Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Switched ISP, PPPoE to DHCP

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F022YF
      F022Y
      last edited by

      Very quick one which is probably down to my stupidity but i'm going to ask and i did search but DHCP brings up other posts about local network.

      I have recently switched from one UK ISP on FTTC which used PPPoE to an altnet which uses DHCP on FTTP. All i have done in pfsense is switched the WAN interface and i have internet yay but all of my firewall rules (BQM monitor to thinkbroadband, port forwards for the 2 game server i run for my friends) have just stopped working.

      Have i missed something?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Anything referencing the old PPPoE gateway might need to be changed to the new WAN_DHCP dynamic gateway. But rules on WAN allowing traffic to, say, WAN address should still apply.
        Unless you created a new interface almost everything should carry across a change like that.

        Steve

        F022YF 1 Reply Last reply Reply Quote 0
        • F022YF
          F022Y @stephenw10
          last edited by

          @stephenw10 Thanks for the reply, I thought i removed all the references to the PPPoE stuff. I have a new box turning up in the next few days to migrate my VMs to (including the PFSense VM) I may just rebuild the router and see if that fixes everything.

          1 Reply Last reply Reply Quote 0
          • F022YF
            F022Y
            last edited by

            So doing some playing I notice the following the IP i get from a "what is my IP" lookup and what appears in the addresses on the interface are different.

            For example:- what is my ip = 188.74.x.x
            WAN interface on pfsense = 100.64.x.x

            My no-ip dynamic ip points at the 188 address so i'm guessing this is why the port forwarding is borked? I did some testing with a friend by opening ICMP to just his public IP and doing packet captures all i could see where 100.x addresses. Is this a case of chatting to my ISP?

            N stephenw10S 2 Replies Last reply Reply Quote 0
            • N
              netblues @F022Y
              last edited by

              @f022y You are behind carried grade nat.
              This is where 100.x is used for.
              Unless your new isp can switch you to "public" ip, nothing related to port forward will ever work.

              F022YF 1 Reply Last reply Reply Quote 1
              • F022YF
                F022Y @netblues
                last edited by

                @netblues Thank you for the reply, i had a horrible feeling that would be the case.

                J 1 Reply Last reply Reply Quote 0
                • J
                  Jarhead @F022Y
                  last edited by

                  @f022y CGNAT only applies to IPv4, see if they can get you on an IPv6 address.
                  Doubtful, but worth a try.

                  N 1 Reply Last reply Reply Quote 0
                  • N
                    netblues @Jarhead
                    last edited by

                    @jarhead one can get a tunneled ipv6 from hurricane, but the whole point is most probably irrelevant to the op.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      Jarhead @netblues
                      last edited by

                      @netblues said in Switched ISP, PPPoE to DHCP:

                      @jarhead one can get a tunneled ipv6 from hurricane, but the whole point is most probably irrelevant to the op.

                      No, what I meant was from his ISP. If they have IPv6 capabilities he wouldn't be behind the CGNAT.
                      Problem is, not many ISP's offer v6 yet.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator @F022Y
                        last edited by

                        @f022y said in Switched ISP, PPPoE to DHCP:

                        WAN interface on pfsense = 100.64.x.x

                        Yup, CGN. That will prevent any port forwards working. So likely the firewall rules are actually fine.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • F022YF
                          F022Y
                          last edited by

                          So got an email today from their support to confirm CGNat is used but i can buy a static IP for a monthly fee I see on their website they support IPv6 so asking about that.

                          N 1 Reply Last reply Reply Quote 0
                          • N
                            netblues @F022Y
                            last edited by

                            @f022y Getting a static ipv4 is your only viable option
                            Life with ipv6 only needs also some kind of nat upstream, if you are to be connected to the Internet as we know it.

                            Sad but true :)

                            F022YF 1 Reply Last reply Reply Quote 0
                            • F022YF
                              F022Y @netblues
                              last edited by

                              @netblues bugger. Annoyingly since discovering CGNat (i'll be honest never came across it in the UK must have been lucky) this explains a few things.

                              Since switching i've had strict NAT on my PS5 which i've not been able to work out, previously I would look at port forwarding to fix but obviously i now know why that didn't work.

                              1 Reply Last reply Reply Quote 0
                              • F022YF
                                F022Y
                                last edited by

                                So after a chat with my ISP they offered me a free public IP, all my rules work again!!

                                Thank you all for the help i'd never come across CGNat before. The more you know.

                                1 Reply Last reply Reply Quote 1
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.