I have no internet access to sites other than Google & youtube through pfSense?
-
When disabling the Firewall, I also disable NAT, and I can't ping out no more, I can't watch videos on youtube or anything, basically no connection.
So my best bet is that its the firewall blocking connectionsI tried getting the logs you asked for, aswell as posting my Firewall rules and Nat setup, hopefully this helps.
I do see all the blocked connections, so I assume this is the problem, but I have no idea what is causing it.https://imgur.com/a/gr5CLUl
I can try a tracert, but I assume it works, since I can ping out from both hosts on lan and pfSense.
-
Maybe you have to set a rule to allow connections from your router to pfsense and from pfsense to PCs.
I have two: allowing everything on all ports to 192.168.1.3:80 (pfsense) and another rule saying the same, but to port 443. (I used easy rule)Try to tracert to sites that does not work to see
ifwhere the packages stops. -
I have 1 rule on WAN, and one one LAN that should allow everything
TraceRT don't seem to be a problem.
https://imgur.com/a/v1DUHc6 -
I'm sorry, but I'm out of ideas. :(
Let's wait for someone else. -
@pagger said in I have no internet access to sites other than Google & youtube through pfSense?:
I have 1 rule on WAN, and one one LAN that should allow everything
TraceRT don't seem to be a problem.
https://imgur.com/a/v1DUHc6Remove that WAN any/any rule. Go do that now.
From the nslookup output it seems you are not using pfsense for DNS. What does your DNS setup look like? -
@andyc My DNS setup is is: 2 Windows DC's with DNS, one at 10.1.0.20 and the next et 10.1.0.21.
Clients are set to use those and primary/sencondary DNS, and both of the servers have 10.0.0.1 (pfSense LAN IP) set as a forwarder.Do you want me to delete the file because it's bad practice, or because It's part of the problem?:p
-
@pagger because you’re using AD, your DNS is correct. Client machines use the AD DNS and that should forward to pfSense (so you can use things like pfBlockerNG).
-
The block rule shows that it was dropping traffic from 10.0.0.1 to 10.0.0.24.
What have you got in system>routing and what packages are you running?
-
@motific Under Gateway i have DHCP and It shows my WAN IP, nothing is set under static rouges og Gateway groups.
I got the following services running:
Dpinger
Ntpd
Syslogd
Unbound -
@pagger i disable my WAN ipv6 and everything is solved .