SG-1100 vlan help, firewall rules to ping between vlan
-
Hi
Im new to pfsense and is now playing with a netgate sg-1100 with an unifi nanohd ap connected to the LAN port.
I have setup 2 vlan, Guest and IOT. (vlan id 50 and 60)
There is internet and ip on LAN, vlan IOT and vlan Guest, all this fare is ok and working, i did follow some of the youtube guides from Tom from lawrence systems on the sg-1100 and pfsense to to this.
But here is the problem, i can not get any firewall rules i try to work on the topic of ping between:
lan <--> vlan
or
vlan <--> vlanI have seached alot and cant get it to work, any tips or help would be greatly appreciated, thanks ;)
-
That should only be a matter of having rules to allow it as long as devices in those subnets can respond to ping from a different subnet.
If you are policy routing you would need specific rules above that to pass it.
Can we see a screenshot on your rules on one of the interfaces that is not working?
Steve
-
Hi, and thank you for your help, your answer got me thinking, and i found that in windows 10 i have to not only enable the windows firewall to echo ICMP ping, but also enable it to echo ping from other subnets to get this to work.
And now i think it all works, thank you.
This is my rules, i can now ping from LAN to both GUEST and IOT, but GUEST and IOT cant ping to LAN.
-
Ok so what's in the 'SecureLANs' alias?
Your rule on IOT only allows traffic to destinations that are not in that alias so if it contains the LAN subnet you will not be able to connect.
You probably need an additional rule to pass only icmp traffic from IOTnet to wherever you need it.Steve
-
Hi
In the SecureLANs alias there is the LAN and i have added a rule like that for the GUEST network also now.I have also the Avahi mDNS service running.
I was under the impression that the devices on the LAN can see and start the connection into the IOT-network and also with the avahi mdns running that things like chromecast could work from IOT-network?
Im new to this so there could be something i have missed?
-
That is correct, LAN will be able to ping IOT. IOT will not be able to create connection to ping LAN though which is what you asked about.
Steve