• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can't obtain external IP on WAN interface

Scheduled Pinned Locked Moved General pfSense Questions
13 Posts 3 Posters 10.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dreadh3ad
    last edited by Nov 13, 2016, 6:29 PM

    Hey Everyone,

    The WAN interface on my pfsense box is not able to receive an external IP address via DHCP with my Verizon Fios router in bridge mode. Was hoping somebody could point me in the right direction. I have a Verizon M1424WR V2 router and a dedicated box with pfsense installed.  The topology looks like this:

    Coax –-- Verizon Router ---cat7--- pfsense

    When the router is not in bridged mode, the pfsense WAN interface is able to obtain an internal IP address and can ping external addresses.

    I used this tutorial to set the router in bridged mode:    http://www.hanselman.com/blog/SimplifyingYourNetworkWithABridgeMakingAnFIOsActionTecMI424WRANetworkBridge.aspx

    Here are screenshots of the pfsense interface configuration and Verizon settings.

    I’m not sure where to go from here.  Any suggestions?

    Interface Status: http://imgur.com/I9yZLVA
    WAN Interface settings:  http://imgur.com/Pxzp6oh
    LAN Interface settings: http://imgur.com/YT6WNRk
    Verizon router settings:
    http://imgur.com/gh8C3B8
    http://imgur.com/rjQHorG
    http://imgur.com/cA2p5YF

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by Nov 13, 2016, 6:41 PM

      Might need to either clone the MAC address from the Verizon router or call them and have them free it up or do whatever else it is that they do.

      My preference would be to actually fix the problem by calling the ISP and having them do whatever they need to do since the other interface with that MAC address is physically still on the network.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • D
        dreadh3ad
        last edited by Nov 13, 2016, 6:56 PM

        What exactly do they need to do?

        1 Reply Last reply Reply Quote 0
        • D
          Derelict LAYER 8 Netgate
          last edited by Nov 13, 2016, 8:29 PM

          Better question for them. They should know everything about what they are providing. Explain to them exactly what you want to do.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • D
            dreadh3ad
            last edited by Nov 13, 2016, 8:31 PM

            They won't provide or validate instructions.  Third party routers are not supported.

            1 Reply Last reply Reply Quote 0
            • D
              Derelict LAYER 8 Netgate
              last edited by Nov 13, 2016, 8:41 PM

              Nice.

              Guess that's money well spent.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • D
                dreadh3ad
                last edited by Nov 13, 2016, 8:45 PM

                i may have to pay to have them run ethernet instead of coax.  :(

                I have a feeling its the router config that's fucked up and not the coax connection.

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by Nov 13, 2016, 8:48 PM

                  About all I can suggest trying is putting 00:26:b8:16:c0:12 in the MAC Address on Interfaces > WAN and seeing what happens.

                  ISPs really do suck.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • D
                    dreadh3ad
                    last edited by Nov 13, 2016, 8:52 PM

                    I'll give that a shot.

                    Where can I find the DHCP logs for the WAN port and how can I force a release/renew?

                    1 Reply Last reply Reply Quote 0
                    • D
                      Derelict LAYER 8 Netgate
                      last edited by Nov 13, 2016, 8:57 PM

                      The regular dhcp logs.

                      Status > Interfaces

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • N
                        NOYB
                        last edited by Nov 13, 2016, 10:32 PM Nov 13, 2016, 10:28 PM

                        There are some threads here re: Verizon DHCP, router impersonation, etc.  In the past they even required certain DHCP options be included in the request.  Try search.

                        Oh, and the Verizon DHCP lease is probably 2 hours, if you want to wait it out to get released.

                        1 Reply Last reply Reply Quote 0
                        • D
                          dreadh3ad
                          last edited by Nov 13, 2016, 11:58 PM

                          I gave the WAN interface the same MAC address as the router.  Still no luck.

                          Looking at the DHCP logs it looks like the WAN interface is getting a DHCP lease?  Am I reading this wrong?  I also saw the WAN lease in the pfsense DHCP leases page.  What is going on here?

                          [dhcp logs.txt](/public/imported_attachments/1/dhcp logs.txt)

                          1 Reply Last reply Reply Quote 0
                          • D
                            Derelict LAYER 8 Netgate
                            last edited by Nov 14, 2016, 1:18 AM

                            No it's not getting responses to DHCPREQUESTs or DHCPDISCOVERs so it used what it had cached from the last time it got 192.168.0.28 from somewhere.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            6 out of 13
                            • First post
                              6/13
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received