Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Opt no internet access

    Firewalling
    4
    10
    185
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bihzs last edited by bihzs

      Hi,
      My opt interface can't access internet.
      I have enabled firewall rules same as LAN. But it still not working.

      Some suggestions, I have also tried bridge connection and still nothing happend.
      To mentioned I have external DHCP server that is manage connections.

      Gertjan 1 Reply Last reply Reply Quote 0
      • johnpoz
        johnpoz LAYER 8 Global Moderator last edited by johnpoz

        @unik-web said in Opt no internet access:

        To mentioned I have external DHCP server that is manage connections.

        So this dhcp server hands out what for the clients gateway that is on your opt network? What does it hand out for dns, etc.

        Why don't you actually post the rules you put on your opt.. See it all the time, users says they did rule(s) X, when really they did Y.. Like forgot to allow for UDP, or wrong source net, etc. etc. etc..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 23.01 | Lab VMs CE 2.6, 2.7

        B 1 Reply Last reply Reply Quote 0
        • B
          bihzs last edited by

          Hi,

          This is my DHCP configuration.

          DHCPConfig.jpg

          1 Reply Last reply Reply Quote 0
          • B
            bihzs @johnpoz last edited by

            @johnpoz of course sorry forget it sending it now.
            Screenshot from 2019-05-28 15-19-21.png

            Gertjan 1 Reply Last reply Reply Quote 0
            • Gertjan
              Gertjan @bihzs last edited by Gertjan

              @unik-web said in Opt no internet access:

              To mentioned I have external DHCP server that is manage connections.

              That's ok. I presume you want to say to us : "DHCP is up and running - my device hookup up to interface OPT1 got an IP - DNS and gateway which are all correct."
              pfSense can handle the DHCP - or you can choose any DHCP server.

              @unik-web said in Opt no internet access:

              I have enabled firewall rules same as LAN. But it still not working.

              Is there any reason for you to hide these rules ? Can't see how we can check them.
              edit : : Ok, I can see them now.

              Btw : "enabled firewall rules" ? I wonder how, as per default, there are no rules whatsoever on OPTx interface when you create them.
              You have to make at least one rule yourself, and this should be a pass all rule (accept any to any). Such a rule dosn't block anything. Very good for interface testing ^^. Afterwards you could narrow down, by adding more specific rules.

              No "help me" PM's please. Use the forum.

              1 Reply Last reply Reply Quote 0
              • Gertjan
                Gertjan @bihzs last edited by

                @unik-web said in Opt no internet access:

                @johnpoz of course sorry forget it sending it now.
                Screenshot from 2019-05-28 15-19-21.png

                Your third rule : Source = LAN Net ...... that can't work.
                Your OPT1 interface isn't LAN, thus it isn't a "LAN net" - you better document about these macros, what they stand for.
                Choose "OPT1 net" as a source.

                Btw : change also the Description : this isn't LAN, it is OPT1 - or whatever you call it - OPT can be renamed for your purposes.

                No "help me" PM's please. Use the forum.

                1 Reply Last reply Reply Quote 0
                • B
                  bihzs last edited by

                  ohh gush so stupidly I have changed it to the right config thanks a lot i was hoppely hope that i might fixing but it still have no internet access.

                  Screenshot from 2019-05-28 15-29-05.png

                  1 Reply Last reply Reply Quote 0
                  • F
                    fsr last edited by fsr

                    Why do you have rule that "Block private networks" in an adapter with a private network range 192.168.x.x?
                    You better disable that two block rules at the top. They only make sense on a WAN adapter.

                    Gertjan 1 Reply Last reply Reply Quote 0
                    • Gertjan
                      Gertjan @fsr last edited by Gertjan

                      @fsr said in Opt no internet access:

                      Why do you have rule that "Block private networks" in an adapter with a private network range 192.168.x.x?
                      You better disable that two block rules at the top. They only make sense on a WAN adapter.

                      ☺

                      4a38b1bb-e55c-4701-957b-f5bf3145d49b-image.png

                      I was betting on the fact that @unik-web would find that out himself ^^
                      He wants to block private networks == RFC 1918 ==
                      8b7e4dc2-6702-4955-afe0-a9f451839a8f-image.png

                      well, ... ok ...
                      I guess he understood by now that his first 2 firewall have no sense on an local interface like LAN or other LAN like OPTx.

                      No "help me" PM's please. Use the forum.

                      1 Reply Last reply Reply Quote 0
                      • B
                        bihzs last edited by

                        Hello,

                        Thanks for your help, I have removed them == RFC 1918 == after uploaded this image.

                        Overall I had found solution on my issue. Under my interfaces -> Opt1 configuration. I has changed under Static IPv4 Configuration ip xx.xxx.x.x / 32 to 24. Then it works perfect.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post