Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Hyper-V pfsense setup with no internet behind LAN interface

    Virtualization
    hyper-v lan no internet
    4
    24
    4.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      Zung
      last edited by

      I have set up the following configuration using pfsense 2.4.4-3 ...

      Windows 10 PC hosts Hyper-v pfsense with 2 NICs. One is for WAN and the other is for LAN. Two virtual switches are associated with these 2 NICs. The installation was successful:
      wan hn0 ipv4 192.168.0.36/24
      lan hn1 ipv4 192.168.1.1/24

      I can access Web configuration OK via 192.168.1.1 on the same PC.
      I have connected the second NIC (for LAN) to a wireless router. Any PC connected to this wireless router has no internet.
      I even connected the second NIC directly to another PC and got the same result.
      Can somebody tell me what could be the issues with this setup?
      Thank you for any help. This is my first time here.

      provelsP 1 Reply Last reply Reply Quote 0
      • provelsP
        provels
        last edited by

        Interfaces / WAN / Reserved Networks
        Turn this OFF.
        ecb69a68-4bf1-40d5-978b-2082056c353e-image.png

        Peder

        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

        1 Reply Last reply Reply Quote 1
        • Z
          Zung
          last edited by

          I have unchecked the option. Saved it and reboot pfsense. Verified the option was not checked. But the problem remains.

          1 Reply Last reply Reply Quote 0
          • M
            Mats
            last edited by

            from that other pc - can you get to 192.168.1.1 ?

            Both your v-switches are of the type external - they should be

            1 Reply Last reply Reply Quote 0
            • Z
              Zung
              last edited by

              Yes they are external types

              1 Reply Last reply Reply Quote 0
              • Z
                Zung
                last edited by

                Excepting the host PC (with Pfsense) other PCs behind the LAN or PCs connecting to ISP router (same as the host PC) cannot get to 192.168.1.1

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @Zung
                  last edited by

                  @Zung said in Hyper-V pfsense setup with no internet behind LAN interface:

                  PCs connecting to ISP router (same as the host PC) cannot get to 192.168.1.1

                  These PC's connecting to the ISP router would be on the same network as what pfSense is calling WAN network.
                  Rather normal that these PC's can't connect to the LAN of pfSense without any NAT set up on pfSense. These PC's are on the wrong side of the firewall/router pfSense.

                  Btw "v-switches are of the type external" : that's fine but in that case both WAN and LAN or used somewhat exclusively for the Hyper-V client. Which is running pfSense. This way, all network traffic is perfectly isolated from even the host running pfSense in Heyper-V.
                  If you want the host PC that runs Hyper-V to access the Internet as any other PC that you hookup to the LAN, typically using a witch, you should have a third NIC in your host PC that should be connected to this LAN switch.
                  I'm not advertising this as best practice, but you could consider attaching the physical real LAN interface as shown here : https://docs.netgate.com/pfsense/en/latest/virtualization/virtualizing-pfsense-with-hyper-v.html : use the "Internal" network for the LAN.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  M 1 Reply Last reply Reply Quote 1
                  • M
                    Mats @Gertjan
                    last edited by

                    @Gertjan said in Hyper-V pfsense setup with no internet behind LAN interface:

                    Btw "v-switches are of the type external" : that's fine but in that case both WAN and LAN or used somewhat exclusively for the Hyper-V client. Which is running pfSense. This way, all network traffic is perfectly isolated from even the host running pfSense in Heyper-V.
                    If you want the host PC that runs Hyper-V to access the Internet as any other PC that you hookup to the LAN, typically using a witch, you should have a third NIC in your host PC that should be connected to this LAN switch.

                    There is no need for that. Simply check the "Allow management operating system to share this network adapter" on the LAN interface instead. That connects the host os to the lan V-switch without the need for extra hw

                    I'm not advertising this as best practice, but you could consider attaching the physical real LAN interface as shown here : https://docs.netgate.com/pfsense/en/latest/virtualization/virtualizing-pfsense-with-hyper-v.html : use the "Internal" network for the LAN.

                    That article is a mess. Since they use a private v-switch for lan only VM:s will be able to use the firewall.

                    As a reminder of V-switch types:
                    Private - Only between VM:s
                    Internal - VM:s and host OS
                    External - VM:s, host OS (if you allow it) and externally through a physical nic

                    1 Reply Last reply Reply Quote 1
                    • Z
                      Zung
                      last edited by

                      It is interesting that at one time I swapped out the second NIC and I got internet via this NIC i.e. connecting with ethernet cable from this NIC to PC. However this is not repeatable. I am not sure what I did to have it happened or not happened. I know that I do not change much as far as configuration goes. I even reinstalled pfsense several times without success .

                      1 Reply Last reply Reply Quote 0
                      • Z
                        Zung
                        last edited by

                        Has anybody had any suggestions on what could cause this issue?

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          Mats @Zung
                          last edited by

                          @Zung

                          Sorry but no, not at the moment

                          1 Reply Last reply Reply Quote 0
                          • M
                            Mats
                            last edited by

                            can you make a sketch of how your network looks like.
                            Might be something simple being overlooked

                            1 Reply Last reply Reply Quote 0
                            • provelsP
                              provels @Zung
                              last edited by

                              @Zung said in Hyper-V pfsense setup with no internet behind LAN interface:

                              I have connected the second NIC (for LAN) to a wireless router. Any PC connected to this wireless router has no internet.

                              What port on the wireless router are you using? Should be a LAN port, not the WAN.

                              Peder

                              MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                              BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                              Z 1 Reply Last reply Reply Quote 0
                              • Z
                                Zung @provels
                                last edited by

                                @provels said in Hyper-V pfsense setup with no internet behind LAN interface:

                                @Zung said in Hyper-V pfsense setup with no internet behind LAN interface:

                                I have connected the second NIC (for LAN) to a wireless router. Any PC connected to this wireless router has no internet.

                                What port on the wireless router are you using? Should be a LAN port, not the WAN.

                                It did not work even with a direct ethernet wired connection between the second NIC and another computer.

                                Here is my situation ...

                                ISP-->switch-->NIC1 of Window 10/Hyper-V/Pfsense from NIC2--->another PC or switch or wireless router.

                                If this config was set with from base hardware i.e. (no WIndows 10+Hyper-v) then this would work fine.

                                1 Reply Last reply Reply Quote 0
                                • M
                                  Mats
                                  last edited by

                                  this seems like some kind of issue with the nic in Windows then.

                                  If I get it right with win 10 on the box and a straight cable to the next box it works.
                                  With win 10 + hyper-v it stops working? Is the allow management operating ...... checked for that adapter?

                                  1 Reply Last reply Reply Quote 0
                                  • Z
                                    Zung
                                    last edited by

                                    You are right that NIC could be a probelm. At first I have used old NIC (lying around the house for years) and it was a hit-and-miss affairs even with bare metal pfsense pc box. After I bought a new Dlink NIC (having 1gb speed too) that the base box behaved more consistent i.e. internet was OK behind LAN.

                                    However when I configured the PC with Windows 10 using Hyper-V to created pfsense box then there was no internet behind the LAN. To me the virtualization of the NIC may have something to do with it. I will keep investigating if anywhere people have same problem or not.

                                    Thank you very much for spending time and offering suggestions to my issue. If you have any other ideas please share them with me. I appreaciate it very much.

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      Mats
                                      last edited by

                                      Have you tried different drivers for the Nic?
                                      I have run into one issue with a realtec card and Hyper-V but it was more than 5 years ago server 2008r2 or 2012 so I'm rather sure it's not exactly the same issue

                                      Z 1 Reply Last reply Reply Quote 0
                                      • Z
                                        Zung @Mats
                                        last edited by

                                        Hi Mats, I updated the NIC driver as detected by Windows 10. However, that did not help either until I preassigned the IPV4 address for the second NIC i.e. static IP address instead of 'obtained an IP address automatically'. That did it! Now PCs behind the LAN interface have internet access.

                                        Thank you very much for your and others' help all along.

                                        My next step is to implement OPENVPN using VPNBOOK services.

                                        1 Reply Last reply Reply Quote 0
                                        • Z
                                          Zung
                                          last edited by

                                          I spoke too early. It was working for hours but failed later for no apparent reason. No internet at LAN connections. I could not recreate the working scenario anymore.

                                          1 Reply Last reply Reply Quote 0
                                          • M
                                            Mats
                                            last edited by

                                            Hmmm, this one seems tricky.
                                            A long shot - do you have any third party antivirus, firewall or other security software on that Win10 box?

                                            Z 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.