Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    LAN <> OPT1 no access with allow *

    Scheduled Pinned Locked Moved Firewalling
    15 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      snoopy-de
      last edited by

      Dear all,

      I have a strange problem on a pfSense (virtual) 2.2.6. We have LAN (Server), OPT1 (going to a router with a leased line to another location) and WAN uplink. If a user is connected via ipsec, he can reach the systems behind OPT1, if I come from LAN, I can't. All rules on LAN and OPT1 allow anything. If I disable pf, I can access the systems behind OPT1 from LAN. Traceroute stops at the system in OPT1 and FROM OPT1, I can access a server in LAN (layout attached).

      Any ideas?

      Cheers,
      Snoopy
      pfsense.png
      pfsense.png_thumb

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        What's in the firewall logs?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S Offline
          snoopy-de
          last edited by

          hi!

          I just see

          The rule that triggered this action is:

          @9(1000000103) block drop in log inet all label "Default deny rule IPv4"

          But it looks like this is not rule blocking the traffic. If I check the log I can't find anything regarding source / destination IP.

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Well, something is blocking it. Post your LAN rules.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • S Offline
              snoopy-de
              last edited by

              hi,

              attached

              lanrules.PNG
              lanrules.PNG_thumb

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Nothing there blocking. Any floating rules?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • S Offline
                  snoopy-de
                  last edited by

                  no, no floating rules.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    From 10.0.100.0/24 can you:

                    Ping

                    10.0.80.254 ?

                    10.0.80.253 ?

                    10.0.50.1 ?

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      snoopy-de
                      last edited by

                      yes, all of them.

                      I also can ping from 10.0.100.10 e.g. 10.0.50.2 if I start a ping FROM 10.0.50.2 TO 10.0.100.10.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        I don't understand that last sentence.

                        Not sure. Seems like it should be working. If traffic's being blocked by the firewall it should be in the logs.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          snoopy-de
                          last edited by

                          hi!

                          I ping from 10.0.100.10 to 10.0.50.2 and I get a timeout. If I now start to ping from 10.0.50.2 to 10.0.100.10, I got a reply from 10.0.100.10 and I can ping from 10.0.100.10 to 10.0.50.2.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Online
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Think we are missing part of the story here..  10.0.80/24 seems like a large transit network to me..  Is there devices on this network?  Clearly your router to your other location is downstream router from pfsense.

                            What are the routes on pfsense to get to this other network?  What are the routes in the other routers?  What is the transit network used over you lease line?  There is no other routers in location B?  It has no internet connections just this point to point to your main location?

                            You say unless you ping from location B to your lan box first you get a timeout from lan to location B.. But if you ping first from location B to your lan box, you can then ping??

                            So traceroute from lan to your location B where does it die?  Sniff along the path, where are the packets being dropped or blocked?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.11.1 | Lab VMs 2.8.1, 25.11.1

                            1 Reply Last reply Reply Quote 0
                            • S Offline
                              snoopy-de
                              last edited by

                              hi,

                              sorry for my late reply:

                              10.0.50.0/24 has a route for 10.0.100.0/24 and 10.0.5.0/24 via 10.0.50.1 and puts this to 10.0.80.253. 10.0.80.253 has a route for 10.0.100.0/24 and 10.0.5.0/24 to 10.0.80.253 (pfsense).

                              But: If I disable pf (pfctl -d), I can reach everything, so it's not a routing issue. If I do a traceroute from 10.0.100.x to 10.0.50.x it stops one before 10.0.50.x

                              Cheers

                              1 Reply Last reply Reply Quote 0
                              • M Offline
                                muswellhillbilly
                                last edited by

                                Post a screen dump of the static routes on your PFS (System/Routing and choose the Routes tab). A screen grab of your firewall rules for OPT1 might also be helpful.

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ Online
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  "But: If I disable pf (pfctl -d), I can reach everything"

                                  You also say you can reach if you ping from the other side first.. So again missing part of the story here..  Prob have some sort of asymmetrical routing issue maybe?

                                  Again /24 is a freaking HUGE transit.. So you have no hosts on this network??  Or are you trying reach this other network from a host on your transit?

                                  Post up a simple traceroutes, your route table and your firewall rules or we are just going to be guessing without knowing the full picture.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 25.11.1 | Lab VMs 2.8.1, 25.11.1

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.