Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PF Sense Setup

    Scheduled Pinned Locked Moved General pfSense Questions
    125 Posts 5 Posters 33.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TravelMore @jsmiddleton4
      last edited by TravelMore

      @jsmiddleton4 this is what it looks like. I took a video of all the settings so if i ever had to go back and look i had an exact replica aside from a backup file.

      2160f82b-98e7-4d00-826f-d002f8379a1e-image.png

      Thank you for that info. I wasnt sure how to set it to be just a modem besides just throwing it in bridge mode. I appreciate your help. I will try this again sometime this week and give updates. hopefully it'll work and i can rely that!

      J 1 Reply Last reply Reply Quote 0
      • J
        jsmiddleton4 @TravelMore
        last edited by jsmiddleton4

        @travelmore

        You want to enable IP Passthrough and then pick the Ethernet port you want to use for the WAN.

        Once you know for sure your modem is passing the WAN’s IP information through to your PFSense box, everything else is all PFSense configuration.

        I have to ask what bridge mode were you setting then? We’re you braiding two Ethernet ports? More commonly called bonding.

        Also I would consider blasting the drive with a new PFSense install.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator @TravelMore
          last edited by

          @travelmore said in PF Sense Setup:

          @stephenw10 i did try swapping the cables at one point and it didn't make a difference. i cant recall if it made it worse or not i just know it was not progress moving forward when i swapped them lol. (so then i reverted the swap to keep troubleshooting.)

          I would try it again to be sure.

          If you can access the pfSense GUI when the laptop is connected to the modem that means the pfSense LAN must also be connected to the modem which is obviously not what you want.
          It also explains why you see no IP on the WAN as that is in fact connected to your internal switch where no DHCP server exists.
          Swapping the cables at the pfSense box (reversing the WAN and LAN NICs) should correct that.

          Steve

          J T 2 Replies Last reply Reply Quote 0
          • J
            jsmiddleton4 @stephenw10
            last edited by

            @stephenw10

            I'm not sure the modem was in IP Pass Through mode. Which means of course no WAN information was being passed to the PFSense box. The modem was "seeing" the PFSense box as a LAN client.

            johnpozJ T 2 Replies Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @jsmiddleton4
              last edited by johnpoz

              @jsmiddleton4 said in PF Sense Setup:

              The modem was "seeing" the PFSense box as a LAN client.

              Which is not a problem - you can for sure run double nat setup. As long as pfsense wan and lan do not overlap networks.. If your pfsense wan is say 192.168.1/24 - just make pfsense lan 192.168.2/24 or something.

              Doesn't matter if pfsense wan gets an IP or doesn't get an IP, or gets an IP and can not go anywhere.. You would still be able to connect to pfsense lan from client on its lan.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              J 1 Reply Last reply Reply Quote 0
              • J
                jsmiddleton4 @johnpoz
                last edited by

                @johnpoz

                I understand. He isn't or wasn't trying to setup a double NAT config though.

                Go back and set up the modem so its doing just the modem piece, IP Pass through. That's what I was calling bridge mode. Pick the port he wants to be the WAN port.

                I'd blast PFSense and start clean.

                Then follow the PFSense document step by step for install/setup.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @jsmiddleton4
                  last edited by johnpoz

                  @jsmiddleton4 I would suggest he gets it working in double nat, before messing with any sort of bridge/passthru mode on his modem.

                  Once he has that working - it its minor to change over to pfsense actually getting a public IP.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    If you read back through this thread it seems pretty clear to me that the WAN and LAN were swapped. Everything else is secondary to that, obviously nothing will work as expected in that situation.

                    the pfSense webgui could not be accessed from the LAN side. It can only be accessed from the WAN side. (using the LAN IP?) The only rational explanation for that is the LAN and WAN are swapped.

                    Steve

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @stephenw10
                      last edited by

                      @stephenw10 quite true - and agree with you.. My point is before concerning with what IP is on pfsense wan.. I would make sure you can access it from the lan.. What pfsense internet/wan interface is doing or not doing has little to do with being able to access it via lan on initial setup.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        jsmiddleton4 @johnpoz
                        last edited by

                        Once he gets the modem configured the way its supposed to be.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @jsmiddleton4
                          last edited by

                          @jsmiddleton4 said in PF Sense Setup:

                          way its supposed to be.

                          Supposed to be for what - out of the box it almost for sure it going to be natting. So you could argue that is the way it is "suppose" to be ;) There are plenty of instances in double nat, shoot even triple nat that cause the users no grief. So I would leave that until after.

                          He seems to be having a hard time getting even a basic setup. So I would get pfsense working to the point you can access it from something behind it on its lan. Before worry about what IP is on wan if any.. Yes it really helps you understand which interface pfsense is using for its lan and wan interfaces ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            jsmiddleton4 @johnpoz
                            last edited by

                            @johnpoz

                            The way it is supposed to be for what he's clearly stated he's trying to accomplish. Which is not double NATing.

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @jsmiddleton4
                              last edited by

                              @jsmiddleton4 said in PF Sense Setup:

                              for what he's clearly stated he's trying to accomplish

                              Where did he state that?

                              @travelmore said in PF Sense Setup:

                              my goal is to monitor all the devices on my network (wired and wireless) and see how much bandwidth they are pulling and by what method (browsing, gaming, streaming, etc.)

                              That has zero do to with him double natting or not.

                              @travelmore said in PF Sense Setup:

                              I still am using my ISP-provided modem/router to hand out DHCP (I’d prefer to keep it that way until I get more familiar w/everything)

                              From that, seems more like he doesn't want to touch anything on his modem router. I am all for removing double nat... My point is might be better to just get his setup working with stuff behind pfsense before messing with anything at all on the router. If his isp device is working.. Then just connect pfsense behind it - get it working and clients behind it working before messing with the config of the isp device. That is all I am trying to say.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              J 1 Reply Last reply Reply Quote 0
                              • J
                                jsmiddleton4 @johnpoz
                                last edited by

                                @johnpoz

                                Have a good day John.

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @jsmiddleton4
                                  last edited by

                                  @jsmiddleton4 you too - but your over complicating it is all.. And seems like just confusing him if you ask me.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  J 1 Reply Last reply Reply Quote 0
                                  • J
                                    jsmiddleton4 @johnpoz
                                    last edited by

                                    @johnpoz

                                    Again John, have a good day.

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      TravelMore @jsmiddleton4
                                      last edited by

                                      @jsmiddleton4 I appreciate your help. the Modem was not in IP Pass-Through mode. I didnt realize I had to do that. I thought I was just supposed to put the modem into bridge mode, which i did so by going into gateway function, clicking the residential gateway function, and selecting disabled (black circled option).

                                      Putting the residential gateway function to disabled pushes the modem/router into bridge mode, so its literally just handing off the ISP internet to whatever device i plug into the modem. (At least that is my impression/understanding from doing this).

                                      1deffa8e-d5fe-4ca0-b438-47b2faed9dfa-image.png

                                      If PFSense should had out dhcp that is fine. As long I know I can just reset my router and put it back to how it was using a back up file (like i did last night) I am fine w/that.

                                      I would like to learn how to setup PF Sense correctly from the start because then I will jot down the way that I got it setup, then get a lab setup and install it again on a lab to test different things w/it before throwing it into my home network production environment.

                                      J 1 Reply Last reply Reply Quote 0
                                      • J
                                        jsmiddleton4 @TravelMore
                                        last edited by

                                        @travelmore

                                        Correctly can be any number of ways.

                                        My understanding is you wanted the modem to be first, PFSense box second doing the heavy lifting, hang everything off the PFSense box.

                                        If that's what you're looking for the modem needs to be in IP Passthrough, not residential gateway, etc. Pick the port you want to be the ethernet WAN port on the back of the modem. Connect that one port to the ethernet, interface, that is configured as the WAN port for the PFSense box.

                                        You're done with the modem. Everything else is the PFSense configuration.

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          TravelMore @stephenw10
                                          last edited by

                                          @stephenw10 I will test things again this week. In the other thread (https://forum.netgate.com/topic/168766/setting-up-pfsense-on-my-home-network), it stated "where your modem/isp device would be connected to "wan" of pfsense, and your switch would be connected to "lan" interface of pfsense."

                                          So that is what I did. I will have to boot up the pf sense box w/a monitor straight to it to verify if the cards are still as is. I was under the impression i had them correct i doubl checked 3 times but who knows maybe i got them mixed up.

                                          J 1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Yes, that is correct and that is how you should connect them but it's easy enough to get them the wrong way round, especially if both your NICs are the same, like re0 and re1.

                                            The best way to check is to use the console directly. At the menu choose option 8 to access the command line and then run: ifconfig re0

                                            Look for the media and status lines to see how that is linked, for example:

                                            [22.01-BETA][admin@apu.stevew.lan]/root: ifconfig re0
                                            re0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
                                            	description: OPT1
                                            	options=8209b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,WOL_MAGIC,LINKSTATE>
                                            	ether 00:0d:b9:37:30:10
                                            	inet6 fe80::20d:b9ff:fe37:3010%re0 prefixlen 64 scopeid 0x1
                                            	inet 10.200.200.1 netmask 0xffffffc0 broadcast 10.200.200.63
                                            	media: Ethernet autoselect (1000baseT <full-duplex,master>)
                                            	status: active
                                            	nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
                                            

                                            Now unplug the NIC you think is re0 and run the command again. Make sure it shows the link went down.

                                            Steve

                                            T 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.