Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense block ICMP echo reply from WAN to OPT1

    Scheduled Pinned Locked Moved Firewalling
    25 Posts 4 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      well if you want to access from rfc1918 to networks behind pfsense via your going to have to remove that rfc1918 block for starters.

      If you want to use pfsense as a downstream network from your cisco then there should be a transit network and nat should only happen then talking to the internet and your cisco should nat all your downstream networks, etc.

      Or you should just double nat everything behind pfsense, etc.

      Why are you using vlan 10? Are you setting the vlans up in pfsense - what does your vswitch/port group do with the vlan(s) what do you have set on this port group, etc. etc..

      But you do NOT put the same network on multiple interfaces... And if your wanting to nat from rfc1918 to rfc1918 you going to have to remove that rfc1918 block.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • T
        tmedtcom
        last edited by

        0_1543329526320_VM Network.PNG

        0_1543329539231_VLAN10.PNG

        1 Reply Last reply Reply Quote 0
        • T
          tmedtcom
          last edited by

          I tried to disable the blocking of rfc1918 but here is the error message:
          0_1543330335881_rfc.PNG
          0_1543330346338_rfc error.PNG

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Dude why do you have so many physical interfaces?

            And you firewall 2 with how many interfaces? All in the same network?

            Then you have all of those same interfaces in firewall 2 also in vlan port group..

            Yeah that screams a MESS!!

            And yeah told you pfsense shouldn't even let you put overlapping networks on multiple interfaces!!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • R
              Rupesh
              last edited by

              I guess you already have a working LAN adapter on pfsense and OPT1 is your additional lan network.
              if that is the case then please create a new firewall rule to allow packets to pass(which you told you created already) and then in your newly created firewall rule , try changing/selecting the protocols which should be set as any by default).

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.