Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SOLVED - Joining 2 separate networks with 2 pfSense boxes

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 7 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elliotcater
      last edited by

      Hi, I'm just about to attempt to join 2 self contained networks, already using pfSense as routers using the OPT1 interfaces on each respective router.  Could someone just take a glance at this and tell me if the PC's on the 2 LANs will be able to ping each other?

      Many thanks!

      edit 01/Jan/18 - image host ditched - see further down thread for re-drawn topology…


      Just checked and this works...

      1 Reply Last reply Reply Quote 0
      • P
        Paint
        last edited by

        @elliotcater:

        Hi, I'm just about to attempt to join 2 self contained networks, already using pfSense as routers using the OPT1 interfaces on each respective router.  Could someone just take a glance at this and tell me if the PC's on the 2 LANs will be able to ping each other?

        Many thanks!


        Just checked and this works…

        Yes, this setup will work if you allow subnet 10.0.2.2/24 to talk to subnet 10.0.2.1/24 via firewall rules.

        pfSense i5-4590
        940/880 mbit Fiber Internet from FiOS
        BROCADE ICX6450 48Port L3-Managed Switch w/4x 10GB ports
        Netgear R8000 AP (DD-WRT)

        1 Reply Last reply Reply Quote 0
        • D
          dalygrey
          last edited by

          I just set up this example in a lab and have been unsuccessful in pinging from lan to lan.  Although my testing has  been trying to ping the lan interface ip on the other side.  Tomorrow I'll get some more computers and hook those up.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            if you can not ping the lan inerface on the other one then pinging pc sure and the hell not going to work.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • I
              ivers
              last edited by

              Just for the record as this is a good match from search engines - after adding static routes between the pfsense boxes, to so System -> Advanced, up top select Firewall & NAT and check the box Static route filtering - Bypass firewall rules for traffic on the same interface.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Huh?  No that is NOT a good match for search engines… Are you the OP and forgot your login so created another account?

                You would not set that sort of setting unless you were hairpin in out an interface and running  - BORKED setup out of the gate, etc. You would never need to do such a setting create a transit network between to pfsense boxes.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • E
                  elliotcater
                  last edited by

                  Image host died so redrawn from memory, hope it's right!

                  You have to add the static routes on both boxes.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Exactly… Zero to do with ivers statement that you would have to bypass firewall rules on the same interface..  Thanks for the update to your drawing... That is good addition to the thread for any that might find this..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • E
                      elliotcater
                      last edited by

                      Yeah, I wasn't quite sure what Ivers is on about with the bypass rules etc…

                      I understand that Ivers might think the title of the thread (which I assume is indexed) could be good SEO as it is fairly succinct (if I do say so myself! ;)).

                      So is the transit network (the 10.0.2.0/24 subnet) with static routes on either box the correct what to go?

                      I did have it set up and working ok but my topology is now different so can't test.

                      It would be cool, in the event of a downed default gateway; to be able to use the default gateway on router a, from router b's lan (10.0.1.0/24). And vice versa, use the default gateway on router b from router a's lan (10.0.0.0/24).

                      I did try this but never quite managed it.

                      I 1 Reply Last reply Reply Quote 0
                      • I
                        itsystemsllc @elliotcater
                        last edited by

                        @elliotcater I know this is quite old but I want to do the exact same thing. My issue is that I'm not getting the route right. The post is missing the configuration you used for successful routing between the devices! Can you update with that info by any chance?

                        keyserK 2 Replies Last reply Reply Quote 0
                        • keyserK
                          keyser Rebel Alliance @itsystemsllc
                          last edited by keyser

                          @itsystemsllc On router A:

                          • Create a Gateway Called “Router B” with address 10.0.2.2
                          • Create a static route for 10.0.1.0/24 using “Router B” as gateway

                          On Router B:

                          • Create a Gateway Called “Router A” with address 10.0.2.1
                          • Create a static route for 10.0.0.0/24 using “Router A” as gateway

                          EDITED for the Typo pointed out by itsystemslic :-)

                          Love the no fuss of using the official appliances :-)

                          1 Reply Last reply Reply Quote 0
                          • keyserK
                            keyser Rebel Alliance @itsystemsllc
                            last edited by keyser

                            @itsystemsllc And remember - you need firewall rules on LAN interfaces (router A/B) for clients to reach out for the remote network - AND:
                            You also need firewall rules on OPT1 (Router A/B), to allow clients from remote networks to reach the local LAN network.

                            Love the no fuss of using the official appliances :-)

                            I 1 Reply Last reply Reply Quote 1
                            • I
                              itsystemsllc @keyser
                              last edited by

                              @keyser Excellent! Thank you for that routing info, works now. I changed a line though, as I think you have a typo...

                              On Router B:
                              Create a Gateway Called “Router A” with address 10.0.2.1
                              Create a static route for 10.0.0.0/24 using “Router B” as gateway
                              Create a static route for 10.0.0.0/24 using "Router A" as gateway

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.