Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Weird issue

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      deanot
      last edited by

      I have a 4 port network adapter, wan1, wan2, lan1 and lan2.  For some reason, wan2 which I just set up, has firewall rules for anti-lockout, I thought that should be on lan1.  I can't get rid of the rule and would like it back on lan1.

      Any idea how to fix this? I do not want to leave that rule on a wan for obvious reasons, port 80 and 22 are wide open to the world.

      PFSense System Specs.
      –---------------
      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
      4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

      1 Reply Last reply Reply Quote 0
      • S Offline
        Soyokaze
        last edited by

        I don't know by what logic they are assigned, but suppose this depends on (non)configured gateway for interface.
        Most simple solution would be to disable autocreation of these rules and define them by yourself.

        Need full pfSense in a cloud? PM for details!

        1 Reply Last reply Reply Quote 0
        • D Offline
          deanot
          last edited by

          I have no idea either, but upon creating the interface, it's name defaults to "lan".  No matter what adapter i assign to it… Very odd.

          PFSense System Specs.
          –---------------
          Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
          4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

          1 Reply Last reply Reply Quote 0
          • D Offline
            deanot
            last edited by

            I noticed there is an option to stop the lockout rule being assigned to the lan interface, but as you said, what defines the lan interface?

            PFSense System Specs.
            –---------------
            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

            1 Reply Last reply Reply Quote 0
            • C Offline
              cmb
              last edited by

              The ID of the second assigned interface is LAN, and that's where the anti-lockout rule goes. Disable the anti-lockout rule if your second assigned interface isn't actually LAN.

              1 Reply Last reply Reply Quote 0
              • D Offline
                deanot
                last edited by

                Interesting, is there no way to move this around between ports?  I mean, it's no big deal, I can just move the cables around and change the IPs of the ports.

                PFSense System Specs.
                –---------------
                Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

                1 Reply Last reply Reply Quote 0
                • S Offline
                  Soyokaze
                  last edited by

                  Just try to assign them in correct (from pfs POV) order from shell menu:
                  1st goes to WAN1, 2nd to LAN1, 3rd and 4th - doesn't matter.

                  Need full pfSense in a cloud? PM for details!

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    deanot
                    last edited by

                    Yeah, I was trying to keep my wans and lans together, can't do that.  I just turned off the lockout rules, changing the IPs is actually a pain in the butt, I was gonna set up an ip in the same range as one of my lans just so I could move the other ones around… can't do that either.

                    It's all good, works ok for me this way, if I get locked out I will just have to use the serial interface.

                    PFSense System Specs.
                    –---------------
                    Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                    4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Online
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      "Interesting, is there no way to move this around between ports?"

                      Huh??  Yes there is.. Just assign your interface to the mac you want.  You can do it via the console cli or even in the gui.. But if your doing it from the web gui your prob going to knock your self off..

                      You need to know the mac of what port you want to assign the interface too.  As you can see with mine the mac are made up since my pfsense virtual.  I did that on purpose so I know exactly which interface is which in my vm setup.

                      But its the same thing for a multiple port nic, each port on the nic will have its own mac, they normally increment by 1..

                      As to which port is which.. Normally going to go from 1 side or the other so like eth0 might be the top as you look at it or might be the bottom, but the port next to it should be eth1 and then eth2, etc..

                      assignports_.jpg_thumb
                      assignports_.jpg

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.