• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to get 2 separate networks to talk to each other?

Routing and Multi WAN
3
74
10.4k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    johnpoz LAYER 8 Global Moderator
    last edited by johnpoz Feb 25, 2020, 3:38 PM Feb 25, 2020, 3:32 PM

    Well there are no pings in there..

    So up the level of output so you can see the mac.. I think your mac is wrong to be honest. Since you set a static.

    And when you did the sniff you did it at the same time as you were pinging?

    Not seeing any response for dns in there either..

    An intelligent man is sometimes forced to be drunk to spend time with his fools
    If you get confused: Listen to the Music Play
    Please don't Chat/PM me for help, unless mod related
    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

    I 1 Reply Last reply Feb 25, 2020, 4:04 PM Reply Quote 0
    • I
      ilovechickennuggets @kiokoman
      last edited by ilovechickennuggets Feb 26, 2020, 11:36 PM Feb 25, 2020, 4:02 PM

      @kiokoman @johnpoz
      πŸ”’ Log in to view

      These are the current static mapping settings of the entry. The first shows pfsense. The second shows the MAC of the nas. So to make sure I was getting the right IP and MAC, I restarted my NAS. Somehow it gave me a new IP from dhcp. I did something wrong.

      P.S. kiokoman, thank you for your help too!

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Feb 25, 2020, 4:04 PM

        And can you ping this IP?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • I
          ilovechickennuggets @johnpoz
          last edited by Feb 25, 2020, 4:04 PM

          @johnpoz
          Yes the sniff happened at the same time as the ping.

          After I restarted my NAS just now, it gave me new IP of 192.168.70.10 - which is the start of my DHCP range.

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz Feb 25, 2020, 4:05 PM Feb 25, 2020, 4:04 PM

            and can you ping that?

            Can your nas ping pfsense 70.1 address?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            I 1 Reply Last reply Feb 25, 2020, 4:10 PM Reply Quote 0
            • I
              ilovechickennuggets @johnpoz
              last edited by Feb 25, 2020, 4:10 PM

              @johnpoz
              πŸ”’ Log in to view
              πŸ”’ Log in to view

              Packet capture is not picking up anything during the ping

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz Feb 25, 2020, 4:24 PM Feb 25, 2020, 4:18 PM

                Well then no nothing is going to work... Can the server ping pfsense IP? Does internet work? You have it directly plugged into an interface on pfsense - there are no switches.

                I am not sure that your doing the sniff correctly to be honest.. do a tcpdump on pfsense while you ping..

                Open up 2 ssh windows to pfsense and do it this way... start a tcpdump for icmp on the interface this server network is on..

                Then in the other windows ping... Then also ping from the server to 70.1 address while your sniff is running

                example
                πŸ”’ Log in to view

                This sever is physical right - its not some VM running on something?

                Lets try this - install the package arping... Lets try that..

                example
                πŸ”’ Log in to view

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                I 1 Reply Last reply Feb 25, 2020, 4:23 PM Reply Quote 0
                • K
                  kiokoman LAYER 8
                  last edited by Feb 25, 2020, 4:23 PM

                  now i'm curious to see where the hell we are hitting the head

                  ΜΏ' ΜΏ'\Μ΅Ν‡ΜΏΜΏ\Π·=(β—•_β—•)=Ξ΅/Μ΅Ν‡ΜΏΜΏ/'ΜΏ'ΜΏ ΜΏ
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the πŸ‘ button for any post you find to be helpful.

                  1 Reply Last reply Reply Quote 0
                  • I
                    ilovechickennuggets @johnpoz
                    last edited by Feb 25, 2020, 4:23 PM

                    @johnpoz @kiokoman
                    The server is a physical machine directly connected to pfsense interface with no switches in between this connection. Unfortunately, I am out of time for now and will come back to this later to try this.

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz Feb 25, 2020, 4:26 PM Feb 25, 2020, 4:24 PM

                      see my edit.. about using arping package as well.

                      Clearly you would use server as the interface and ip of your nas..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      I 1 Reply Last reply Feb 25, 2020, 10:03 PM Reply Quote 0
                      • I
                        ilovechickennuggets @johnpoz
                        last edited by Feb 25, 2020, 10:03 PM

                        @johnpoz @kiokoman
                        Ok I did a complete shut down and reboot. The NAS is now getting the correct static IP. In Pfsense, under Status/ DHCP Leases -showing as online
                        πŸ”’ Log in to view

                        I installed ARPing and ran it with following settings
                        πŸ”’ Log in to view
                        πŸ”’ Log in to view

                        As for SSH and tcpdump, I am going to need to educate myself on this because I'm treading onto something completely new to me. I'll be back try your advice after I go through some documentations and tutorials. I don't have SSH set up and it looks like I need to generate a key.

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz Feb 25, 2020, 10:21 PM Feb 25, 2020, 10:20 PM

                          so arping works, but normal ping does not?

                          That just SCREAMS, SCREAMS!!! firewall on that box!!!

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          I 1 Reply Last reply Feb 25, 2020, 10:22 PM Reply Quote 0
                          • I
                            ilovechickennuggets @johnpoz
                            last edited by Feb 25, 2020, 10:22 PM

                            @johnpoz
                            πŸ”’ Log in to view
                            Correct, this is the newest try at pinging.

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by Feb 25, 2020, 10:24 PM

                              Well your clearly arping for the IP.. Which comes back with mac correct, and you got your dhcpd address you reserved. So you seem to not being answering..

                              The odd thing is you didn't show any pings going out even when you tried to ping.. Which makes no sense - unless you didn't do the sniff right..

                              Again can the server ping pfsense IP? Sniff when your doing that test..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              I 1 Reply Last reply Feb 25, 2020, 10:38 PM Reply Quote 0
                              • I
                                ilovechickennuggets @johnpoz
                                last edited by Feb 25, 2020, 10:38 PM

                                @johnpoz
                                Sorry! Ran the sniff and ping from NAS server to 192.168.70.1 resulted in 100% packet loss.
                                πŸ”’ Log in to view
                                πŸ”’ Log in to view

                                1 Reply Last reply Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz Feb 25, 2020, 10:43 PM Feb 25, 2020, 10:41 PM

                                  Ok so your seeing traffic to pfsense interface on 192.168.70.1 - but no answers!

                                  That points to firewall on pfsense, but that shouldn't stop you from pinging from pfsense unless you have an outbound rule on your lan.. Do you have anything in floating?

                                  example

                                  πŸ”’ Log in to view

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  I 1 Reply Last reply Feb 25, 2020, 10:44 PM Reply Quote 0
                                  • I
                                    ilovechickennuggets @johnpoz
                                    last edited by Feb 25, 2020, 10:44 PM

                                    @johnpoz
                                    Current floating and LAN rules
                                    πŸ”’ Log in to view
                                    πŸ”’ Log in to view

                                    1 Reply Last reply Reply Quote 0
                                    • J
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by johnpoz Feb 25, 2020, 10:51 PM Feb 25, 2020, 10:46 PM

                                      Well what interfaces do you have all those rules on? Its quite possible your blocking something in all those rules...

                                      Disable them all for "testing"

                                      Your lan and server rules mean nothing for pinging from pfsense - the only thing that could cause what seeing would be a outbound rule on your server interface blocking pfsense from sending the ping even..

                                      What are you rules on your server interface?

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      I 1 Reply Last reply Feb 25, 2020, 10:56 PM Reply Quote 0
                                      • I
                                        ilovechickennuggets @johnpoz
                                        last edited by ilovechickennuggets Feb 29, 2020, 6:48 PM Feb 25, 2020, 10:56 PM

                                        @johnpoz
                                        So counting from top to bottom, the first 11 rules (pfB_Top_v4 to pfb_TOR_v4) - all 11 have the same setting with block to WAN interface only (only WAN is highlighted in interface box).
                                        πŸ”’ Log in to view

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by Feb 25, 2020, 11:01 PM

                                          Ok well your server interface rules would not allow ping.. So that explains why pfsense would not answer ping.

                                          Set a rule to allow ping to pfsense server address.
                                          And possible dns is not listening on on 70.1

                                          Set your ping rule, and try to ping from server again to 70.1

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                          I 1 Reply Last reply Feb 25, 2020, 11:07 PM Reply Quote 0
                                          39 out of 74
                                          • First post
                                            39/74
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.