Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense: online and pingable upstream gateway via PPPoE but no internet

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 2 Posters 1.6k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bfj7234
      last edited by bfj7234

      Hi everyone,
      I've had issues with my recent migration to a virtulized pfSense installation as my main router. As you can see in the included screenshots, the gateway is online and I am able to ping it from my workstation but even though I can ping the upstream gateway, I have no internet. This is my second attempt at configuring pfSense from scratch.

      Network setup:
      FTTH --> ONT(bridge mode) --> NIC1 on server --> Proxmox bridge vmbr1 --> WAN pfSense VM --> (LAN)vmbr0 --> NIC2 --> Mikrotik 24port 2SFP+ switch.

      pfSense version: 2.5.1-RELEASE
      Proxmox version: Linux proxmox-ve 5.4.106-1-pve

      Hypervisor network config:
      proxmox-network-config.png
      VM config:
      proxmox-vm-hw.png
      proxmox-vm-options.png
      As you can see, I even tried to setup the VM with a 30 second start delay after boot.

      pfSense dashboard:
      pfsense-dash.png

      System > Routing > Gateways
      system-routing-gateways.png

      Interfaces > WAN
      interfaces-wan.png

      Interfaces > PPPs > PPPoE
      interfaces-ppps-pppoe.png

      Logs > gateway
      logs-gateway.png

      Logs > routing
      system-routing-logs.png

      Diagnostics > Routes
      diagnostics-routes.png

      Log > PPPoE
      pfsense-PPPoE.txt

      Ping log from my laptop
      ping.txt

      This configuration sometimes works after changing random settings and reverting the changes while doing plenty reboots.

      Please ask if you need more logs.

      DaddyGoD 1 Reply Last reply Reply Quote 0
      • DaddyGoD Offline
        DaddyGo @bfj7234
        last edited by

        @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

        I have no internet.

        Hi,

        Is the default allow rule set?

        3ddbf1cb-f726-4b9c-90e1-d5c67150c6cf-image.png

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          bfj7234 @DaddyGo
          last edited by bfj7234

          @daddygo
          Hi, yes I do have an allow all rule enabled on all LAN interfaces.

          Note: I do have pfBlocker installed and configured but have since disabled it completely.

          DaddyGoD 1 Reply Last reply Reply Quote 0
          • DaddyGoD Offline
            DaddyGo @bfj7234
            last edited by DaddyGo

            @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

            I do have pfBlocker installed and configured but have since disabled it completely.

            This should not be a problem.

            but...

            Resolver and or forwarder? settings are correct?

            what this shows for example:

            a483e552-5e3e-442f-8d69-98ffcd73b482-image.png

            and / or

            1f16d79c-47fe-4066-b381-63a10b6b4811-image.png

            +++edit:

            jah,.... and why are you disabling the GW monitor action?

            +++edit2:
            note, you should see something like this...

            c375f9b2-2d36-4aa3-b6b6-eb4090f2d321-image.png

            f1a00fc5-820e-45e5-9da4-c7ce5d25e16f-image.png

            Cats bury it so they can't see it!
            (You know what I mean if you have a cat)

            B 2 Replies Last reply Reply Quote 0
            • B Offline
              bfj7234 @DaddyGo
              last edited by

              @daddygo
              If I include the @ 1.1.1.1 it gives an error(no route to 1.1.1.1), without the @1.1.1.1 it resolves bbc.com via unbound.
              Screenshot-20210607211459-1032x394.png

              Screenshot-20210607212512-766x1053.png

              DaddyGoD 1 Reply Last reply Reply Quote 0
              • B Offline
                bfj7234 @DaddyGo
                last edited by

                @daddygo said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                +++edit:
                jah,.... and why are you disabling the GW monitor action?

                One of the troubleshooting steps I tried, have since enabled it again without success.

                1 Reply Last reply Reply Quote 0
                • DaddyGoD Offline
                  DaddyGo @bfj7234
                  last edited by DaddyGo

                  @bfj7234

                  gotcha... - you have no DNS resolution at the moment
                  Okhay, I show you.... ๐Ÿ˜‰

                  you do not have to use CF DNS - choose what you want

                  642528d6-ad37-4812-80ac-cbe5491f1db2-image.png

                  1. network interfaces to the internals (LAN, OPT1, OPT2, etc,)
                  2. Outgoing Intf.s (WAN, WAN2 or VPN intf., etc.)

                  aa2a9683-dbcd-47fb-969e-7809522c24da-image.png

                  +++edit:

                  Unbound in forwarding mode!

                  pls. on GENERAL TAB + DNS servers + DNS behavior = USE REMOTE DNS SERVERS!!!

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  B 1 Reply Last reply Reply Quote 0
                  • B Offline
                    bfj7234 @DaddyGo
                    last edited by

                    @daddygo said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                    you do not have to use CF DNS - choose what you want

                    CF is my 2nd choice for DNS provider:
                    Screenshot-20210607213726-1034x430.png

                    DaddyGoD 1 Reply Last reply Reply Quote 0
                    • DaddyGoD Offline
                      DaddyGo @bfj7234
                      last edited by DaddyGo

                      @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                      CF is my 2nd choice for DNS provider:

                      this is not relevant now๐Ÿ˜‰

                      +++edit:

                      Unbound in forwarding mode! (at least that's what's on the PRTSC you showed me)

                      pls. on GENERAL TAB + DNS servers + DNS behavior = USE REMOTE DNS SERVERS!!!

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      B 1 Reply Last reply Reply Quote 0
                      • B Offline
                        bfj7234 @DaddyGo
                        last edited by bfj7234

                        @daddygo said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                        Unboud in forwarding mode! (at least that's what's on the PRTSC you showed me)

                        Yes its enabled (should it be enabled or disabled? I assume it should be enabled)

                        pls. on GENERAL TAB + DNS servers + DNS behavior = USE REMOTE DNS SERVERS!!!

                        ๐Ÿ‘

                        DaddyGoD 1 Reply Last reply Reply Quote 0
                        • DaddyGoD Offline
                          DaddyGo @bfj7234
                          last edited by DaddyGo

                          @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                          Yes its enabled

                          don't touch it ๐Ÿ˜‰
                          this is correct if you want to use third party DNS (like CloudFlare 1.1.1.1) instead of root servers

                          the problem will be with this: ( System / General Setup)

                          5461011c-465e-4316-87c1-46713c2e3bd6-image.png

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          B 1 Reply Last reply Reply Quote 0
                          • B Offline
                            bfj7234 @DaddyGo
                            last edited by

                            @daddygo I just did my 7th restart of the ONT and re-socket of the Ethernet cable, internet is working now. No idea what it could be, maybe a faulty ONT or NIC๐Ÿค”

                            DaddyGoD 1 Reply Last reply Reply Quote 0
                            • DaddyGoD Offline
                              DaddyGo @bfj7234
                              last edited by DaddyGo

                              @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                              restart of the ONT and re-socket of the Ethernet cable, internet is working now

                              that doesn't fix your DNS setting, just look up your Dig

                              885cd801-09b2-48ef-bb45-f1a0e70396e2-image.png

                              +++edit:

                              I guess the DNS server override is checked

                              Cats bury it so they can't see it!
                              (You know what I mean if you have a cat)

                              B 2 Replies Last reply Reply Quote 0
                              • B Offline
                                bfj7234 @DaddyGo
                                last edited by bfj7234

                                @daddygo said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                                @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                                restart of the ONT and re-socket of the Ethernet cable, internet is working now

                                that doesn't fix your DNS setting, just look up your Dig

                                885cd801-09b2-48ef-bb45-f1a0e70396e2-image.png

                                DNS is working:

                                pfSense command prompt:

                                ; <<>> DiG 9.16.12 <<>> bbc.com
                                ;; global options: +cmd
                                ;; Got answer:
                                ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22534
                                ;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1

                                ;; OPT PSEUDOSECTION:
                                ; EDNS: version: 0, flags:; udp: 512
                                ;; QUESTION SECTION:
                                ;bbc.com. IN A

                                ;; ANSWER SECTION:
                                bbc.com. 300 IN A 151.101.128.81
                                bbc.com. 300 IN A 151.101.192.81
                                bbc.com. 300 IN A 151.101.0.81
                                bbc.com. 300 IN A 151.101.64.81

                                ;; Query time: 170 msec
                                ;; SERVER: 9.9.9.9#53(9.9.9.9)
                                ;; WHEN: Mon Jun 07 21:56:26 SAST 2021
                                ;; MSG SIZE rcvd: 100

                                My laptop

                                ; <<>> DiG 9.16.15 <<>> bbc.com
                                ;; global options: +cmd
                                ;; Got answer:
                                ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41
                                ;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1

                                ;; OPT PSEUDOSECTION:
                                ; EDNS: version: 0, flags:; udp: 1432
                                ;; QUESTION SECTION:
                                ;bbc.com. IN A

                                ;; ANSWER SECTION:
                                bbc.com. 300 IN A 151.101.0.81
                                bbc.com. 300 IN A 151.101.64.81
                                bbc.com. 300 IN A 151.101.128.81
                                bbc.com. 300 IN A 151.101.192.81

                                ;; Query time: 19 msec
                                ;; SERVER: 192.168.10.1#53(192.168.10.1)
                                ;; WHEN: Mon Jun 07 21:58:07 SAST 2021
                                ;; MSG SIZE rcvd: 100

                                DaddyGoD 1 Reply Last reply Reply Quote 0
                                • DaddyGoD Offline
                                  DaddyGo @bfj7234
                                  last edited by

                                  @bfj7234 said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                                  DNS is working:

                                  Ok magic ๐Ÿ˜‰

                                  but you have a lot of wrong settings...

                                  this will help you in many ways

                                  https://www.vikash.nl/setup-pfblockerng-python-mode-with-pfsense/

                                  Cats bury it so they can't see it!
                                  (You know what I mean if you have a cat)

                                  1 Reply Last reply Reply Quote 0
                                  • B Offline
                                    bfj7234 @DaddyGo
                                    last edited by bfj7234

                                    @daddygo said in pfSense: online and pingable upstream gateway via PPPoE but no internet:

                                    I guess the DNS server override is checked

                                    Nope it isn't
                                    The DNS Resolution Behavior is also set to "Use remote DNS servers, Ignore local DNS"

                                    this will help you in many ways
                                    https://www.vikash.nl/setup-pfblockerng-python-mode-with-pfsense/

                                    Will check it out tnx!

                                    I used Lawrence Systems on youtube's guide on configuring pfBlocker and other areas.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.