• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Traffic from an IP-address behind Interface LAN1 does not reach the desired IP-address behind Interface LAN4 and vice-versa.

Scheduled Pinned Locked Moved Routing and Multi WAN
5 Posts 2 Posters 579 Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    DebexeL
    last edited by Apr 21, 2020, 5:53 PM

    Traffic from an IP-address behind Interface LAN1 does not reach the desired IP-address behind Interface LAN4 and vice-versa.

    Below are all the rules I've made in pursuit of allowing such traffic. No success.

    Help would be much appreciated!

    e99e4e10-3a41-4cdf-a267-8dc644214ccf-image.png
    f6acf692-0d04-4a18-815a-b12e61a15e36-image.png 4a870e4f-bd57-4a2a-9a1d-f23555151c98-image.png 497c03b7-f8a6-43a3-bd15-64343a4b5e27-image.png 0c684aef-3b7b-4b1a-8a72-ec5dbe5e829a-image.png

    1 Reply Last reply Reply Quote 0
    • V Offline
      viragomann
      last edited by Apr 21, 2020, 8:22 PM

      Ensure that the destination devices firewall does not block the access. By default system firewalls block access from outside the subnet they belong to.

      D 1 Reply Last reply Apr 22, 2020, 6:16 AM Reply Quote 0
      • D Offline
        DebexeL @viragomann
        last edited by Apr 22, 2020, 6:16 AM

        @viragomann I do not have any firewalls apart from the one in pfSense.

        For me, pfSense acts as the router/firewall/dhcp/dns resolver.

        This is my layout:
        ISP VDSL2 --> DMZ Eth4 --> pfSense WAN

        pfSense's interfaces:

        WAN (This is connected to my VDSL2 modem Eth4 which is in DMZ mode. This method provides the pfSense box a public IP, separate from our main home network.)

        LAN1 has a computer connected to them directly, no switches etc..

        LAN2 has no connected device at the moment (But is used for direct ethernet to device)

        LAN3 has a computer connected to them directly, no switches etc..

        LAN4 has a POE-powered Cisco AirLap 1600 series AccessPoint connected to it, which has three devices connected to it wirelessly (one of the devices is connected to my workplace via VPN, as all the traffic on that specific device is forced to go through the workplace network, either via VPN or real office ethernet/wireless)

        I'll update my subnets here after work.

        V 1 Reply Last reply Apr 22, 2020, 12:51 PM Reply Quote 0
        • V Offline
          viragomann @DebexeL
          last edited by Apr 22, 2020, 12:51 PM

          @DebexeL said in Traffic from an IP-address behind Interface LAN1 does not reach the desired IP-address behind Interface LAN4 and vice-versa.:

          I do not have any firewalls apart from the one in pfSense.
          LAN1 has a computer connected to them directly, no switches etc..

          So that computer and the other devices on LAN4 are not running firewalls? So you have deactivated it?

          D 1 Reply Last reply Apr 22, 2020, 3:31 PM Reply Quote 0
          • D Offline
            DebexeL @viragomann
            last edited by DebexeL Apr 22, 2020, 3:31 PM Apr 22, 2020, 3:31 PM

            @viragomann
            Ah, yes those devices do indeed have Windows firewalls on. I thought you meant like actual firewall hardware. My bad. :)

            I'll check those too. Anyway, here are the subnet infos I promised.

            WAN 1000baseT <full-duplex> 84.*********
            LAN1 1000baseT <full-duplex,master> 10.0.0.1/28 (10.0.0.1 - 10.0.0.14 range / 10.0.0.10 - 10.0.0.14 for DHCP)
            LAN2 none ......... 10.0.0.17/28 (10.0.0.17 - 10.0.0.30 / Fully allocated for DHCP)
            LAN3 1000baseT <full-duplex> 10.0.0.33/28 (10.0.0.33 - 10.0.0.46 / Fully allocated for DHCP)
            LAN4 1000baseT <full-duplex> 10.0.0.100/27 (10.0.0.97 - 10.0.0.126 / 10.0.0.101 - 10.0.0.126 for DHCP, 10.0.0.101 Static Leased for Access Point)

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received