Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to get 2 separate networks to talk to each other?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    74 Posts 3 Posters 12.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      Well then no nothing is going to work... Can the server ping pfsense IP? Does internet work? You have it directly plugged into an interface on pfsense - there are no switches.

      I am not sure that your doing the sniff correctly to be honest.. do a tcpdump on pfsense while you ping..

      Open up 2 ssh windows to pfsense and do it this way... start a tcpdump for icmp on the interface this server network is on..

      Then in the other windows ping... Then also ping from the server to 70.1 address while your sniff is running

      example
      ping.jpg

      This sever is physical right - its not some VM running on something?

      Lets try this - install the package arping... Lets try that..

      example
      arping.jpg

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      I 1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by

        now i'm curious to see where the hell we are hitting the head

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • I
          ilovechickennuggets @johnpoz
          last edited by

          @johnpoz @kiokoman
          The server is a physical machine directly connected to pfsense interface with no switches in between this connection. Unfortunately, I am out of time for now and will come back to this later to try this.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            see my edit.. about using arping package as well.

            Clearly you would use server as the interface and ip of your nas..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            I 1 Reply Last reply Reply Quote 0
            • I
              ilovechickennuggets @johnpoz
              last edited by

              @johnpoz @kiokoman
              Ok I did a complete shut down and reboot. The NAS is now getting the correct static IP. In Pfsense, under Status/ DHCP Leases -showing as online
              setup23.PNG

              I installed ARPing and ran it with following settings
              setup21.PNG
              setup22.PNG

              As for SSH and tcpdump, I am going to need to educate myself on this because I'm treading onto something completely new to me. I'll be back try your advice after I go through some documentations and tutorials. I don't have SSH set up and it looks like I need to generate a key.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                so arping works, but normal ping does not?

                That just SCREAMS, SCREAMS!!! firewall on that box!!!

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                I 1 Reply Last reply Reply Quote 0
                • I
                  ilovechickennuggets @johnpoz
                  last edited by

                  @johnpoz
                  setup24.PNG
                  Correct, this is the newest try at pinging.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Well your clearly arping for the IP.. Which comes back with mac correct, and you got your dhcpd address you reserved. So you seem to not being answering..

                    The odd thing is you didn't show any pings going out even when you tried to ping.. Which makes no sense - unless you didn't do the sniff right..

                    Again can the server ping pfsense IP? Sniff when your doing that test..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    I 1 Reply Last reply Reply Quote 0
                    • I
                      ilovechickennuggets @johnpoz
                      last edited by

                      @johnpoz
                      Sorry! Ran the sniff and ping from NAS server to 192.168.70.1 resulted in 100% packet loss.
                      setup25.PNG
                      setup26.PNG

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Ok so your seeing traffic to pfsense interface on 192.168.70.1 - but no answers!

                        That points to firewall on pfsense, but that shouldn't stop you from pinging from pfsense unless you have an outbound rule on your lan.. Do you have anything in floating?

                        example

                        example.jpg

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        I 1 Reply Last reply Reply Quote 0
                        • I
                          ilovechickennuggets @johnpoz
                          last edited by

                          @johnpoz
                          Current floating and LAN rules
                          setup27.PNG
                          setup28.PNG

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by johnpoz

                            Well what interfaces do you have all those rules on? Its quite possible your blocking something in all those rules...

                            Disable them all for "testing"

                            Your lan and server rules mean nothing for pinging from pfsense - the only thing that could cause what seeing would be a outbound rule on your server interface blocking pfsense from sending the ping even..

                            What are you rules on your server interface?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            I 1 Reply Last reply Reply Quote 0
                            • I
                              ilovechickennuggets @johnpoz
                              last edited by ilovechickennuggets

                              @johnpoz
                              So counting from top to bottom, the first 11 rules (pfB_Top_v4 to pfb_TOR_v4) - all 11 have the same setting with block to WAN interface only (only WAN is highlighted in interface box).
                              setup29.PNG

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by

                                Ok well your server interface rules would not allow ping.. So that explains why pfsense would not answer ping.

                                Set a rule to allow ping to pfsense server address.
                                And possible dns is not listening on on 70.1

                                Set your ping rule, and try to ping from server again to 70.1

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                I 1 Reply Last reply Reply Quote 0
                                • I
                                  ilovechickennuggets @johnpoz
                                  last edited by

                                  @johnpoz
                                  Is this the correct way to set up this rule?
                                  setup31.PNG

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by johnpoz

                                    No!

                                    On your server interface allow ping to the server address.

                                    example
                                    example.jpg

                                    You want to allow your server to ping pfsense server IP 70.1 - lets get that working atleast!

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    I 1 Reply Last reply Reply Quote 0
                                    • I
                                      ilovechickennuggets @johnpoz
                                      last edited by

                                      @johnpoz
                                      Ping resulted in 100% packet loss
                                      setup32.PNG
                                      setup33.PNG

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by

                                        OH my GAWD!! dude... how is the dest 70.2 that is not pfsense IP address!!

                                        Please set a rule on your server interface to allow PING to pfsense address server address.. And ping from your server..

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        I 1 Reply Last reply Reply Quote 0
                                        • I
                                          ilovechickennuggets @johnpoz
                                          last edited by

                                          @johnpoz
                                          Sorry! Dumb mistake! Fixed it. I pinged from the NAS and resulted in packet loss
                                          setup35.PNG
                                          setup36.PNG

                                          1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator
                                            last edited by johnpoz

                                            Well there is something major wrong... You sure pfsense IP is actually 192.168.70.1?

                                            Can you use a different interface? You don't have any vlans setup or anything like that?

                                            Why was there no answer to the dhcp you show there on port 67? You can arp, but not doing any sort of traffic... Makes no sense at all..

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                                            I 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.