• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Cannot Ping WAN Interface

Scheduled Pinned Locked Moved General pfSense Questions
13 Posts 3 Posters 4.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    andy10 @SteveITS
    last edited by Jun 11, 2020, 3:18 AM

    @teamits Thank you for your answer...I have a any-any rule under WAN...do I still need to create another rule?

    S 1 Reply Last reply Jun 11, 2020, 4:07 PM Reply Quote 0
    • G
      Gertjan @andy10
      last edited by Jun 11, 2020, 6:06 AM

      @andy10 said in Cannot Ping WAN Interface:

      Thoughts?

      Your "any to any rule on WAN" is just temporary to make ICMP work, right ? What about, at least, limiting this "IPv4*" protocols to "ICMP" ?
      DO NOT keep it rule.
      Or change pfSense for a switch to have close to identical results, and zero admin efforts.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      A 1 Reply Last reply Jun 11, 2020, 6:12 AM Reply Quote 0
      • A
        andy10 @Gertjan
        last edited by Jun 11, 2020, 6:12 AM

        @Gertjan yes it’s a temp rule...i need to figure out first why i cannot ping my WAN IP...

        1 Reply Last reply Reply Quote 0
        • G
          Gertjan
          last edited by Jun 11, 2020, 8:00 AM

          Using what ? From where ? Through which other upstream devices - the ones between you and pfSense ?

          @andy10 said in Cannot Ping WAN Interface:

          I can ping the LAN interface but I cannot ping the WAN IP

          From where ?

          You have already a pass all rule - that's ok for testing purposes.
          You know now that ant traffic coming into WAN will be 'seen' by the network stack. At that level, ICMP is handled.
          You should fire up tcpdump (packet capture), select WAN as the interface and ICMP for the type of protocol.
          Now you ping from where ever you ping.
          Stop the capturing : if it's empty, the traffic never reached pfSense.

          Most often this is explained easily : right after you discover that the ISP router is also a router (...) it becomes clear that router should a) also reply to ICMP (because this router has the actual WAN IP, not pfSense, which uses a RFC1819 type IP), or b) pass the ICMP requests through.

          Are you trying to ping from pfSense's LAN the WAN IP ? What are your LAN rule(s) ?
          Your WAN IP is a RFC1918 type ?

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          A 1 Reply Last reply Jun 11, 2020, 4:45 PM Reply Quote 0
          • S
            SteveITS Galactic Empire @andy10
            last edited by Jun 11, 2020, 4:07 PM

            @andy10 I was assuming you were pinging from LAN. If no block is logged by the default block rule then it's not being blocked, meaning it's generally a routing or some other issue.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote πŸ‘ helpful posts!

            1 Reply Last reply Reply Quote 0
            • A
              andy10
              last edited by Jun 11, 2020, 4:42 PM

              I am pinging from another server on the LAN network.

              6918f15e-5eb0-419c-9727-abd7dcaed0d8-image.png

              S 1 Reply Last reply Jun 11, 2020, 5:29 PM Reply Quote 0
              • A
                andy10 @Gertjan
                last edited by Jun 11, 2020, 4:45 PM

                @Gertjan
                From where ?

                You have already a pass all rule - that's ok for testing purposes.
                You know now that ant traffic coming into WAN will be 'seen' by the network stack. At that level, ICMP is handled.
                You should fire up tcpdump (packet capture), select WAN as the interface and ICMP for the type of protocol.
                Now you ping from where ever you ping.
                Stop the capturing : if it's empty, the traffic never reached pfSense. colored text please see screenshot

                8df4a0a4-4b9d-40de-8b19-3f8be12214e9-image.png

                Most often this is explained easily : right after you discover that the ISP router is also a router (...) it becomes clear that router should a) also reply to ICMP (because this router has the actual WAN IP, not pfSense, which uses a RFC1819 type IP), or b) pass the ICMP requests through.

                ISP is not involved here...it's installed on a VM which is behind a Palo Alto firewall...

                Are you trying to ping from pfSense's LAN the WAN IP ? What are your LAN rule(s) ? trying to ping from 2 servers on the LAN and WAN networks...both fail
                Your WAN IP is a RFC1918 type ?colored text 10.1.100.110/24

                1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @andy10
                  last edited by Jun 11, 2020, 5:29 PM

                  @andy10 Does the server you're pinging from have a firewall rule that is blocking the replies?
                  If you're pinging from LAN the WAN rule shouldn't be used.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote πŸ‘ helpful posts!

                  A 1 Reply Last reply Jun 11, 2020, 5:31 PM Reply Quote 0
                  • A
                    andy10 @SteveITS
                    last edited by Jun 11, 2020, 5:31 PM

                    @teamits no..the windows firewall is off....the weird thing is that when i reboot pfsense...and run a continuous ping to the WAN interface...i get responses right before it shuts down ...could it be a bug ?

                    1 Reply Last reply Reply Quote 0
                    • A
                      andy10
                      last edited by Jun 12, 2020, 10:51 PM

                      I reinstalled pfsense on another VM and i can ping the interfaces now...could be a bug! Issue resolved. Thanks!

                      1 Reply Last reply Reply Quote 0
                      • G
                        Gertjan
                        last edited by Jun 13, 2020, 7:29 AM

                        Bug ?
                        Setup !

                        pfSense handles ICMP as per user settings.
                        If not, this forum would be swamped by angry user posts ^^

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        12 out of 13
                        • First post
                          12/13
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received