Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense setup question CGNAT

    Scheduled Pinned Locked Moved General pfSense Questions
    25 Posts 6 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Crossy2 @SteveITS
      last edited by Crossy2

      @SteveITS

      No worries, thx for taking your time to reply

      Unfortunately I canโ€™t make a drawing as I am not at home.

      But the situation is this currently

      WWW - CGNAT - ISP ROUTER - LAN

      And I want it to be

      WWW - CGNAT - ISP ROUTER - PFSENSE - LAN

      And the WAP could be placed like this

      WWW - CGNAT - ISP ROUTER - WAP - PFSENSE - LAN

      So the the WAP will be connected to a port on the ISP router and the WAN interface of the PFSENSE is also connected to a Port on the ISP router.

      Edit: will I need to setup some block/allow rules to prevent the WAP to access the LAN but the LAN to be able to access the WAP?

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Crossy2
        last edited by

        @Crossy2 A true AP will put those devices on the pfSense WAN network. They are all on the iSP router LAN.

        pfSense WAN blocks all incoming traffic by default.

        pfSense LAN has an allow all by default so can access devices in WAN.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        C 1 Reply Last reply Reply Quote 1
        • C
          Crossy2 @SteveITS
          last edited by Crossy2

          @SteveITS

          Thx again.

          Itโ€™s an asus router I still have I would like to use as AP for the inverters

          asus rt-n12

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Crossy2
            last edited by

            @Crossy2 If it has AP mode then the above applies. Some routers let you plug in only LAN and thus act like an AP. If it will only be a router then you can forward a port to your inverter on its LAN.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            C 1 Reply Last reply Reply Quote 1
            • C
              Crossy2 @SteveITS
              last edited by

              @SteveITS

              Yep it has I believe 3 modes and one of those is AP.

              I will do some testing and report back but could be a while as I am not at home due to personal circumstances but will report back.

              That option to place the AP there is a really great one as it also frees up a port on the Pfsense SG-1100 (I ordered one before I came to this forum, if I knew then what I know I would have ordered a 2100 ๐Ÿ˜‚๐Ÿ˜‰

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.