Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No ipv4 Internet on LAN

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 1.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • blista99B Offline
      blista99
      last edited by

      Hey guys
      I am somewhat in despair with my problem.
      My LAN devices cannot access the internet over ipv4. Everything over ipv6 is working as it should.
      A couple of days ago I changed some settings on my fully working pfSense Instance (2.6.0) that corrupted my system and I had to reinstall pfsense completely.
      I did that, uploaded my backup configuration and from there on, my internet access on LAN wasn't working anymore. Then (and currently) I tried it with a complete fresh install of pfsense without any special settings and the problem still remains.

      pfSense itself can access (ping, resolve) everything (ipv4 and ipv6 sites), can install packages and more. I do get a public IP address on both (ipv4 and ipv6) and my gateways are reported to be online.

      My setup:
      ISP -> FTTH -> T-Link Media Converter (fiber to LAN) -> pfSense (custom hardware) -> LAN Network

      I do have some special entries on WAN to register with my ISP (dhcp option 60 an VLAN tagging). But since pf itself can access the internet I doubt that this is the source of the problem.
      Nothing else is changed from default in pfSense (though before this crash my setup was the same but with more complicated routes and it worked without a hitch.
      DNS Resolver is active, NAT outbound on automatic.

      0b6d8bec-cfec-4cc5-b47b-859d2666282e-image.png

      4242745c-ca1b-4cc8-82f2-5a4bc794915a-image.png

      3e60e543-fe98-45d6-86ec-9abf5dbf3dc5-image.png

      7962e412-81c8-42d9-bcb8-bc18c7baddd6-image.png

      fce28f24-663e-4d37-9e34-baaa181512eb-image.png

      2cb3acca-5fc2-45c0-9f63-8a21ea3b9653-image.png

      These are the ping results:

      b991c481-91dc-4ba8-bc34-95b8acdffa6a-image.png

      e9a1012b-75f7-4719-bacf-1fdbbc08e807-image.png

      d012c334-d5c5-40c1-a05d-cbdf3120a971-image.png

      037f32ea-099b-4996-bc8c-b41dd0878844-image.png

      Many thanks for your help!
      Regards

      V 1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @blista99
        last edited by

        @blista99
        Check the outbound NAT if there is a proper rule for the LAN network.

        1 Reply Last reply Reply Quote 1
        • blista99B Offline
          blista99
          last edited by

          @viragomann Ok. You are right...I did not realize that.
          It is set to default...so automatic rule generation...
          But then again the tab is empty....

          486ce8f8-4953-4e19-8208-f77d5ba0e3b2-image.png

          Shouldn't there be at least one rule? How can a change this?

          blista99B V 2 Replies Last reply Reply Quote 0
          • blista99B Offline
            blista99 @blista99
            last edited by

            OK. Update:
            I did get it up and running...but only with a manual entry:
            e2cf055a-a57a-4621-a4f1-893808bd0d3e-image.png

            431fd937-5a9b-4d74-b999-06ce8c1272d0-image.png

            This solves my immediate problem...but raises the question, why a fresh pfSense install does not generate a auto-rule for that....?

            1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann @blista99
              last edited by

              @blista99
              The rules are generated automatically, when there is a gateway stated in the WAN interface settings. But when using DHCP configuration, this should be set automatically.
              So don't know, why it didn't.

              Is the IPv4 WAN gateway set as default in System > Routing > Gateways?

              blista99B 2 Replies Last reply Reply Quote 0
              • blista99B Offline
                blista99 @viragomann
                last edited by

                @viragomann Yes...and no??
                67c7e546-a622-481e-a444-84f6b8eb5ac1-image.png

                The settings should assume so...but the "planet"-symbol-standard gateway is on ipv6.
                But I don't see how to change that.

                And thank you very much....you saved me a lot of fiddling!!

                1 Reply Last reply Reply Quote 0
                • blista99B Offline
                  blista99 @viragomann
                  last edited by

                  @viragomann Could this automatic generation be influenced by my manual entry in "DHCP Client Configuration" of WAN? (see above)
                  Maybe I need to add something to that..?
                  But then again....it worked the first time when I set my pfSense up 3 years ago.

                  V 1 Reply Last reply Reply Quote 0
                  • V Offline
                    viragomann @blista99
                    last edited by viragomann

                    @blista99 said in No ipv4 Internet on LAN:

                    Could this automatic generation be influenced by my manual entry in "DHCP Client Configuration" of WAN? (see above)

                    Maybe, didn't notice before. But I'm also not familiar with this.
                    I guess, these settings are required by your ISP?

                    Is it not possible to state the additional settings in the advanced options?

                    blista99B 1 Reply Last reply Reply Quote 0
                    • blista99B Offline
                      blista99 @viragomann
                      last edited by

                      @viragomann Yeah. The DHCP Option 60 needs to be sent to the ISP to NOT get blocked of accessing.
                      Because they "allow" third-party routers connected directly to their network (without the official ISP-router in between) but do not like it very much.
                      But no, I cannot state additional, advanced settings in DHCP when the configuration override is active. I'd have to add something to the string in the .conf file I link to in the settings.
                      Maybe I'll open a separate topic for this.

                      Anyway thank you @viragomann for your help! 👍 😀

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by stephenw10

                        Yeah, it looks like however you have created that custom dhclient is causing a problem. There is no gateway IP shown. It's like it doesn't realise it has a connection.

                        You should be able to enter that custom dhcp option 60 setting via the GUI. Just check the advanced options box and enter it in the send options field.

                        Steve

                        blista99B 1 Reply Last reply Reply Quote 1
                        • blista99B Offline
                          blista99 @stephenw10
                          last edited by

                          @stephenw10 Alright. Thanks!
                          I'll try that, when I'm less dependent on a stable connection. 😬
                          My way was posted in my ISP's forum a couple of years ago. I think back then this "send option" was not implemented into pfSense.

                          blista99B 1 Reply Last reply Reply Quote 0
                          • blista99B Offline
                            blista99 @blista99
                            last edited by

                            For everyone having the same problem:
                            DO NOT add something custom to the DHCP configuration of WAN via "Custom Override" before connecting once on WAN. It will fuck up your automatic rule generation in NAT and resolve in not getting any ipv4 connection on anything but WAN.
                            If this rule generation has happend...then it is ok to add whatever you want.

                            For my specific situation I only had to add the string of my conf-file into the "Send" options of the advanced DHCP settings (as @stephenw10 mentioned) and it works better than it has ever had!

                            91084322-bdfb-48a7-a21f-0fc5a3627541-image.png

                            Thank you netgate community!

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.