Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    pfSense can ping ISP gateway but not connect to internet

    General pfSense Questions
    5
    15
    389
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DominikHoffmann last edited by DominikHoffmann

      I have switched ISPs. I cannot get out to the internet from my LAN. My new ISP is Spectrum, but I am not thinking that this has anything to do with my troubles.

      I can ping the WAN gateway address:

      dominik@DominikMBP ~ % ping 47.227.192.1
      PING 47.227.192.1 (47.227.192.1): 56 data bytes
      64 bytes from 47.227.192.1: icmp_seq=0 ttl=254 time=6.944 ms
      64 bytes from 47.227.192.1: icmp_seq=1 ttl=254 time=25.989 ms
      64 bytes from 47.227.192.1: icmp_seq=2 ttl=254 time=7.132 ms
      64 bytes from 47.227.192.1: icmp_seq=3 ttl=254 time=7.688 ms
      

      The pfSense gateway has an IP address:
      Screenshot 2023-01-28 at 4.29.01 PM.png

      I am using the ISP’s DNS servers:

      209.18.47.61
      209.18.47.62
      

      The LAN firewall rules are alright, as well:
      Screenshot 2023-01-28 at 4.37.36 PM.png

      And, finally, when I connect my laptop directly to the cable modem through an Ethernet cable, the laptop is online without issues.

      The Spectrum support agent told me she could see my modem but not the router on my side of it, which she would expect to be able to see.

      What are things I might be missing?

      D NollipfSense 2 Replies Last reply Reply Quote 0
      • D
        DominikHoffmann @DominikHoffmann last edited by

        @dominikhoffmann: I have a tendency to answer my own questions. This may not quite be the answer, but may lead me there:

        Troubleshooting Network Connectivity in the Netgate Docs.

        I will report back with what I find, when I am back at my client’s on Monday.

        J 1 Reply Last reply Reply Quote 1
        • stephenw10
          stephenw10 Netgate Administrator last edited by

          If pfSense can ping the gateway but nothing beyond (even by IP) I'd suspect a bad or missing default route. Check Diag > Routes. If there's no default route go to Sys > Routing > Gateways and resave the WAN gateway.

          Steve

          D 1 Reply Last reply Reply Quote 1
          • J
            Jarhead @DominikHoffmann last edited by

            @dominikhoffmann
            If the pc can work then the modem has that MAC in is address table.
            Plug the router into the modem and power cycle the modem.

            D 1 Reply Last reply Reply Quote 1
            • NollipfSense
              NollipfSense @DominikHoffmann last edited by

              @dominikhoffmann said in pfSense can ping ISP gateway but not connect to internet:

              I am using the ISP’s DNS servers:

              Just to confirm whether pfSense is configured to use ISP's DNS?

              pfSense+ 22.01 Lenovo Thinkcentre M93P SFF Quadcore i7 Raid-ZFS 128GB-SSD 32GB-RAM PCI-dual Intel i350 NIC.

              D 1 Reply Last reply Reply Quote 1
              • D
                DominikHoffmann @Jarhead last edited by

                @jarhead: I had done that multiple times, every time I tried something different. That was not the issue.

                I had realized that changing devices on the LAN side of the modem required a restart of the modem. Why does it have to take that long to re-establish the connection with cable-based service?

                S 1 Reply Last reply Reply Quote 0
                • D
                  DominikHoffmann @NollipfSense last edited by

                  @nollipfsense: A reverse lookup of 209.18.47.61 results in dns-cac-lb-01.rr.com, and 209.18.47.62 brings up dns-cac-lb-02.rr.com.

                  1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS @DominikHoffmann last edited by

                    @dominikhoffmann said in pfSense can ping ISP gateway but not connect to internet:

                    I had realized that changing devices on the LAN side of the modem required a restart of the modem. Why does it have to take that long to re-establish the connection with cable-based service?

                    Some tie one MAC address to the account and disallow others. Restarting is generally a fast way to clear it. Alternatively MAC spoofing often works.

                    I had a situation recently where the data center forgot to allow outbound routing even though they configured inbound. (On a second public subnet). It could ping the gateway but a traceroute out further returned no response from the gateway.

                    Steve

                    Only install packages for your version, or risk breaking it. If yours is older, select it in System/Update/Update Settings.
                    When upgrading, let it finish; do not reboot early. Allow 10-15 minutes, or more depending on packages and device speed.

                    D 1 Reply Last reply Reply Quote 2
                    • D
                      DominikHoffmann @SteveITS last edited by

                      @steveits said in pfSense can ping ISP gateway but not connect to internet:

                      Some tie one MAC address to the account and disallow others. Restarting is generally a fast way to clear it. Alternatively MAC spoofing often works.

                      I tried that, to no avail.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10
                        stephenw10 Netgate Administrator last edited by

                        If pfSense can ping it's gateway and that gateway is some upstream public IP then it's nothing to do with the modem or MAC addresses.
                        If it was a DNS issue then pfSense could still ping, say, 8.8.8.8.

                        Did you check for a correct default route as I suggested?

                        D 1 Reply Last reply Reply Quote 1
                        • D
                          DominikHoffmann @stephenw10 last edited by

                          @stephenw10: I can’t physically get to it until tomorrow. I wish, I could check on that remotely, but then I wouldn’t have this problem, because the gateway would already be online.

                          1 Reply Last reply Reply Quote 0
                          • D
                            DominikHoffmann @stephenw10 last edited by DominikHoffmann

                            @stephenw10: The gateway configuration was the issue.

                            In System → Routing → Gateways I had this
                            Screenshot 2023-01-30 at 1.14.02 PM.png

                            When I changed the setting to this
                            Screenshot 2023-01-30 at 1.14.19 PM.png
                            it started working immediately. How could I have been thinking that “Automatic” would automatically select the correct gateway.

                            1 Reply Last reply Reply Quote 0
                            • stephenw10
                              stephenw10 Netgate Administrator last edited by

                              It normally would, it may have lost it for some reason. Did you check Diag > Routes?

                              Setting anything there re-creates the default route even if you had just resaved that page without making any changes.

                              Steve

                              D 1 Reply Last reply Reply Quote 2
                              • D
                                DominikHoffmann @stephenw10 last edited by

                                @stephenw10: I admit, I didn’t pursue it any further, after setting it explicitly it started working. This is what it shows now:

                                Screenshot 2023-01-31 at 12.07.33 AM.png

                                … and I honestly don’t at all know, what I can diagnose from that information.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10
                                  stephenw10 Netgate Administrator last edited by

                                  You can see it has a default route at the top of the table and I would guess that it would would not have shown that before. It might show in logs still but it probably won't tell you anything.
                                  If it happens again check the routing table before making any gateway changes. I doubt it will though.

                                  Steve

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post