• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to get 2 separate networks to talk to each other?

Routing and Multi WAN
3
74
10.3k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    ilovechickennuggets @johnpoz
    last edited by Feb 25, 2020, 10:03 PM

    @johnpoz @kiokoman
    Ok I did a complete shut down and reboot. The NAS is now getting the correct static IP. In Pfsense, under Status/ DHCP Leases -showing as online
    🔒 Log in to view

    I installed ARPing and ran it with following settings
    🔒 Log in to view
    🔒 Log in to view

    As for SSH and tcpdump, I am going to need to educate myself on this because I'm treading onto something completely new to me. I'll be back try your advice after I go through some documentations and tutorials. I don't have SSH set up and it looks like I need to generate a key.

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz Feb 25, 2020, 10:21 PM Feb 25, 2020, 10:20 PM

      so arping works, but normal ping does not?

      That just SCREAMS, SCREAMS!!! firewall on that box!!!

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      I 1 Reply Last reply Feb 25, 2020, 10:22 PM Reply Quote 0
      • I
        ilovechickennuggets @johnpoz
        last edited by Feb 25, 2020, 10:22 PM

        @johnpoz
        🔒 Log in to view
        Correct, this is the newest try at pinging.

        1 Reply Last reply Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator
          last edited by Feb 25, 2020, 10:24 PM

          Well your clearly arping for the IP.. Which comes back with mac correct, and you got your dhcpd address you reserved. So you seem to not being answering..

          The odd thing is you didn't show any pings going out even when you tried to ping.. Which makes no sense - unless you didn't do the sniff right..

          Again can the server ping pfsense IP? Sniff when your doing that test..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          I 1 Reply Last reply Feb 25, 2020, 10:38 PM Reply Quote 0
          • I
            ilovechickennuggets @johnpoz
            last edited by Feb 25, 2020, 10:38 PM

            @johnpoz
            Sorry! Ran the sniff and ping from NAS server to 192.168.70.1 resulted in 100% packet loss.
            🔒 Log in to view
            🔒 Log in to view

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz Feb 25, 2020, 10:43 PM Feb 25, 2020, 10:41 PM

              Ok so your seeing traffic to pfsense interface on 192.168.70.1 - but no answers!

              That points to firewall on pfsense, but that shouldn't stop you from pinging from pfsense unless you have an outbound rule on your lan.. Do you have anything in floating?

              example

              🔒 Log in to view

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              I 1 Reply Last reply Feb 25, 2020, 10:44 PM Reply Quote 0
              • I
                ilovechickennuggets @johnpoz
                last edited by Feb 25, 2020, 10:44 PM

                @johnpoz
                Current floating and LAN rules
                🔒 Log in to view
                🔒 Log in to view

                1 Reply Last reply Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz Feb 25, 2020, 10:51 PM Feb 25, 2020, 10:46 PM

                  Well what interfaces do you have all those rules on? Its quite possible your blocking something in all those rules...

                  Disable them all for "testing"

                  Your lan and server rules mean nothing for pinging from pfsense - the only thing that could cause what seeing would be a outbound rule on your server interface blocking pfsense from sending the ping even..

                  What are you rules on your server interface?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  I 1 Reply Last reply Feb 25, 2020, 10:56 PM Reply Quote 0
                  • I
                    ilovechickennuggets @johnpoz
                    last edited by ilovechickennuggets Feb 29, 2020, 6:48 PM Feb 25, 2020, 10:56 PM

                    @johnpoz
                    So counting from top to bottom, the first 11 rules (pfB_Top_v4 to pfb_TOR_v4) - all 11 have the same setting with block to WAN interface only (only WAN is highlighted in interface box).
                    🔒 Log in to view

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Feb 25, 2020, 11:01 PM

                      Ok well your server interface rules would not allow ping.. So that explains why pfsense would not answer ping.

                      Set a rule to allow ping to pfsense server address.
                      And possible dns is not listening on on 70.1

                      Set your ping rule, and try to ping from server again to 70.1

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      I 1 Reply Last reply Feb 25, 2020, 11:07 PM Reply Quote 0
                      • I
                        ilovechickennuggets @johnpoz
                        last edited by Feb 25, 2020, 11:07 PM

                        @johnpoz
                        Is this the correct way to set up this rule?
                        🔒 Log in to view

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz Feb 25, 2020, 11:10 PM Feb 25, 2020, 11:08 PM

                          No!

                          On your server interface allow ping to the server address.

                          example
                          🔒 Log in to view

                          You want to allow your server to ping pfsense server IP 70.1 - lets get that working atleast!

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          I 1 Reply Last reply Feb 25, 2020, 11:17 PM Reply Quote 0
                          • I
                            ilovechickennuggets @johnpoz
                            last edited by Feb 25, 2020, 11:17 PM

                            @johnpoz
                            Ping resulted in 100% packet loss
                            🔒 Log in to view
                            🔒 Log in to view

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by Feb 25, 2020, 11:20 PM

                              OH my GAWD!! dude... how is the dest 70.2 that is not pfsense IP address!!

                              Please set a rule on your server interface to allow PING to pfsense address server address.. And ping from your server..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              I 1 Reply Last reply Feb 25, 2020, 11:29 PM Reply Quote 0
                              • I
                                ilovechickennuggets @johnpoz
                                last edited by Feb 25, 2020, 11:29 PM

                                @johnpoz
                                Sorry! Dumb mistake! Fixed it. I pinged from the NAS and resulted in packet loss
                                🔒 Log in to view
                                🔒 Log in to view

                                1 Reply Last reply Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz Feb 25, 2020, 11:44 PM Feb 25, 2020, 11:40 PM

                                  Well there is something major wrong... You sure pfsense IP is actually 192.168.70.1?

                                  Can you use a different interface? You don't have any vlans setup or anything like that?

                                  Why was there no answer to the dhcp you show there on port 67? You can arp, but not doing any sort of traffic... Makes no sense at all..

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  I 1 Reply Last reply Feb 25, 2020, 11:45 PM Reply Quote 0
                                  • I
                                    ilovechickennuggets @johnpoz
                                    last edited by Feb 25, 2020, 11:45 PM

                                    @johnpoz
                                    The vlans are all on the LAN side (192.168.69.1) with switch.
                                    The SERVER side has nothing, just a straight direct connection to NAS.

                                    1 Reply Last reply Reply Quote 0
                                    • J
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by johnpoz Feb 25, 2020, 11:47 PM Feb 25, 2020, 11:46 PM

                                      Well makes no sense at all... Do you have another interface you can use? Another cable.. Post a ifconfig output on pfsense. If it was a bad cable - you would think you wouldn't see the traffic too pfense, and you would see traffic out even if didn't get to the client when you sniff when you pinged.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      I 1 Reply Last reply Feb 25, 2020, 11:55 PM Reply Quote 0
                                      • I
                                        ilovechickennuggets @johnpoz
                                        last edited by ilovechickennuggets Feb 29, 2020, 6:49 PM Feb 25, 2020, 11:55 PM

                                        @johnpoz
                                        ifconfig

                                        I do have one more open interface and 1 extra cable. Let's call it a day for now and maybe try some other time and set up the rules and etc for new interface.

                                        Thank you both for your time today! @kiokoman

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by Feb 26, 2020, 12:47 AM

                                          dude... How do you have 192.168.70.1 on igb2, and you also have it on igb1.70??

                                          Pfsense shouldn't even let you do that - because the interfaces overlap!!

                                          🔒 Log in to view

                                          Yeah that is not going to work ;)

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                          I 1 Reply Last reply Feb 26, 2020, 12:57 AM Reply Quote 0
                                          49 out of 74
                                          • First post
                                            49/74
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.