Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static route

    Scheduled Pinned Locked Moved Russian
    18 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by Antibiotic

      Please, what is going wrong?

      pfSense IP 192.168.10.1
      WIFI router IP 192.168.10.10
      WIFI router LAN IP 192.168.40.1

      I want to switch OFF NAT on WIFI router and pass traffic to pfSense ( pfSense NAT in manual mode)
      Screenshot_1-4-2024_165216_192.168.10.1.jpeg Screenshot_1-4-2024_165239_192.168.10.1.jpeg

      I'm understood that need to make rule on NAT outbound , but no any idea which rule and where. You can right in russian, for this moment don't have russian keyboard.
      Screenshot_1-4-2024_17057_192.168.10.1.jpeg Screenshot_1-4-2024_1705_192.168.10.1.jpeg

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Antibiotic
        last edited by

        @Antibiotic
        Are you sure, that the Wifi router doesn't nat?
        In this case pfSense wouldn't see the IPs behind in upstream traffic.

        Yes, you need to manually add an outbound NAT rule on WAN for the subnet behind the Wifi router.
        Just copy a WAN rule, e.g. the one for 192.168.30.0/24 and change the source network to 192.168.40.0/24.
        If you want to run IPSec on the wifi devices you also need a rule for ISAKMP with static port 500.

        BTW: There is no need to have the outbound NAT in manual mode. Hybrid mode should work fine for you.

        A 2 Replies Last reply Reply Quote 0
        • A
          Antibiotic @viragomann
          last edited by Antibiotic

          @viragomann But except NAT rule, the rest rules is correct? regarding my IP examples? First screenshot with static route gateway?

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @Antibiotic
            last edited by

            @Antibiotic
            The static route is correct.
            But the firewall rules will only allow internet access if the Wifi router does NAT.
            If not, you have to add a pass rule for 192.168.40.0/24.

            A 3 Replies Last reply Reply Quote 0
            • A
              Antibiotic @viragomann
              last edited by

              @viragomann Switched OFF NAT on WIFI router and get this rule on NAT:
              Screenshot_2-4-2024_203246_192.168.10.1.jpeg
              Start working))) Can me switch OFF also DCHP server on WIFI router?

              pfSense plus 24.11 on Topton mini PC
              CPU: Intel N100
              NIC: Intel i-226v 4 pcs
              RAM : 16 GB DDR5
              Disk: 128 GB NVMe
              Brgds, Archi

              V 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @viragomann
                last edited by

                @viragomann Second question, how to set permanent IP for WIFI router, its going via DCHP lease of pfSense?
                Lets say , have for this ethernet point DCHP range 192.168.10.10-192.168.10.20, but sometimes WIFI router changing IP from 192.168.10.10 to other!

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • A
                  Antibiotic @viragomann
                  last edited by

                  @viragomann What i have now in gateway status on main, is it normally?
                  Screenshot_2-4-2024_204242_192.168.10.1.jpeg

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Antibiotic
                    last edited by

                    @Antibiotic said in Static route:

                    Can me switch OFF also DCHP server on WIFI router?

                    Depends on the router, but as far as I remember, I read, that this is not possible.
                    Why want you do this? Do you want pfSense to do DHCP for the wifi?
                    If so the wifi router would need relays DHCP requests, and I think, it's not capable of this.

                    If you want to pfSense to administer the wifi, best practice would be to set the wifi router into AP mode. I guess, this should be possible.

                    Second question, how to set permanent IP for WIFI router, its going via DCHP lease of pfSense?

                    Go to Status > DHCP leases, find its entry and hit the "add static mapping" action button. State an IP of your choice for it. Remember that the IP has to be outside of the DHCP range.

                    The gateway offline indicates, that the device is not responding to pings. Go to the gateway settings and disable the monitoring.

                    A 1 Reply Last reply Reply Quote 0
                    • A
                      Antibiotic @viragomann
                      last edited by

                      @viragomann I mean, it's no any conflicts if pfSense as main will do NAT but WIFI router will do DCHP for local subnet behind this router but not pfSense?

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @Antibiotic
                        last edited by

                        @Antibiotic
                        No.

                        A 1 Reply Last reply Reply Quote 0
                        • A
                          Antibiotic @viragomann
                          last edited by Antibiotic

                          @viragomann Ok , thank you my friend for an assistance!)))) Have a good day! All now, looks working)))

                          pfSense plus 24.11 on Topton mini PC
                          CPU: Intel N100
                          NIC: Intel i-226v 4 pcs
                          RAM : 16 GB DDR5
                          Disk: 128 GB NVMe
                          Brgds, Archi

                          1 Reply Last reply Reply Quote 0
                          • A
                            Antibiotic @viragomann
                            last edited by Antibiotic

                            @viragomann said in Static route:

                            ISAKMP

                            But if me planning to use OpenVPN on WFI router, do need to create any more rules? in case of NAT will disable on WIFI router?or its only for IPsec

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            V 1 Reply Last reply Reply Quote 0
                            • V
                              viragomann @Antibiotic
                              last edited by

                              @Antibiotic
                              This rule is only for IPSec. It needs a static outbound port, so a rule is required to achieve this.

                              Your current rule set on the wifi interface allows any port to any destination in the internet anyway. So there is no additional rule needed.

                              Consider that it also allows access to the LAN. Maybe this is not desired and you want to block it.

                              A 2 Replies Last reply Reply Quote 0
                              • A
                                Antibiotic @viragomann
                                last edited by Antibiotic

                                @viragomann said in Static route:

                                Consider that it also allows access to the LAN. Maybe this is not desired and you want to block it.

                                Can you suggest rule example for this? Have a dedicated NIC for WIFI router connected to pfSense ( pfSense have 4th NIC's and all home network on different NIC's of pfSense)

                                pfSense plus 24.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                V 1 Reply Last reply Reply Quote 0
                                • A
                                  Antibiotic @viragomann
                                  last edited by Antibiotic

                                  @viragomann Also have an option on WAN page of WIFI router (Forward local domain queries to upstream DNS) Upstream DNS my pfSense. Is it better to set ON this option or does not matter? in case of NAT doing pfSense!

                                  pfSense plus 24.11 on Topton mini PC
                                  CPU: Intel N100
                                  NIC: Intel i-226v 4 pcs
                                  RAM : 16 GB DDR5
                                  Disk: 128 GB NVMe
                                  Brgds, Archi

                                  1 Reply Last reply Reply Quote 0
                                  • V
                                    viragomann @Antibiotic
                                    last edited by

                                    @Antibiotic
                                    I use an RFC 1918 alias, which I had add all private network ranges to.
                                    128232e0-2184-4ce9-8430-cee9aee2e74b-grafik.png

                                    Add a block or reject rule and use this alias as destination. Put this rule above of the allow-any rule.

                                    Also have an option on WAN page of WIFI router (Forward local domain queries to upstream DNS) Upstream DNS my pfSense. Is it better to set ON this option or does not matter?

                                    Seems to apply to local domains only. This might assume, that you have domains configured on the router.

                                    If it's possible, I would set pfSense as DNS in the DHCP settings of the wifi router, so that the devices send requests directly to pfSense.

                                    A 2 Replies Last reply Reply Quote 0
                                    • A
                                      Antibiotic @viragomann
                                      last edited by

                                      @viragomann Ah, thank you

                                      pfSense plus 24.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      1 Reply Last reply Reply Quote 0
                                      • A
                                        Antibiotic @viragomann
                                        last edited by

                                        @viragomann Could you please assist with OpenVPN, don't understanding where is my mistake with settings?
                                        https://forum.netgate.com/post/1161108

                                        pfSense plus 24.11 on Topton mini PC
                                        CPU: Intel N100
                                        NIC: Intel i-226v 4 pcs
                                        RAM : 16 GB DDR5
                                        Disk: 128 GB NVMe
                                        Brgds, Archi

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.