Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't route between subnets?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    6 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jamet
      last edited by

      pfSense 2.3.2
      WAN:  not connected
      LAGG interface >
      VLAN 10: 192.168.10.0/24
      VLAN 20: 192.168.20.0/24
      DHCP Scope for both vlans run by pfSense
      Firewall rule for both vlans is any source, any protocal allowed to any destination, any protocal

      connected to Cisco SG300-20
      LAGG interface - connection successful
      LAGG interface - trunk mode VLAN 1, VLAN 10, VLAN 20
      port 1 access Vlan 10
      port 2 access Vlan 20
      management interface 192.168.10.2

      Two laptops each connected to a port
      Laptop 1 - DHCP -192.168.10.100/24
      Can ping both gateways 192.168.10.1 & 192.168.20.1
      Can access pfSence webgui on both interfaces 192.168.10.1 & 192.168.20.1
      Can access cisco switch on management interface 192.168.10.2
      Cannot ping other laptop 192.168.20.100

      Laptop 2 - DHCP -192.168.20.100/24
      Can ping both gateways 192.168.10.1 & 192.168.20.1
      Can access pfSence webgui on both interfaces 192.168.10.1 & 192.168.20.1
      Can not access cisco switch on management interface 192.168.10.2
      Cannot ping other laptop 192.168.10.100

      Where to go from here?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Local "software/windows" firewalls on the laptops?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • J
          jamet
          last edited by

          No firewall software and windows firewall is disabled.

          1 Reply Last reply Reply Quote 0
          • J
            jamet
            last edited by

            Okay so after playing around awhile, I am now able to get both laptops to ping each other.  Still can not ping or access management interface on cisco switch from laptop 2 on vlan20.  Everything works correctly from laptop 1 on vlan10.  tracert shows request go to gateway of vlan20 and then dies.  Logs don't show anything.  I have not been able to find anything in cisco docs that says that request must come from same subnet.  I thought that was the purpose of a management vlan.  To put all my switch and ilo access on that vlan  Then restrict that vlan to only allow access from certain IPs.  really stumped or I am misunderstanding cisco's management vlan concept.

            1 Reply Last reply Reply Quote 0
            • J
              jamet
              last edited by

              Being new to pfSense, I am sure I am overlooking something but here is a gotcha that I don't understand out of the box.

              I had assigned a static IP to my switch 192.168.10.2 on Vlan10(management)  anything from vlan20 that attempted to find it failed.  Pings, tracert, even packet sniffing.  Thought maybe that it was something that cisco was doing as I am still learning the whole VLAN setup procedures.  But it does not appear to be cisco but something that pfSense is controlling.  I enabled the management interface to get its IP from the DHCP service on vlan10 and viola.  I have access.  So why cant pfSense deal with static IPs.  This software is so highly configurable, I am sure that I just need to turn something on.  And I could use DHCP static leases, but I would like to understand this gotcha if someone might be able to explain?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                pfSense deals with static IP addresses just fine.

                Maybe you did not properly program a default gateway on your switch?

                A switch in layer 2 mode is usually managed by the address on its management VLAN. Set its default gateway to the pfSense interface address on the same VLAN.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.