Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    XG2758 LAN not getting out to WAN

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    29 Posts 5 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      david.mundt @akuma1x
      last edited by

      @akuma1x This is a fresh install, I wiped the old config using the console cable. I switched to ASA a few years back so I'm sure all that's wrong is a misconfiguration.
      Version 2.4.5 is running and screenshots of rules are attached. I'm using the ping tool to try and ping the next hop from the WAN interface and it doesn't![alt text](image url) ping.Screen Shot 2020-04-15 at 11.25.36 AM.png Screen Shot 2020-04-15 at 11.24.04 AM.png Screen Shot 2020-04-15 at 11.23.50 AM.png

      1 Reply Last reply Reply Quote 0
      • A
        akuma1x
        last edited by akuma1x

        Your WAN rules look a little wonky. I say that, because this is the default:

        MQ5_hB0ugCXoRr2XnWiyQiwmvAtUC1YxoEUWxn5e2gY.png

        Block private and bogon networks is selected during setup, but you can reactivate them here:

        Interfaces -> WAN, all the way at the bottom.

        screenshot775648.png

        That single WAN rule you've got in there isn't valid, you can delete it. Also, you didn't answer the DNS question, what have you got setup in there?

        System -> General Setup -> DNS Server Settings

        Did you setup anything on your Floating firewall rule tab?

        Jeff

        1 Reply Last reply Reply Quote 0
        • D
          david.mundt
          last edited by

          @akuma1x screenshots attached

          Screen Shot 2020-04-15 at 12.34.06 PM.png Screen Shot 2020-04-15 at 12.33.50 PM.png Screen Shot 2020-04-15 at 12.33.30 PM.png Screen Shot 2020-04-15 at 12.32.55 PM.png

          1 Reply Last reply Reply Quote 0
          • A
            akuma1x
            last edited by akuma1x

            @david-mundt You generally don't need to define gateways for the DNS servers. If you mark those 2 dropdown menus, the ones next to 1.1.1.1 and 8.8.8.8 in your screenshot, as "none" that might fix this problem.

            Here's an example screenshot I found on the net:

            pfsense_dns_servers.png

            The boxes to the right of the red-outilned DNS server boxes are the ones I'm talking about. Set yours the same way. Might need to reboot the pfsense box when you're done, but maybe not.

            Jeff

            D 1 Reply Last reply Reply Quote 0
            • D
              david.mundt @akuma1x
              last edited by

              @akuma1x said in XG2758 LAN not getting out to WAN:

              t

              I actually just turned those on to try to get a ping out of the WAN but I will turn them back off.

              A 1 Reply Last reply Reply Quote 0
              • A
                akuma1x @david.mundt
                last edited by

                @david-mundt Any luck yet?

                Jeff

                D 1 Reply Last reply Reply Quote 0
                • D
                  david.mundt @akuma1x
                  last edited by

                  @akuma1x no luck... It's not making any sense to me.

                  1 Reply Last reply Reply Quote 0
                  • A
                    akuma1x
                    last edited by akuma1x

                    @david-mundt If it were me, and if it won't disrupt the network it's on too much, I would reset the pfsense box back to factory defaults and start from scratch.

                    https://docs.netgate.com/pfsense/en/latest/config/factory-defaults.html

                    When you go thru the setup process, don't put in anything special. These tutorial steps here (see page with setup screenshots) are the most basic, besides manually entering DNS servers, which is ok for this exercise, and should get you up and running very quickly.

                    https://techexpert.tips/pfsense/pfsense-server-installation/

                    Again, still a couple of unanswered questions from earlier...

                    Which port on the pfsense box did you use for WAN - one of the SFP ports, or one of the RJ45 ports? If SFP ports, is the link actually alive and active? Sometimes, if you use a 3rd party SFP adapter, they behave unexpectedly.

                    Who is your ISP? Sometimes when you install a NEW router between the ISP modem and LAN network, the ISP modem needs to be restarted before traffic will flow to/from the internet. Cable modems are notorious for this type of behavior.

                    Jeff

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by stephenw10

                      Yes, at a basic level does the WAN have a link to whatever it's attached to? At the correct link rate?
                      Check Status > Interfaces.

                      You have a WANGW but it looks like it was configured as static, correct?
                      Does it show as up in Status > Gateways?

                      Can you ping anything from pfSense itself via Diag > Ping?

                      The most likely explanation is that the WAN is misconfigured or not connected correctly.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Can you even ping out to anything like 8.8.8.8 using Diagnostics > Ping?

                        If not, why not?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • D
                          david.mundt
                          last edited by david.mundt

                          Ok guys I just wiped the appliance and restored it to factory. I added the interface addresses in the terminal, logged into the device and set the external DNS servers. I still cant ping anything out of the WAN interface. The device is so easy to configure I cant imagine what is going wrong.

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            Again, just in case you missed it: https://docs.netgate.com/pfsense/en/latest/routing/connectivity-troubleshooting.html

                            -Rico

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Still the same questions, start from the lowest level and work up:

                              Do you see link LEDs on the WAN?

                              Do you see the WAN pull and IP address (if it's using dhcp)?

                              If it's static check the ARP table for anything on the WAN.

                              Steve

                              D 1 Reply Last reply Reply Quote 0
                              • D
                                david.mundt
                                last edited by david.mundt

                                This post is deleted!
                                1 Reply Last reply Reply Quote 0
                                • D
                                  david.mundt
                                  last edited by

                                  This post is deleted!
                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    david.mundt @stephenw10
                                    last edited by

                                    @stephenw10 said in XG2758 LAN not getting out to WAN:

                                    Still the same questions, start from the lowest level and work up:

                                    Do you see link LEDs on the WAN?

                                    Do you see the WAN pull and IP address (if it's using dhcp)?

                                    If it's static check the ARP table for anything on the WAN.

                                    Steve

                                    Sorry for the delay guys. I've been swamped and just now able to get back to this.

                                    The LAN and WAN links show link lights

                                    WAN pulls an IPv6 address from DHCP but not IPv4 so I set it to static

                                    ARP table shows a MAC from the upstream first hop router with the ISP

                                    Dashboard shows both interfaces as UP... Still unable to ping outside

                                    Screen Shot 2020-04-22 at 8.00.25 AM.png

                                    WAN IP is not missing its just been redacted on this screenshot

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Does it pull a real, routable IPv6 address? Can you ping6 out of it?

                                      But you cannot ping the first hop device using whatever IP it appears as?

                                      Are you sure you're using the correct IP and gateway info?

                                      Steve

                                      D 1 Reply Last reply Reply Quote 0
                                      • D
                                        david.mundt @stephenw10
                                        last edited by

                                        @stephenw10 said in XG2758 LAN not getting out to WAN:

                                        Does it pull a real, routable IPv6 address? Can you ping6 out of it?

                                        But you cannot ping the first hop device using whatever IP it appears as?

                                        Are you sure you're using the correct IP and gateway info?

                                        Steve

                                        config is what ISP provided. Yes it is correct, it's the same IP config loaded on the old internal router.

                                        I am able to ping google.com using IPv6 but it fails for IPv4

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          If it is supposed to be DHCP and you set it to static it will probably not work.

                                          Configure it how the ISP says to configure it based on how it is provisioned.

                                          If it is supposed to be DHCP and you are not getting a lease you need to troubleshoot why - maybe with the ISP - not set it to some random provisioning.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          D 1 Reply Last reply Reply Quote 0
                                          • D
                                            david.mundt @Derelict
                                            last edited by

                                            @Derelict said in XG2758 LAN not getting out to WAN:

                                            If it is supposed to be DHCP and you set it to static it will probably not work.

                                            Configure it how the ISP says to configure it based on how it is provisioned.

                                            If it is supposed to be DHCP and you are not getting a lease you need to troubleshoot why - maybe with the ISP - not set it to some random provisioning.

                                            ISP is spectrum and I've got other clients using the same ISP and it's always a static IPv4 address. I just tried DHCP on 4 and 6 and IPv4 gets 0.0.0.0 for its IP.

                                            Still able to ping google.com with v6 and unable to ping using v4

                                            DerelictD 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.