• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Internet breakout

Scheduled Pinned Locked Moved Firewalling
8 Posts 4 Posters 534 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    smk
    last edited by Dec 12, 2022, 4:31 PM

    Hi

    Can someone please help me understand how to correctly configure pfsense to allow traffic from the yellow box (LAN) to the blue box (WAN). Currently I am not able to ping any internet address nor dns name. Neither of these work: ping 8.8.8.8 nor ping goole.com.

    51883a4b-af9b-4ba2-8c94-652f23ec563b-image.png

    Configuration:

    • eth1-4 on Mikrotik are in bridge mode
    • pfsense has a DHCP server enabled on LAN interface. PC1-3 are getting DHCP assignments
    • pfsense FW > Rules > LAN has a "Allow LAN to any rule"
      24cbfa27-e9b2-40bf-97b4-f33e8aa5967f-image.png
    • pfsense FW > NAT > Outbound Mode is set to "Automatic outbound NAT rule generation"
      9d5e5ee0-9030-4dd3-a294-66972bfd49c9-image.png
      What am I missing to enable traffic from PC1-3 access the internet?

    Thanks in Advance!

    R S 2 Replies Last reply Dec 12, 2022, 4:37 PM Reply Quote 0
    • R
      rcoleman-netgate Netgate @smk
      last edited by Dec 12, 2022, 4:37 PM

      1. Are there entries in the Firewall Log on pfSense that show the traffic being blocked?

      2. Have you run a packet capture on your LAN interface to see if the traffic is even getting to the pfSense?

      3. Have you put a dumb switch where your Mikrotik is to see if it's the configuration issue?
        3b) Are you running a CRS100-series or 300-series? Are you running it in SwitchOS? Mikrotik can be great hardware but the CRS100-series are routers only and not good switches... (ask me how I know).

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      M S 2 Replies Last reply Dec 12, 2022, 4:47 PM Reply Quote 1
      • M
        mer @rcoleman-netgate
        last edited by Dec 12, 2022, 4:47 PM

        Item #3 from @rcoleman-netgate is a good quick test; it's pretty much how most home offices are going to be set up (mine is).

        1 Reply Last reply Reply Quote 1
        • S
          smk @rcoleman-netgate
          last edited by Dec 15, 2022, 12:40 AM

          @rcoleman-netgate & @mer : Thank you for your response. Your pointers were very helpful in determining that "IPv4 Upstream gateway" was set on the LAN interface which caused the issue. My lack of knowledge on what that setting does.

          S 1 Reply Last reply Dec 15, 2022, 1:46 AM Reply Quote 0
          • S
            smk @smk
            last edited by Dec 15, 2022, 1:46 AM

            @smk : But DNS resolutions still not happening. Wondering why:
            95e33351-a42d-4973-9510-674f7404c63d-image.png

            As you can see, I have a DNS resolver running pointing to all network interfaces with outgoing network interface set to WAN. Would that not cause DNS queries to be forwarded to the upstream DNS server in the home network (which works BTW) and be resolved there?

            1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @smk
              last edited by SteveITS Dec 15, 2022, 1:57 AM Dec 15, 2022, 1:56 AM

              @smk Aren't the automatic outbound NAT rules missing a subnet? The source should include the LAN subnet, and not have the second two lines:
              ac67e9c9-8d75-4642-aa6d-0b06c481f800-image.png
              I would not expect to see outbound NATting for LAN.

              Edit: how it got that way while set to "automatic" is the confusing part to me. Was an interface removed?

              If you leave the DNS Resolver outgoing interfaces set to the default of All, it will "figure it out" for you.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              S 1 Reply Last reply Dec 15, 2022, 2:45 AM Reply Quote 1
              • S
                smk @SteveITS
                last edited by Dec 15, 2022, 2:45 AM

                @steveits Thank you for your response.

                Under System> Routing> Gateways, still had a legacy config with LAN gateway pointing to the upstream gateway that is accessible via WAN. That is not correct. As I just learnt, LAN interface should not have an upstream gateway. After removing the upstream gateway, now hosts are able to resolve DNS as well.

                The outbound NAT rules in the screenshot above (with the extra rules for LAN) were taken when the Upstream Gateway was incorrectly set for the LAN interfaces. Once I corrected that, mine looks just like what you posed - only has outbound rules for WAN (the outbound interface) and not LAN.

                S 1 Reply Last reply Dec 15, 2022, 2:50 AM Reply Quote 0
                • S
                  SteveITS Galactic Empire @smk
                  last edited by Dec 15, 2022, 2:50 AM

                  @smk Ah, that makes sense, thanks.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received