Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't reach access point on other interface/subnet to configure it.

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 627 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      Indiegamesfan
      last edited by

      I am making a guest network on a separate interface and have my machine on what is my private network. I am able to ping the access point and receive a reply but am unable to access the web interface for the access point. Have been trying to find any information online and am at my wits end so any help will be appreciated.

      e1fc37e0-7071-44d3-bd64-6cc72a5a4562-image.png

      c2cf9eb2-01a6-4906-abb9-bc0fa5f3d15e-image.png

      34f346f6-9570-46c3-8f35-36a9c47ff1e9-image.png

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Indiegamesfan
        last edited by

        @indiegamesfan Does the AP have a gateway configured?

        Any chance its web server only listens from its subnet?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        I 1 Reply Last reply Reply Quote 0
        • I
          Indiegamesfan @SteveITS
          last edited by

          @steveits The gateway is configured since I can access the AP if I wire myself into the other network.
          The AP is a TP-Link EAP225 V2 and I can't find any information about it only looking on it's own subnet.

          The goal is for the main network to be the administration network and block the web interface on the guest network.

          S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            There are (at least) two things that could be in play here:

            The access point has no route to the Main subnet.

            The access point is actively blocking connections from outside it's subnet.

            It seems like it does have a route since it is able to reply to pings. So it's probably configured to only allow access to it's webgui from inside the same subnet.
            Try to connect to it from pfSense using Diag > Test Port.
            Test agaibnst the AP IP address on port 443 leaving the source addess as 'Any' or setting it to APS. If that works try setting the source as MAIN. That will probably fail.

            If so either configure the AP to allow it or add an outbound NAT rule in pfSense to hide the source IP.

            Steve

            1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @Indiegamesfan
              last edited by

              @indiegamesfan said in Can't reach access point on other interface/subnet to configure it.:

              and block the web interface on the guest network

              I doubt that would be possible with most AP devices, but probably the best chance is to use an outbound NAT rule as mentioned and on the AP allow access only from that IP (the IP of that NAT rule).

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote ๐Ÿ‘ helpful posts!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.