Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense box not allowing Internet on LAN side

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Beserker
      last edited by

      Hi Guys

      I am very new to Networking and PFSense, but I have followed all tutorials and guides possible and I still cant seem to get my PFSense box to work.
      The PFSense box itself has internet connectivity, it can check for updates, trace route and Ping external addresses, but when I try to access a web page from a PC connected on the LAN side, it wont says that it cant find the page.
      I am assuming that it has something to do with the NAT or DNS?

      I have also checked hardware checksum offloading, which got my gateway to become active, but has still not fixed my connectivity issues.
      Attached is a diagram of my network setup.

      Please let me know what you would need from my side to help diagnose this problem

      Thanks in advance for your help!

      Graph.png
      Graph.png_thumb

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        Hi,

        Try this one : https://doc.pfsense.org/index.php/Connectivity_Troubleshooting
        And, what about posting what is wrong ? This way we can answer you right away.

        On a PC :

        ipconfig /all
        
        ping 8.8.8.8
        
        ping google.com
        

        and do not forget to mention the pfSense LAN settings - anything you changed on LAN (DHCP server ..).

        Also : just in case : on the WAN interface : what is the IP ? and is "Block private networks and loopback addresses" checked, or not ?

        A router (pfSense) after a router after a router(?). Ok, why not. Love it already.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • B
          Beserker
          last edited by

          To help eliminate some of the obvious problems:

          WAN: 192.168.1.5/24 - no DHCP - Upstream Gateway: 192.168.1.1 (Router)
          LAN: 192.168.10.1/24 - DHCP enabled

          Firewall:

          WAN: Left as Default
          LAN: Allow all - Set to Pass - Port: Any

          Block private Networks from entering via WAN - Enabled
          Block Bogon Networks - Enabled

          Will try and post logs in a few hours when I get home

          1 Reply Last reply Reply Quote 0
          • B
            Beserker
            last edited by

            @Gertjan:

            Hi,

            A router (p

            Think you only posted half the reply :P

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan
              last edited by

              See above, I edited my post (my train went in a tunnel …)

              @Beserker:

              …
              Block private Networks from entering via WAN - Enabled
              ....

              Perfect.

              So you have this IP "RFC 1918 (10/8, 172.16/12, 192.168/16)" on your WAN and Block private Networks from entering via WAN set.
              Using other words : your WAN IP will be blocked.

              => Undo the check ;)

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • B
                Beserker
                last edited by

                Thanks for the help so far @Gertjan

                Followed the troubleshooter and I am still having trouble. I figured the easiest way for me to get all the info on my Firewall across is to make a video going through all the settings. Had to wait a little for my public IP to change before posting. If you dont mind watching a little and letting me know if you see anything out of place.

                Thanks again

                General Settings: https://youtu.be/EuZTMaYkBAU

                Firewall Log: https://youtu.be/MMoOl8TNshM

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad
                  last edited by

                  My guess would be the Mikrotik needs a static route for your pfSense LAN subnet pointing to the pfSense WAN IP address.

                  Get rid of the Mikrotik, you'll have a double NAT going on.

                  PS the videos don't play.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  1 Reply Last reply Reply Quote 0
                  • B
                    Beserker
                    last edited by

                    Sorry let me change them from Private to Unlisted.
                    I'll look into that though, thanks a lot!

                    1 Reply Last reply Reply Quote 0
                    • B
                      Beserker
                      last edited by

                      So I spoke to my ISP, since I have no idea how to setup static routes in the mikrotik, and they recommended turning off NAT on the PFSense Box, since I still have phones and tablets connect to the mikrotik via wifi.

                      Would turning off NAT on the PFSense box fix this problem?

                      1 Reply Last reply Reply Quote 0
                      • B
                        Beserker
                        last edited by

                        We've tried adding static routes from both the Router and from the Pfsense box, and neither seem to work. Still completely stumped on this. If anyone has any idea of what I could do next it would be greatly appreciated.

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          cyberzeus @Beserker
                          last edited by

                          @beserker Is this still not working?

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            You are running 32bit and not even the latest 32bit version. That CPU can run 2.4.3_1 so you should be on that really.

                            You have no DNS resolution at the client. Is Unbound even running? Check Status > Services. Try Diag > DNS lookup which should try pfSenses own DNS servers.

                            You can ping 192.168.10.1 from the client but can you ping 192.168.1.20 or 192.168.1.1?

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.