Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to get 2 separate networks to talk to each other?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    74 Posts 3 Posters 12.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      Well what interfaces do you have all those rules on? Its quite possible your blocking something in all those rules...

      Disable them all for "testing"

      Your lan and server rules mean nothing for pinging from pfsense - the only thing that could cause what seeing would be a outbound rule on your server interface blocking pfsense from sending the ping even..

      What are you rules on your server interface?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      I 1 Reply Last reply Reply Quote 0
      • I
        ilovechickennuggets @johnpoz
        last edited by ilovechickennuggets

        @johnpoz
        So counting from top to bottom, the first 11 rules (pfB_Top_v4 to pfb_TOR_v4) - all 11 have the same setting with block to WAN interface only (only WAN is highlighted in interface box).
        setup29.PNG

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Ok well your server interface rules would not allow ping.. So that explains why pfsense would not answer ping.

          Set a rule to allow ping to pfsense server address.
          And possible dns is not listening on on 70.1

          Set your ping rule, and try to ping from server again to 70.1

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          I 1 Reply Last reply Reply Quote 0
          • I
            ilovechickennuggets @johnpoz
            last edited by

            @johnpoz
            Is this the correct way to set up this rule?
            setup31.PNG

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              No!

              On your server interface allow ping to the server address.

              example
              example.jpg

              You want to allow your server to ping pfsense server IP 70.1 - lets get that working atleast!

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              I 1 Reply Last reply Reply Quote 0
              • I
                ilovechickennuggets @johnpoz
                last edited by

                @johnpoz
                Ping resulted in 100% packet loss
                setup32.PNG
                setup33.PNG

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  OH my GAWD!! dude... how is the dest 70.2 that is not pfsense IP address!!

                  Please set a rule on your server interface to allow PING to pfsense address server address.. And ping from your server..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  I 1 Reply Last reply Reply Quote 0
                  • I
                    ilovechickennuggets @johnpoz
                    last edited by

                    @johnpoz
                    Sorry! Dumb mistake! Fixed it. I pinged from the NAS and resulted in packet loss
                    setup35.PNG
                    setup36.PNG

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      Well there is something major wrong... You sure pfsense IP is actually 192.168.70.1?

                      Can you use a different interface? You don't have any vlans setup or anything like that?

                      Why was there no answer to the dhcp you show there on port 67? You can arp, but not doing any sort of traffic... Makes no sense at all..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      I 1 Reply Last reply Reply Quote 0
                      • I
                        ilovechickennuggets @johnpoz
                        last edited by

                        @johnpoz
                        The vlans are all on the LAN side (192.168.69.1) with switch.
                        The SERVER side has nothing, just a straight direct connection to NAS.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz

                          Well makes no sense at all... Do you have another interface you can use? Another cable.. Post a ifconfig output on pfsense. If it was a bad cable - you would think you wouldn't see the traffic too pfense, and you would see traffic out even if didn't get to the client when you sniff when you pinged.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          I 1 Reply Last reply Reply Quote 0
                          • I
                            ilovechickennuggets @johnpoz
                            last edited by ilovechickennuggets

                            @johnpoz
                            ifconfig

                            I do have one more open interface and 1 extra cable. Let's call it a day for now and maybe try some other time and set up the rules and etc for new interface.

                            Thank you both for your time today! @kiokoman

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              dude... How do you have 192.168.70.1 on igb2, and you also have it on igb1.70??

                              Pfsense shouldn't even let you do that - because the interfaces overlap!!

                              broken.jpg

                              Yeah that is not going to work ;)

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              I 1 Reply Last reply Reply Quote 0
                              • I
                                ilovechickennuggets @johnpoz
                                last edited by ilovechickennuggets

                                @johnpoz
                                igb1.70 is a vlan right? That was deleted sometime ago and doesn't exist currently? Here's all of the vlans as of now:

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz

                                  But the interface is still there via your ifconfig - so yeah that not going to work ;)

                                  I would check in your xml - forwhatever reason its still there.. So yeah big issue!

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  I 1 Reply Last reply Reply Quote 0
                                  • I
                                    ilovechickennuggets @johnpoz
                                    last edited by

                                    @johnpoz
                                    Nice! How do I get rid of it cleanly? This doesn't actually show up on my GUI. I have routine XML backups so doing it through XML shouldn't be a problem.

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by johnpoz

                                      I would look in your xml to see if its stuck in their somehow.. Then you could remove it from the xml and then reload.. Then do a reboot to validate it goes away.

                                      You could remove it from cli command - but if its stuck in some xml, then on a reboot it could get put back.

                                      I thought I was going nuts - cuz it sure didn't make sense. But now seeing you have 2 interfaces with the same IP makes sense that it was sending traffic out the other interface - or trying ;) So yeah our symptoms make sense for this sort of issue.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      I 1 Reply Last reply Reply Quote 0
                                      • I
                                        ilovechickennuggets @johnpoz
                                        last edited by

                                        @johnpoz
                                        Oh so I can just go through xml and delete all lines related to igb1.70? Just to be clear on the correct way:

                                        1. Delete igb.70 from xml
                                        2. Restore new xml
                                        3. Reboot and check xml again
                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          Yeah must be something left in the xml I would think... Or maybe the interface just didn't get delete.. But I have to assume you have rebooted at some point in troubleshooting this.

                                          So I take it something must be messed up in the xml.

                                          So validate its not in there in some messed up way.. If it is, remove it and then restore it. And then either delete the interface with cli, or reboot and make sure that igb1.70 interface is not there.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          I 1 Reply Last reply Reply Quote 0
                                          • I
                                            ilovechickennuggets @johnpoz
                                            last edited by ilovechickennuggets

                                            @johnpoz
                                            So I looked through the entire XML file line by line and also with search function using any combinations of igb1, igb1.70, 70, and igb. Igb1.70 or even vlan 70 does not exist in the XML file at all anywhere. I ran ifconfig and it does still indeed show up. Thoughts on maybe something I missed?
                                            This is the only group of igb.X in the entire XML file.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.