Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN not getting IP

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    39 Posts 2 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DaddyGoD
      DaddyGo
      last edited by

      I see that there is a Dell (vendor) MAC address in the interface list as a WAN interface. (I don't think this is the ISP CPE)

      if the MAC spoofing is successful, you can see the MAC of the old / ISP router here

      85664ab0-2eb0-4397-b214-54cd2993e338-image.png

      I think MAC spoofing failed, because you need to show something like this with different MAC addresses within a device....

      this is a 4 eth. port on APU device with spoofed MAC address on WAN (with Cisco MAC)

      2f861427-efe1-46fe-b99b-a2593ae8947f-image.png

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      1 Reply Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo
        last edited by

        your PRTSC is show that, you have all interfaces on b8: ca: 3a: ........ this a DELL NIC

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 0
        • DaddyGoD
          DaddyGo
          last edited by

          sorry if you've tried this in the meantime and haven't taken a new screenshot,
          Your VLAN setup is good at first glance, what does the dhcp log file show?.....by the way :-)?

          Cats bury it so they can't see it!
          (You know what I mean if you have a cat)

          1 Reply Last reply Reply Quote 0
          • DaddyGoD
            DaddyGo
            last edited by

            One more idea, sorry I'm not very consistent.....

            PPPOE + Dell hardware I go further...
            Dell Hardware = Broadcom bce(4) Cards ??? (BCM57XX family)
            maybe it is: PPPoE with Multi-Queue NICs - https://docs.netgate.com/pfsense/en/latest/hardware/tuning-and-troubleshooting-network-cards.html

            Sorry, if I'm little bit to much to you, but this COVID has locked everyone in theirs home and the home office clients are working well so I have had a lot of free time .....

            Cats bury it so they can't see it!
            (You know what I mean if you have a cat)

            M 2 Replies Last reply Reply Quote 0
            • M
              MrSunamix @DaddyGo
              last edited by

              @DaddyGo Don't worry im so thankfull for your time, im just getting the think you asked me, I managed to get to work de MAC spoofing, now im gonna test if the ONT get's the ip into the router.

              1 Reply Last reply Reply Quote 0
              • M
                MrSunamix @DaddyGo
                last edited by

                @DaddyGo Okay, we made progress, now my ONT starts blinking on the lan side, it seems that it's trying to do something, also the PPPOE conecction goes up than goes down, give a moment and ill make a screenshot of the DHCP logs.

                1 Reply Last reply Reply Quote 0
                • DaddyGoD
                  DaddyGo
                  last edited by

                  if you have time, read into this, although it is not FTTH, but DOCSIS, but there may be crosstalk between them: https://forum.netgate.com/topic/151929/pfsense-wan-interface-wont-get-ip-address

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  M 2 Replies Last reply Reply Quote 0
                  • M
                    MrSunamix @DaddyGo
                    last edited by

                    @DaddyGo I have plenty of time hahaha, also I have a dell poweredge r620 with and integrated intel i350-t4 nic, im planning on getting another 4Port also i350 and a dual port sfp+ to get rid of the ONT aswell, this is for future upgrade, first I want to have it working.

                    1 Reply Last reply Reply Quote 0
                    • M
                      MrSunamix @DaddyGo
                      last edited by MrSunamix

                      @DaddyGo Just a stupid question, having the clock wrongly set can impact the way it get's acces to the ISP server, or it just mess up with just the logs and anything else. I know that having a minute behind for example, google authinticator doesn't work anymore, just asking for that reason.

                      1 Reply Last reply Reply Quote 0
                      • DaddyGoD
                        DaddyGo
                        last edited by

                        of course, NTP is very important, just think of certificates with SSL
                        but that's another question, hmmm
                        BTW, specify your time exactly, because the timings are based on that as well
                        especially since pfSense is a very good NTP server on your network and you don't need to use external pools

                        Cats bury it so they can't see it!
                        (You know what I mean if you have a cat)

                        1 Reply Last reply Reply Quote 0
                        • DaddyGoD
                          DaddyGo
                          last edited by

                          we use old, but little used Dell R210IIs for pfSense with NICs I350-F4 / I350-T4 (because the on -board BCM chipset is not very suitable for IPS) / it’s a fantastic configuration, it survives everything

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            MrSunamix @DaddyGo
                            last edited by

                            @DaddyGo Okay, im gonna set the time right, also I need to take a break for this, my roommate started playing a videogame and I can't mess with the network right now till 23 so ill be back on doing testing at that hour, thanks so much honestly you made more progress for me than the 4 days im stuck with this. I'll reply with more thinks later as I can mess with the network again.

                            1 Reply Last reply Reply Quote 0
                            • DaddyGoD
                              DaddyGo
                              last edited by

                              thank you for your kind comment, let’s spend time with what we love
                              if I can even help, I'll be here tomorrow and now I'll check out the How the Universe Works (next episode)

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                MrSunamix @DaddyGo
                                last edited by

                                @DaddyGo Back at work hahaha, I changed the time, this is the DHCP log is showing up, ill link the pictures throught drive because it's faster than taking a screenshot and uploading since only my laptop has an internet connection (https://drive.google.com/open?id=1-1ooMoEYBpKMLVECANBQ9Hvi2wyp3y8d) that's what DHCP is showing.

                                1 Reply Last reply Reply Quote 0
                                • DaddyGoD
                                  DaddyGo
                                  last edited by

                                  Two things :-)
                                  so that we can get into the "picture" more seriously, so your system looks like this: ISP modem or router (in bridge mode) + pfSense box ???

                                  the another:

                                  • the following should be observed in the dhcp log.... from WAN
                                    but in front of it press a button on the status / interface tab, WAN section "release WAN" / with this button we start a process which, if we are lucky, generates a log entry in dhcp

                                  Cats bury it so they can't see it!
                                  (You know what I mean if you have a cat)

                                  M 2 Replies Last reply Reply Quote 0
                                  • M
                                    MrSunamix @DaddyGo
                                    last edited by

                                    @DaddyGo my actual system is like this ONT->pfSense box, the ONT is a Nokia G-010G-PPL, in it's config it doesn't have any toggle for bridge mode so it's bare as it is on it's own, ill get that button pressed in a moment and ill share the result.

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      MrSunamix @DaddyGo
                                      last edited by MrSunamix

                                      @DaddyGo Sorry to bother you but I can't find that "release wan" button this is what I have (https://drive.google.com/open?id=1-MPYaGvSxfTnW02o-kkVxdYjGNeEGXE2) also everytime I try to connect "WAN_FI" it automatically disconnects, so that's the "problem"

                                      1 Reply Last reply Reply Quote 0
                                      • DaddyGoD
                                        DaddyGo
                                        last edited by

                                        This is similar to what we use in Portugal: Altice Network = (Nokia)
                                        I know this ONT well, but it's always paired with an ISP router like Technicolor brand.
                                        It doesn’t work on its own (ONT), in general.
                                        So that's eth. port (on ONT) does not directly access the GPON network.
                                        This way you can't switch directly to pfSense box. (by replacing your original ISP's router)

                                        Requires: original ISP ONT (Nokia Altice) + original ISP router configured in bridge mode + pfSense box

                                        Are you trying to connect the pfSense box directly to your ISP ONT?
                                        Do I think the situation is right?
                                        Or am I on the wrong way?

                                        Cats bury it so they can't see it!
                                        (You know what I mean if you have a cat)

                                        M 1 Reply Last reply Reply Quote 0
                                        • M
                                          MrSunamix @DaddyGo
                                          last edited by MrSunamix

                                          @DaddyGo Yes, you nailed, im trying to connect the pfSense box directly to the ONT, the router provided doesn't have either a bridge mode or something similar to it, so it's kind imposible to configure it that way. Would this be posible if I buy an SFP+ GPON ONT trasciever and put the data of the nokia ont into the transciever?

                                          1 Reply Last reply Reply Quote 0
                                          • DaddyGoD
                                            DaddyGo
                                            last edited by

                                            We solved the problem :-)
                                            You cannot get a dynamic IP for pfSense directly from the ONT!

                                            The providers (ISPs) usually give the option to bridge mode, pls. call your ISP.....
                                            and if possible in the ISP’s policy (business) then they centrally set your bridge mode, with that set the original ISP router to one of eth. port to bridge port

                                            Don't experiment with your own GPON SFP and similar solutions, it WILL NOT WORK! (money toss)
                                            The Altice Network has the same structure everywhere and I know it well

                                            Cats bury it so they can't see it!
                                            (You know what I mean if you have a cat)

                                            M 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.