Can't ping or access router on OPT1 interface

  • I'm new to Pfsense and have basic knowledge of networking. My topology is as follows:
    WAN -> pfsense box
    3 NICs - WAN, LAN, OPT1

    LAN to switch -> Netgear Nighthawk R8500 in AP mode
    OPT1 Static -> LAN Port on Netgear WNDR3800 DHCP dissabled
    LAN on WNDR3800

    The problem I'm having is I can't access the GUI on the Netgear router, internally or remotely. I can ping from LAN but can't ping Netgear LAN192.168.4.2 or computer on LAN I have dynamic address through No-ip and have setup Rules and port forewarding the best I can. Please check out my screen shots and advise as to what changes i should make.


    ![Rules - LAN.png](/public/imported_attachments/1/Rules - LAN.png)
    ![Rules - LAN.png_thumb](/public/imported_attachments/1/Rules - LAN.png_thumb)
    ![Rules- OPT1.png](/public/imported_attachments/1/Rules- OPT1.png)
    ![Rules- OPT1.png_thumb](/public/imported_attachments/1/Rules- OPT1.png_thumb)
    ![Rules WAN.png](/public/imported_attachments/1/Rules WAN.png)
    ![Rules WAN.png_thumb](/public/imported_attachments/1/Rules WAN.png_thumb)

  • Your rules need some cleaning, when you're on the LAN tab, your source should almost always be LAN net (unless you're double NATting), it's only going to filter traffic coming "in" to the interface. That same rule goes for the OPT1 interface. Your rules, how they are, currently allow internal routing between LAN and OPT1, so don't change anything just yet.

    Now for your problem, you're unable to access the GUI on the Netgear at Is the computer at behind that Netgear router (OPT1 > LAN port on WNDR3800 > computer plugged into a separate LAN port on WNDR3800)?

    If so, pfSense wouldn't even be coming into play here. Troubleshooting internal access first would be smart before troubleshooting the remote access.

    Can the computer ping or access the Netgear GUI at Can anything on the 192.168.4.x subnet ping or access (GUI) that IP?

  • Thank you bjaffe for the input, yes the computer at is behind the WNDR3800 plugged into a separate LAN port. That computer can access the GUI and it's the only computer on the WNDR3800. I also have a Insteon hub connected.

  • Your router at can be accessed from inside the subnet, but not outside. Does it have a default gateway set? If it has the option, it needs to be set to (OPT1 address of pfSense). If not, the requests will make it to the router but it'll send the replies to a black hole.

  • is the default gateway setting on the WNDR3800? I have WAN\internet set to DHCP(wired) right now and there is no option for Gateway. If i set it to Static (Wired) I get the option for GATEWAY. that is the way I used to have it set but, decided to change it because OPT1 is set to static

  • LAYER 8 Netgate

    Consumer routers generally do not have the facility for a default gateway on the LAN side.

    You might be able to create a static route for with a destination of the firewall interface.

  • do I setup the static route on the Netgear router. If so, how?

  • LAYER 8 Netgate

    Don't know, man. This is not a netgear forum.

  • Derelict, Thank you for reply.
    I set it up like this: Destination- Interface-WAN Gateway- Is this correct?

  • LAYER 8 Netgate

    No. dest

    If probably does not support a default route - you're trying to use gear for something it is not designed to do - but it's worth a try.

  • LAYER 8 Global Moderator

    Your other option when dealing with a device that does not allow routes, default route/gateway on its interface is to source nat it..  So now your traffic coming from your lan, pfsense would nat that to look like it came from pfsense IP In opt network, just like when you nat to the public internet.  So in that case your netgear just sees someone talking to it from its own network..

    While this works, to be honest just get a real AP ;) hehe  Can you put 3rd party firmware on that wifi router.. Something like dd-wrt, openwrt, tomato all allow putting a default gateway on the lan interface so you can access the gui from another network.

  • The router is flashed with Gargoyle which I think is Openwrt. I did setup the static route on the netgear like derelict suggested but, that didn't help. I still can't access the router from LAN on 1.1 iP range. I would also like to access folders on the computer connected to the router.

    I'll try source nating. Can you provide a quick how-to?

    Thanks johnpoz

  • please check out the attached pics. is this where i setup routing and are those entries okay?

    ![gargoyle routing.png_thumb](/public/imported_attachments/1/gargoyle routing.png_thumb)
    ![gargoyle routing.png](/public/imported_attachments/1/gargoyle routing.png)
    ![gargoyle basic.png_thumb](/public/imported_attachments/1/gargoyle basic.png_thumb)
    ![gargoyle basic.png](/public/imported_attachments/1/gargoyle basic.png)

  • LAYER 8 Global Moderator

    your not using it as a gateway any more, change it to a wireless bridge/repeater mode - now it might allow you to set default route on your lan interface..

  • Banned

    Yes, that thing should be set up as a dumb bridge, certainly not router/gateway.

  • Ok, I set the router to wireless bridge/repeater and now  I can ping the bridge IP (, the Gateway IP (,
    and Insteon hub at all from the LAN but, i can't ping the computer. is this a pfsense issue or window/antivirus?

    Thank you all for the help.

  • LAYER 8 Global Moderator

    Out of box windows firewall will block pings from anything other its lock network u can change it to allow

  • Got it, Thanks. Am I bridging to the OPT1 ( interface? also is OPT1 handing out DHCP?

  • LAYER 8 Global Moderator

    Your running your wifi router as ap yes that is bride ypur opt1 could be dhcp unless u have other dhcp on that network typical would be dhcp on pfsense

  • you're right again, OPT1 is setup as DHCP server.

Log in to reply