Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to get 2 separate networks to talk to each other?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    74 Posts 3 Posters 11.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      ilovechickennuggets @kiokoman
      last edited by

      @kiokoman
      setup6.PNG

      setup7.PNG

      For clarification, Pfsense has WAN, LAN and OPT 1 (which I renamed SERVER). The NAS server is 192.168.70.2

      I created rule to permit source SERVER net to destination 192.168.70.1- the port 53 error is now resolved. However, I still cannot ping the NAS. What else am I missing?

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by kiokoman

        from where are you pinging ? from LAN ?

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        I 1 Reply Last reply Reply Quote 0
        • I
          ilovechickennuggets @kiokoman
          last edited by

          @kiokoman Pinging from pfsense GUI (192.168.69.1)

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by kiokoman

            i see no reason here, a ping should work from LAN to SERVER, maybe the NAS has its own firewall ?
            if there isn't anything new on the firewall log
            ip protocol is set to IPv4 right?

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            I 1 Reply Last reply Reply Quote 0
            • I
              ilovechickennuggets @kiokoman
              last edited by ilovechickennuggets

              @kiokoman

              Previous error cleared up in the log. The NAS is a fresh new install of Freenas and no settings have been modified yet. The NAS is directly plugged into pfsense router OPT 1. The NAS automatically grabs IPv4 with DHCP after plugging in.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Does your nas have a gateway set? That points back to pfsense 70.1 address?

                Can you ping the NAS from pfsense server interface, ie 70.1 ?

                Either the nas has firewall, or has no gateway. I would sniff on the server interface while you ping - do you see the pings going out to the nas IP? Is it the correct mac? If so then its an issue with the traffic not actually getting to the nas, or the nas not answering, or the nas not having a way to answer because wrong gateway or no gateway.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                I 1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8
                  last edited by

                  yeah the problem is the freenas, maybe try to restart it / check its network interface / check its firewall

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    I think he has floating rules as well, since looks like he is blocking outbound traffic on his lan with those arrows before the interface name.

                    BTW - you might want to edit your firewall log pic, your showing your wan IP there in those blocks to 1433 and 2236, oh your first pic of firewall rules is showing it as well.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • kiokomanK
                      kiokoman LAYER 8
                      last edited by kiokoman

                      that ipv6 blocking rule is due to the fact that he disabled ipv6 from here
                      Immagine.jpg

                      i think that removing that create a hidden floating rule

                      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                      Please do not use chat/PM to ask for help
                      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                      1 Reply Last reply Reply Quote 0
                      • I
                        ilovechickennuggets @johnpoz
                        last edited by ilovechickennuggets

                        @johnpoz @kiokoman

                        I have my NAS set up in the above picture after a new start over on the NAS. NAS gateway is pointing to 70.1
                        In addition, I have set pfsense DHCP server to identify the NAS by MAC address linking to 192.168.70.2 as static. I double checked and made sure the MAC of the NAS is matching correctly.

                        I am not able to log in or ping my NAS at 192.168.70.2 from my LAN network. Traffic graph on my pfsense dashboard now shows activity on 192.168.70.1, previously nothing.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          @ilovechickennuggets said in How to get 2 separate networks to talk to each other?:

                          I am not able to log in or ping my NAS at 192.168.70.2 from my LAN network

                          But can you ping it from the server IP on your pfsense?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          I 1 Reply Last reply Reply Quote 0
                          • I
                            ilovechickennuggets @johnpoz
                            last edited by

                            @johnpoz Did you mean in pfsense - Diagnostics -> Ping 192.168.70.2? I'm not quite understanding this.

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              yes - exactly how your pinging from the lan interface.. Just pick the server interface... example

                              ping.jpg

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              I 1 Reply Last reply Reply Quote 0
                              • I
                                ilovechickennuggets @johnpoz
                                last edited by

                                @johnpoz
                                setup10.PNG

                                No, 100% packet loss

                                1 Reply Last reply Reply Quote 0
                                • kiokomanK
                                  kiokoman LAYER 8
                                  last edited by

                                  eh now i remember an old 3d where someone enabled static arp and was unable to ping
                                  did you perhaps enabled static arp somewhere?

                                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                  Please do not use chat/PM to ask for help
                                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                  I 1 Reply Last reply Reply Quote 0
                                  • I
                                    ilovechickennuggets @kiokoman
                                    last edited by

                                    @kiokoman I have new information to present. I was doing my ping wrong using default as source. I was curious and tried again with LAN and also resulted in packet loss.
                                    setup11.PNG

                                    setup12.PNG
                                    setup13.PNG

                                    Static ARP is not enabled.

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      PING it from the SERVER IP of pfsense - change your source to server!!

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      I 1 Reply Last reply Reply Quote 0
                                      • I
                                        ilovechickennuggets @johnpoz
                                        last edited by

                                        @johnpoz setup10.PNG

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          Well sniff on pfsense server interface when you ping - looks like you have just plain connectivity problem..

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          1 Reply Last reply Reply Quote 0
                                          • kiokomanK
                                            kiokoman LAYER 8
                                            last edited by kiokoman

                                            the nas is out of the dhcp range, it must have a static entry, please check if you inadvertently enabled

                                            ARP Table Static Entry Create an ARP Table Static Entry for this MAC & IP Address pair.

                                            if so disable / untick it

                                            or if you have set a wrong gateway (should be empty)

                                            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                            Please do not use chat/PM to ask for help
                                            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.