Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing between 2 LAN NIC

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 2 Posters 903 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      abidkhanhk
      last edited by

      Hi, this question has probably been asked 10k times before i am kind of confused and hit a roadblock,

      i got 2 LAN NIC on pfsense,

      1. 192.168.1.0/24
      2. 192.168.0.0/24

      WAN DHCP- set as default gateway,

      under interface assignment i have not set a default Gateway for either of the LANs, because once my PC is connect i can reach the public internet just fine,
      However, i am unable to ping from 192.168.0.40 to 10.168.1.40

      BUT when from 192.168.0.40 i CAN ping 192.168.1.1 , but not the rest of the network, I have disabled the firewall on the client machines but still no joy,

      i have added the firewall rules on both LAN NIC for any to any allow, but still cannot ping
      Kindly assist.

      1 Reply Last reply Reply Quote 0
      • chpalmerC Offline
        chpalmer
        last edited by

        Windows machines treat anything outside of their own subnet as "public" and will block it as such.

        Im going out on a small limb as blaming the firewall on the client machines even if you think they are disabled. Gateway on those machines should point to 192.168.1/0.1 Not your WAN gateway..

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        A 1 Reply Last reply Reply Quote 0
        • A Offline
          abidkhanhk @chpalmer
          last edited by abidkhanhk

          @chpalmer firewall on the Windows machine is disabled, in fact i also have a small Pi unit on the networks, on same network the ping is working fine, but cross network its not working

          EDIT, Regarding Gateway, Should i create a new gateway for each Lan? i.e. 192.168.1.1 and 192.168.0.1 ? or just create a single one 192.168.1.1 and define that as default for all Gateway?
          also when i run ipconfig in cmd., i can see that the dhcp server had already provided the gateway to the client Machine, like 192.168.0.1 for the 192.168.0.0/24 network, so is there still a need for setting a default gateway?

          1 Reply Last reply Reply Quote 0
          • chpalmerC Offline
            chpalmer
            last edited by

            No gateways on the LAN interfaces.

            You made the comment above- "WAN DHCP- set as default gateway," Is that on the WAN interface?

            Are client machines all set with static or DHCP?

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            A chpalmerC 2 Replies Last reply Reply Quote 0
            • A Offline
              abidkhanhk @chpalmer
              last edited by

              @chpalmer Sorry i meant to say WAN is a DHCP,

              Both Lan gets their IP via DHCP,

              1 Reply Last reply Reply Quote 0
              • chpalmerC Offline
                chpalmer @chpalmer
                last edited by

                Ok I see your edit.

                Show your firewall rules for each LAN interface..

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                A 1 Reply Last reply Reply Quote 0
                • A Offline
                  abidkhanhk @chpalmer
                  last edited by abidkhanhk

                  @chpalmer

                      • LAN1 Address 443
                        80 * * Anti-Lockout Rule

                  IPv4 * LAN1 net * * * * none Default allow LAN to any rule
                  IPv6 * LAN1 net * * * * none Default allow LAN IPv6 to any rule

                  for Lan2

                  IPv4 * LAN2 net * * * * none Default allow LAN to any rule
                  IPv6 * LAN2 net * * * * none Default allow LAN IPv6 to any rule

                  Both LAN interfaces have allowed for any to any traffic.

                  chpalmerC 1 Reply Last reply Reply Quote 0
                  • chpalmerC Offline
                    chpalmer @abidkhanhk
                    last edited by

                    @abidkhanhk

                    Do you mean?

                    IPv4 * LAN1 net * * * * none Default allow LAN1 to any rule
                    IPv6 * LAN1 net * * * * none Default allow LAN1 IPv6 to any rule

                    for Lan2

                    IPv4 * LAN2 net * * * * none Default allow LAN2 to any rule
                    IPv6 * LAN2 net * * * * none Default allow LAN2 IPv6 to any rule

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    A 1 Reply Last reply Reply Quote 0
                    • A Offline
                      abidkhanhk @chpalmer
                      last edited by

                      @chpalmer Yes, these are the default allow any to any rule,

                      chpalmerC 1 Reply Last reply Reply Quote 0
                      • chpalmerC Offline
                        chpalmer @abidkhanhk
                        last edited by

                        @abidkhanhk

                        The 2nd LAN would not have a default rule. You would have had to make it up. That's why I wanted to verify that the rules were built right.

                        Pfsense by default routes between subnets. If the firewall rules are correct (a screenshot would be great) then the issue must lie on the client machines.

                        Example from one of my boxes.

                        firewallrule.jpg

                        Triggering snowflakes one by one..
                        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                        A 1 Reply Last reply Reply Quote 1
                        • A Offline
                          abidkhanhk @chpalmer
                          last edited by

                          @chpalmer I think i am screwing up somewhere on the switches... sigh

                          Thanks for your help~

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.