Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (SOLVED) Unable to ping from outside to WAN port

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SipriusPTS
      SipriusPT
      last edited by

      Hello guys,

      I have not figure it out, why I am unable to ping from outside to pfsense wan port.

      This is my current setup:

      Huawei 3/4g wifi router (LAN IP: 196.23.85.173, DHCP: OFF):

      • PC A (IP: 196.23.85.175)
      • pfsense 2.3.3 router (WAN IP: 196.23.85.174, LAN IP: 192.168.1.1, LAN port DHCP: 192.168.1.10 to 192.168.1.254):
        – PC B (IP: 192.168.1.10)

      From PC A can ping to internet, Huawei router, but unable to ping to pfsense router.
      From PC B can ping to internet, Huawei router, PC A, and pfsense WAN port.

      After tried to connect PC A to pfsense router with OpenVPN, and there was no response I tried to ping to it, and notice that I was unable to do it. And yes I had a rule to OpenVPN (http://prntscr.com/ehsogn).

      And right now I dont know how to solve this =/

      1xSG-4860-1U
      1xSG-3100
      2xpfSense Virtual Machines

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        So your pcA is on the wan side of pfsense.. And on a rfc1918 address.. Even if you allow ping on the wan firewall rules?  Did you??  You would have to allow rfc1918 which would be blocked by default.

        As to why pc b can ping all of it - is its on the lan side, lan default rules are any any.. So your coming into the backdoor to ping the wan IP..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • SipriusPTS
          SipriusPT
          last edited by

          @johnpoz:

          So your pcA is on the wan side of pfsense.. And on a rfc1918 address.. Even if you allow ping on the wan firewall rules?  Did you??  You would have to allow rfc1918 which would be blocked by default.

          As to why pc b can ping all of it - is its on the lan side, lan default rules are any any.. So your coming into the backdoor to ping the wan IP..

          Thank you a lot John, it is true, by default I have (I totally forgot about it): http://prntscr.com/eht02i

          Next I have added a ICMP rule for it and it is working =): http://prntscr.com/eht82f

          1xSG-4860-1U
          1xSG-3100
          2xpfSense Virtual Machines

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.