Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG3100 Single WAN NAT Issues.

    Scheduled Pinned Locked Moved Firewalling
    55 Posts 2 Posters 9.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wc2l @mcury
      last edited by

      @mcury OK well interestingly, the Guest WiFi may have stopped working. I need to figure out what caused it..

      I can go back and uncheck it.. I will set the host over-ride. I'm a newbie and learning slowly.. If there was a way we could do this together would save some time ;-)

      M 1 Reply Last reply Reply Quote 0
      • M
        mcury Rebel Alliance @wc2l
        last edited by

        @wc2l said in SG3100 Single WAN NAT Issues.:

        @mcury OK well interestingly, the Guest WiFi may have stopped working. I need to figure out what caused it..

        I can go back and uncheck it.. I will set the host over-ride. I'm a newbie and learning slowly.. If there was a way we could do this together would save some time ;-)

        Sure, I like to help.. why not? Also, my life has been destroyed by this pandemic, so I'm the one who is being helped by you.

        What are your doubts?

        dead on arrival, nowhere to be found.

        W 1 Reply Last reply Reply Quote 0
        • W
          wc2l @mcury
          last edited by

          @mcury lack of my skills.. This is a new world to me ;-)

          OK, It appears that the guest WiFi VLAN has stopped working. My LAN WiFi is working. I didn't think that anything I did would have affected the Guest WiFi (using my phone as a test unit).

          Not going to last too much tonight. I'm early riser. If you want, you can always email WC2L at YCCC dot ORG. I'm guessing most of this a couple of check marks somewhere. Will

          W 1 Reply Last reply Reply Quote 1
          • W
            wc2l @wc2l
            last edited by

            @mcury Since we setup the split DNS, is there something I need to do to get the guest WiFi to work again?? I can't seem to get to the Internet, ddns.example.com or pretty much anything.. It is handing out DHCP from the SG3100. I'm guessing it is a routing issue. Just don't know how to address it.

            M 1 Reply Last reply Reply Quote 0
            • M
              mcury Rebel Alliance @wc2l
              last edited by

              Show some screenshots of your config.

              And no, split DNS wouldn't cause internet outage.

              dead on arrival, nowhere to be found.

              W 1 Reply Last reply Reply Quote 0
              • W
                wc2l @mcury
                last edited by

                @mcury
                Not sure what screens you want to see.

                1f682900-bd92-47d1-ab4e-9d8e4dc81dcf-image.png
                f4552c45-b7ee-4fdc-b950-1136141c6705-image.png
                898f27c6-a889-47ee-8bea-dc4801f1ab6d-image.png

                M 1 Reply Last reply Reply Quote 0
                • M
                  mcury Rebel Alliance @wc2l
                  last edited by

                  @wc2l Can users in this guest WiFi ping 8.8.8.8?

                  dead on arrival, nowhere to be found.

                  W 1 Reply Last reply Reply Quote 0
                  • W
                    wc2l @mcury
                    last edited by

                    @mcury NOPE 👎

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mcury Rebel Alliance @wc2l
                      last edited by

                      @wc2l Are these users getting IP address from the DHCP?

                      dead on arrival, nowhere to be found.

                      W 1 Reply Last reply Reply Quote 0
                      • W
                        wc2l @mcury
                        last edited by

                        @mcury Yes.. I just connected a Surface to the Guest WiFi..
                        It got the expected IP address

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          mcury Rebel Alliance @wc2l
                          last edited by

                          @wc2l Ok, it was working before? Problem started with the host override inside DNS Resolver?
                          Try to remove the host override and try again.

                          dead on arrival, nowhere to be found.

                          W 1 Reply Last reply Reply Quote 0
                          • W
                            wc2l @mcury
                            last edited by wc2l

                            @mcury no change
                            Both ways shows that DNS servers are not responding
                            DNS_PROBE_FINISHED_NO_INTERNET

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              mcury Rebel Alliance @wc2l
                              last edited by

                              @wc2l Ok, what DNS server are these users using?
                              Are your firewall rules allowing connections to this DNS server on port 53 UDP/TCP?

                              dead on arrival, nowhere to be found.

                              W 1 Reply Last reply Reply Quote 0
                              • W
                                wc2l @mcury
                                last edited by

                                @mcury
                                7b380704-ff7a-4429-abb2-447992e18185-image.png

                                78a8c873-a644-431f-803a-4de953c0053b-image.png

                                ac26a3da-1ee7-4b2f-a2ed-ed2be0939ea2-image.png

                                M 1 Reply Last reply Reply Quote 0
                                • M
                                  mcury Rebel Alliance @wc2l
                                  last edited by

                                  @wc2l You need firewall rules inside this last image, WC2LWIFIGUEST
                                  You need to allow the GUEST network to go out to the internet.

                                  Do you see the difference between LAN and WC2LWIfIGUEST?

                                  The last two rules in LAN, try to create them inside WC2LWIfIGUEST, this will allow internet access for these guests.

                                  dead on arrival, nowhere to be found.

                                  W 1 Reply Last reply Reply Quote 0
                                  • W
                                    wc2l @mcury
                                    last edited by

                                    @mcury Protocol - Any, Source - Any, Destination Any?
                                    I remember something that I saw online. I will have to see if I can find it

                                    M 1 Reply Last reply Reply Quote 0
                                    • M
                                      mcury Rebel Alliance @wc2l
                                      last edited by

                                      @wc2l It's easy to create a firewall rule.

                                      Protocol: any
                                      Source: WC2LWIfIGUEST_NET
                                      source port: *
                                      destination: *
                                      port: *

                                      Exactly as it is inside LAN, you replicate that but now for WC2LWIfIGUEST

                                      dead on arrival, nowhere to be found.

                                      W 1 Reply Last reply Reply Quote 0
                                      • W
                                        wc2l @mcury
                                        last edited by

                                        @mcury
                                        That was it!! I can get out to the internet.. I can't get to ddns.example.com, but I'm not sure I truly care.. more of a way for me to test some stuff.

                                        M 1 Reply Last reply Reply Quote 0
                                        • M
                                          mcury Rebel Alliance @wc2l
                                          last edited by

                                          @wc2l Ok, to users in the WC2LWIfIGUEST to be able to access ddns.example.com
                                          You will need the host override in place, and confirm that the users inside WC2LWIfIGUEST are using the pfsense DNS and not other DNS server.

                                          dead on arrival, nowhere to be found.

                                          W 1 Reply Last reply Reply Quote 0
                                          • W
                                            wc2l @mcury
                                            last edited by

                                            @mcury I had already placed the Host override in place.
                                            When I check the ipconfig of the device it is 172.30.32.1

                                            M 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.