• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

(SOLVED) Unable to ping from outside to WAN port

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 4.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    SipriusPT
    last edited by Mar 9, 2017, 11:32 AM Mar 9, 2017, 10:45 AM

    Hello guys,

    I have not figure it out, why I am unable to ping from outside to pfsense wan port.

    This is my current setup:

    Huawei 3/4g wifi router (LAN IP: 196.23.85.173, DHCP: OFF):

    • PC A (IP: 196.23.85.175)
    • pfsense 2.3.3 router (WAN IP: 196.23.85.174, LAN IP: 192.168.1.1, LAN port DHCP: 192.168.1.10 to 192.168.1.254):
      – PC B (IP: 192.168.1.10)

    From PC A can ping to internet, Huawei router, but unable to ping to pfsense router.
    From PC B can ping to internet, Huawei router, PC A, and pfsense WAN port.

    After tried to connect PC A to pfsense router with OpenVPN, and there was no response I tried to ping to it, and notice that I was unable to do it. And yes I had a rule to OpenVPN (http://prntscr.com/ehsogn).

    And right now I dont know how to solve this =/

    1xSG-4860-1U
    1xSG-3100
    2xpfSense Virtual Machines

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Mar 9, 2017, 10:52 AM

      So your pcA is on the wan side of pfsense.. And on a rfc1918 address.. Even if you allow ping on the wan firewall rules?  Did you??  You would have to allow rfc1918 which would be blocked by default.

      As to why pc b can ping all of it - is its on the lan side, lan default rules are any any.. So your coming into the backdoor to ping the wan IP..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • S
        SipriusPT
        last edited by Mar 9, 2017, 11:31 AM

        @johnpoz:

        So your pcA is on the wan side of pfsense.. And on a rfc1918 address.. Even if you allow ping on the wan firewall rules?  Did you??  You would have to allow rfc1918 which would be blocked by default.

        As to why pc b can ping all of it - is its on the lan side, lan default rules are any any.. So your coming into the backdoor to ping the wan IP..

        Thank you a lot John, it is true, by default I have (I totally forgot about it): http://prntscr.com/eht02i

        Next I have added a ICMP rule for it and it is working =): http://prntscr.com/eht82f

        1xSG-4860-1U
        1xSG-3100
        2xpfSense Virtual Machines

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received