• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

3rd and 4th Lan Ports for internet

Scheduled Pinned Locked Moved Routing and Multi WAN
24 Posts 5 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    Gertjan
    last edited by Gertjan Sep 30, 2020, 11:05 AM Sep 30, 2020, 11:04 AM

    When you (think you) finished the setup of OPT1 :
    Connect the cable of a device - typically, a PC.

    Use the

    ipconfig /all
    

    command to check if the IP, mask, gateway and DNS are ok.

    The gateway and DNS should be the IP of pfSense, the interface you are connected to.
    The IP should be in the pool of that interface.

    Also, check on pfSense, Status > System Logs > DHCP and look for the MAC of your device you connected to the OPT interface. The same IP - the 'lease' is shown there .

    The firewall rules you shwoed, one for IPv4 and one for IPv6 are ok.
    IPv6 are needed only needed if you actually need and set up IPv6 .

    No "help me" PM's please. Use the forum, the community will thank you.
    Edit : and where are the logs ??

    1 Reply Last reply Reply Quote 0
    • J
      jonefc
      last edited by Oct 2, 2020, 3:14 PM

      done everything above, and still no luck !

      Any ideas. I copied the firewall profile as shown below.

      6a03c475-04f2-4cf5-aa65-6afddc5c5d14-image.png

      D 2 Replies Last reply Oct 2, 2020, 3:56 PM Reply Quote 0
      • J
        jonefc
        last edited by Oct 2, 2020, 3:24 PM

        i get nothing on the other connections using IPCONFIG

        fc1caef1-bd78-4e41-9da4-92aab9ca2cac-image.png

        1 Reply Last reply Reply Quote 0
        • P
          pete35
          last edited by Oct 2, 2020, 3:38 PM

          pls show the rules for opt1 and opt2, and the dhcp server for opt1 and opt2. There should be a rule " IP4 * allow any to any" in opt1 and opt2 and a running dhcp server on both interfaces.

          <a href="https://carsonlam.ca">bintang88</a>
          <a href="https://carsonlam.ca">slot88</a>

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Oct 2, 2020, 3:56 PM

            Well your never going to get anywhere with a 169.254 address. Clearly you device did not get an IP from dhcp server.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • D
              DaddyGo @jonefc
              last edited by DaddyGo Oct 2, 2020, 3:58 PM Oct 2, 2020, 3:56 PM

              @jonefc said in 3rd and 4th Lan Ports for internet:

              I copied the firewall profile as shown below.

              the copy must be apply / validated on OPT1 and OPT2, not under the LAN interface

              +++edit:
              the firewall sets the "default allow rule" to LAN only by default

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Oct 2, 2020, 4:05 PM

                While true he needs firewall rules on optX interfaces to allow internet access from them.

                Step 1 in his problem is whatever client that was on whatever optX network is not getting IP from dhcp server.

                You need to validate dhcp server is enabled on your optX interface, and the client that is set for dhcp is actually connected to this optX network..

                Either directly into the interface on your pfsense box, or a switch that is only connected to this optX network and your clients you want on this optX network.

                You can not plug lan and optX networks into some dumb switch and hope to run multiple L2 networks on it and for dhcp to just magically know which client should get what IP from which dhcp server.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                D 1 Reply Last reply Oct 2, 2020, 4:10 PM Reply Quote 0
                • D
                  DaddyGo @johnpoz
                  last edited by DaddyGo Oct 2, 2020, 4:13 PM Oct 2, 2020, 4:10 PM

                  @johnpoz

                  In principle, the OP configured a DHCP server somewhere for OPT1, but it failed....?!? (shown above)...hmmm

                  192.168.2.0.....if I see it right

                  so there are several problems here

                  +++edit:
                  I suggested him / her read the handbook first, because these are very basic steps, what will happen later?

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz Oct 2, 2020, 4:14 PM Oct 2, 2020, 4:12 PM

                    Yeah failed why? He never stated where he has that device plugged in. Maybe it connected it to opt2 and only enabled dhcp on opt1?

                    But clearly the optput of ipconfig shown did not get an IP from dhcp server. 169.254 isn't going anywhere that is a APIPA address when a dhcp client doesn't get an IP from a dhcp server.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    D 1 Reply Last reply Oct 2, 2020, 4:18 PM Reply Quote 0
                    • D
                      DaddyGo @johnpoz
                      last edited by Oct 2, 2020, 4:18 PM

                      @johnpoz said in 3rd and 4th Lan Ports for internet:

                      169.254 isn't going anywhere

                      this is true....

                      he wants both interfaces, (OPT1 / OPT2), but none succeed

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz Oct 2, 2020, 4:28 PM Oct 2, 2020, 4:24 PM

                        Did he remove the bridge nonsense he setup?

                        There is not enough info to try and help him figure out what he is doing wrong.

                        If interface is configured with an IP, and dhcp is enabled on this interface. Then a dhcp client connected to that interface should and would get an IP from the dhcp server.

                        If doesn't then no its not going to get internet.

                        Once it gets an IP and other info from the dhcp server, gateway, dns - then you would need firewall rules on this interface to allow whatever traffic you want.

                        And you would also need outbound nat, which should be automatic and working as soon as created an IP on the interface and enabled it. But you don't know maybe he set his outbound nat to manual?

                        First step is to figure out why client that is set for dhcp did not get an IP from the dhcp server.

                        But also we need to know what he is plugging into this opt interface, is it the same dumb switch he is using for his lan interface, is it a windows device directly? Is it some wifi router? etc..

                        For all we know he plugged in some wifi router into this opt interface and its wan got an IP, but the lan side of that wifi router where he has his client connected doesn't have dhcp enable?

                        Info is required to help figure out whatever the problem is - without information, any guessing to what might be the issue is just that, guessing.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • D
                          DaddyGo @jonefc
                          last edited by DaddyGo Oct 2, 2020, 6:44 PM Oct 2, 2020, 5:02 PM

                          @jonefc said in 3rd and 4th Lan Ports for internet:

                          Any ideas.

                          I think you need to understand first that these are separate interfaces...(OPT1 / OPT2)
                          they do not depend on the LAN,...... just because it has Internet access by default (the LAN)

                          forget your "bridge" idea - you presented above

                          set each interface separately and give them a "default allow rule" as shown on the LAN
                          (copy is good ....because fast)

                          review the DHCP setting and cable connections...
                          say review the DHCP logs and connect your cable to the ports step by step

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          24 out of 24
                          • First post
                            24/24
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received