Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No Internet

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 970 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Bert 0
      last edited by

      Hello,

      I have anSG-1100. It has been working perfectly fine for the last year or so. Then I moved my office. My ISP remained the same but I had to change from fiber to co-ax. No big deal but now I have no internet access. I was able to ping external routers but tracert went a max of 4 hops and then failed. Of course my ISP is blaming the firewall but I haven’t changed any settings from when it was running in my old office so I can’t see it being he router. I did connect a computer directly to the modem through a switch and the behavior remained exactly the same. The last tech “reprovisioned” the modem and now I can’t even ping the firewall’s default gateway.

      My question is: what have I missed? Is there a setting in the 1100 I should be changing?

      Very frustrated:-(

      Bert

      bingo600B JKnottJ 2 Replies Last reply Reply Quote 0
      • bingo600B
        bingo600 @Bert 0
        last edited by bingo600

        @bert-0 said in No Internet:

        I did connect a computer directly to the modem through a switch and the behavior remained exactly the same.

        If your PC can't ping out on the internet, and your SG-1100 can't too.
        The arrow clearly points towards the ISP or Modem.

        Well techically it could be your switch too , but .....
        Does the SG-1100 connect directly to the modem , or also via a switch ?

        What did you ping ?
        8.8.8.8 or 1.1.1.1 or ???

        Don't ping by dns name, when doing "low level" debugging , but by ip address.

        /Bingo

        If you find my answer useful - Please give the post a 👍 - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

        B 1 Reply Last reply Reply Quote 0
        • B
          Bert 0 @bingo600
          last edited by Bert 0

          @bingo600 Any ping on the internet like 8.8.8.8 fails. When I did a tracert to 8.8.8.8, it only managed 4 hops but I could successfully ping the last reported router. Since the lack of internet causes my DNS to fail, tracert is unable to resolve the router ip addresses to names so I have no idea if the last router in the list belongs to my ISP or if it is a public router on the internet.

          Bert

          OnEdit: I should have mentioned that all of the above was true before the last tech reprovisioned my modem. Now, I can’t even ping my external DG

          bingo600B 1 Reply Last reply Reply Quote 0
          • bingo600B
            bingo600 @Bert 0
            last edited by bingo600

            @bert-0
            If you give the ip(s) , i'll look it up for you

            Ahh . Now no connection at all .. Sorry to hear.
            But that must make "Good case at the ISP"

            Drop mentioning pfSense during ISP conversations , just use the PC (enable firewall)

            That would make it somewhat harder for them to point at the "complicated firewall" as the cause.

            If you find my answer useful - Please give the post a 👍 - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

            B 1 Reply Last reply Reply Quote 0
            • B
              Bert 0 @bingo600
              last edited by

              @bingo600 The router ip was 24.244.60.53

              bingo600B 1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @Bert 0
                last edited by

                @bert-0 said in No Internet:

                24.244.60.53

                Here's the info for that IP

                xxx:~$ host 24.244.60.53
                Host 53.60.244.24.in-addr.arpa. not found: 3(NXDOMAIN)
                
                
                xxx:~$ whois 24.244.60.53
                
                #
                # ARIN WHOIS data and services are subject to the Terms of Use
                # available at: https://www.arin.net/resources/registry/whois/tou/
                #
                # If you see inaccuracies in the results, please report at
                # https://www.arin.net/resources/registry/whois/inaccuracy_reporting/
                #
                # Copyright 1997-2022, American Registry for Internet Numbers, Ltd.
                #
                
                
                NetRange:       24.244.0.0 - 24.244.63.255
                CIDR:           24.244.0.0/18
                NetName:        SHAW-COMM
                NetHandle:      NET-24-244-0-0-1
                Parent:         NET24 (NET-24-0-0-0-0)
                NetType:        Direct Allocation
                OriginAS:       
                Organization:   Shaw Communications Inc. (SHAWC-1)
                RegDate:        2000-02-04
                Updated:        2012-03-20
                Comment:        ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
                Ref:            https://rdap.arin.net/registry/ip/24.244.0.0
                
                
                OrgName:        Shaw Communications Inc.
                OrgId:          SHAWC-1
                Address:        Suite 800
                Address:        630 - 3rd Ave. SW
                City:           Calgary
                StateProv:      AB
                PostalCode:     T2P-4L4
                Country:        CA
                RegDate:        2003-07-09
                Updated:        2014-06-11
                Ref:            https://rdap.arin.net/registry/entity/SHAWC-1
                
                
                OrgAbuseHandle: SHAWA-ARIN
                OrgAbuseName:   SHAW ABUSE
                OrgAbusePhone:  +1-403-750-7420 
                OrgAbuseEmail:  internet.abuse@sjrb.ca
                OrgAbuseRef:    https://rdap.arin.net/registry/entity/SHAWA-ARIN
                
                OrgTechHandle: ZS178-ARIN
                OrgTechName:   IP Admin
                OrgTechPhone:  +1-403-648-5711 
                OrgTechEmail:  ipadmin@sjrb.ca
                OrgTechRef:    https://rdap.arin.net/registry/entity/ZS178-ARIN
                
                
                #
                # ARIN WHOIS data and services are subject to the Terms of Use
                # available at: https://www.arin.net/resources/registry/whois/tou/
                #
                # If you see inaccuracies in the results, please report at
                # https://www.arin.net/resources/registry/whois/inaccuracy_reporting/
                #
                # Copyright 1997-2022, American Registry for Internet Numbers, Ltd.
                #
                
                xxx:~$ 
                
                

                If you find my answer useful - Please give the post a 👍 - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                B 1 Reply Last reply Reply Quote 0
                • B
                  Bert 0 @bingo600
                  last edited by

                  @bingo600 Thank you. Shaw is my ISP and I suspected that the router was theirs but, without internet access, I couldn’t prove it.

                  They have scheduled a tech to come on site tomorrow so the can blame the firewall face to face. I just wanted to verify that I didn’t miss something.

                  JKnottJ 1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @Bert 0
                    last edited by

                    @bert-0

                    If it manages 4 hops, it's not your firewall. Regardless, you can test by connecting your computer directly to the modem to see if that works. One thing I've noticed is ISPs are all to quick to blame a customers firewall, without even looking at the problem.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    B 1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott @Bert 0
                      last edited by

                      @bert-0 said in No Internet:

                      They have scheduled a tech to come on site tomorrow so the can blame the firewall face to face.

                      Make sure he tries with his own computer, so that your gear is entirely out of the picture. I had a problem with IPv6 with my ISP a few years ago. Their network guy refused to even look at the problem because I had my own firewall, even though my next door neighbour had the same problem using only the modem in gateway mode. Also, I had identified the failing equipment in the head end by host name. I was able to get a senior tech out and his own modem & computer failed, so he went back to the office and connected to 4 different CMTS. They all worked, except the one I was connected to and had identified. The problem was resolved shortly after that.

                      BTW, since you're on Shaw, you should have IPv6 available.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      B 1 Reply Last reply Reply Quote 0
                      • B
                        Bert 0 @JKnott
                        last edited by

                        @jknott I tried in vain to explain that none of the Shaw routers are on my network and, therefore, the outgoing traffic was traversing both my firewall and the modem. No luck :-(

                        Right now, I would settle for an IPv2 address if it would get me on the internet. I'd prefer to not complicate things more by introducing to idea of an IPv6 address. If they don't know how to read the output of a tracert or what a router is, I suspect that IPv6 would cause their heads to explode. :-(

                        Bert

                        1 Reply Last reply Reply Quote 0
                        • B
                          Bert 0 @JKnott
                          last edited by

                          @jknott BTW: I am new to CMTs. How can you tell if a device you hit is a CMT or not?

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @Bert 0
                            last edited by

                            @bert-0 said in No Internet:

                            BTW: I am new to CMTs. How can you tell if a device you hit is a CMT or not?

                            A CMTS is the device you connect to at the cable company head end. I used Wireshark to examine the DHCPv6-PD packets and saw the error message that identified, by host name, the failing system.

                            Anyway, as I said, try connecting a computer to your modem directly. And if a tech comes make sure he can connect with his own equipment.

                            BTW, have him try test-ipv6.com to show you everything is working properly. You should get 10/10.

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.