am missing something so obvious ...

          c36948eb-3d2a-4e6b-b472-30270c382042-image.png

          Confused, I remain ..

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @kappclark
            last edited by

            @kappclark

            A few things to check:-

            Can you ping the ap from pfsense?

            If you connect a PC to the guest interface does it get an ip address?

            Have you connected the guest pfsense interface to the LAN interface on the AP?

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              How are you connecting the router? Is it really just as an Access Point? If it's just acting as a layer 2 device DHCP should pass it.

              Steve

              1 Reply Last reply Reply Quote 0
              • kappclarkK
                kappclark
                last edited by

                Yes - can ping the AP from pfsense:
                710951be-3a5c-4bca-b95b-baa92a017d0d-image.png

                Disconnected AP. Connected laptop to OPT port directy -- received IP address from given scope (192.168.2 104) ...

                but amazingly - it now works ... I removed the firewall rules on the interface and added only a default rule.

                e134e88c-76db-4678-91cc-a34a0353b3c0-image.png

                I have the laptop and the firestick both working off the AP ... and Alexa is happy as well....

                I will connect wife's phone, laptop and tablet ...

                Thank you very much for your help in this ...

                1 Reply Last reply Reply Quote 0
                • kappclarkK
                  kappclark
                  last edited by


                  Just a followup -

                  FWIW - Here is a very good guide I found on securing the private network -- maybe be of some help for the next person ..

                  once the crew here steered me in the right direction, I knew what to search for ... what a valuable resource ..

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad @kappclark
                    last edited by NogBadTheBad

                    @kappclark said in Great pfsense start:


                    Just a followup -

                    FWIW - Here is a very good guide I found on securing the private network -- maybe be of some help for the next person ..

                    once the crew here steered me in the right direction, I knew what to search for ... what a valuable resource ..

                    Slight issue with the guide he creates an IPv4/IPv6 rule with an IPv4 only alias and also allows http, ssh, etc ... access to the guest lan interface.

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @NogBadTheBad
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • kappclarkK
                        kappclark
                        last edited by

                        Never would have picked that up ! Thx for heads up ... this is gong to be lots of fun ..

                        1 Reply Last reply Reply Quote 0
                        • J
                          joshepmurray Banned
                          last edited by joshepmurray

                          This post is deleted!
                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.