Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allow all trafic from a vlan problem.

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 623 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bolvar
      last edited by

      Hy

      Im a little bit confused about my problem.
      I have a mobile vlan for the smartphones and i want to enable all trafic from it to the internet, but i get blocked when a program tries to use random port every time not mather how i add the rule to the fw to enable the outgoing trafic.
      Im running on HA cfg, i dont know it is need to be set up a plus nat from this vlan.

      Thanks for the help!

      bolvar

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        Your going to have to show us the rules your putting on the vlan.. And yeah if you dicked with outbound nat and changed it from auto, you would have to make sure your new vlan is being correctly natted outbound if you want internet.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          bolvar @johnpoz
          last edited by

          @johnpoz

          I have a lot of rule and it hase internet on it, just a few app fail to connect what uses random port.
          And if i set up to source my mobile wifi destination everything on my wan gw the apps didnt work, if i change to default gw it wokres but then i can reach thing on my lan what is not so good.
          I have hybrid nat ticked in.
          pfsense_mobilevlan.jpg

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            @bolvar said in Allow all trafic from a vlan problem.:

            if i change to default gw it wokres but then i can reach thing on my lan

            Well you put a rule above that rule that blocks where you don't want clients to go..

            All of those allow rules are pretty pointless.. Why do you think you need a an allow rule to Wan Net? for your vpn?

            Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated.

            Chromecast is multicast - not sure how you think that Google_Chromecast is going to work.. The chromecast needs to be on the same L2 as the clients.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            B 1 Reply Last reply Reply Quote 0
            • B Offline
              bolvar @johnpoz
              last edited by bolvar

              @johnpoz

              Thats a funny thing when someone tries to connect from the mobile phone via vpn it not worked.I put this rule in and voálá worked.
              Half of the rule is for testing, aka chromecast to. But avahi is helping about this problem.
              In mikrotik this was az easy setup i didnt need to setup a lot of deny rule to my other vlan-s.But if there is no other way i will do.

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                You don't need to setup a lot of deny rules... It can be done with 1..

                Are you trying to connect from your mobile phone to your vpn from your own internal wifi network? For why? Is your own internal network hostile?? Mobile phone on their cell network sure ok - that rule would be on your wan not your lan..

                Not sure where there is to play with with chromecast - its L2, its not going to talk to pfsense in anyway at all.. Clicking and making rules without any idea of how they work isn't going to get you anywhere! ;)

                The raktar_kaputelefon to Mobilevoipclients - not sure what that is suppose to do? The only source on your mobile wifi could be IPs on your mobilewifi, and then I assume mobile voip clients are also on this mobile wifi network - traffic between devices on the same network, ie mobile wifi would not even touch pfsense - so how would that rule come into play?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.