Connecting pfSense Web Interface GUI from different home LAN
-
Hello folks .
My home network is separate with two LAN's .The first (native) LAN are belong to the house owners in the first floor of the house laying under the ISP router. The second LAN is mine and is located at the second floor and it segmented and separated by the pfSense .The first (native) LAN is 10.100.102.0/24
The second (pfsense) LAN is 192.168.1.0/24
pfSense WAN is 10.100.102.111I need to be able to connect to the pfSense Web GUI from one of the hosts in the first LAN .
How do i do that ? is it port forwarding ? is it by VPN ? its all inside my house so vpn connection sounds a bit excessive, doesn't it?im sure its pretty simple sorry im just new to networking and firewalling hahahaha
-
@johnytb would just a firewall rule.. if you allow 192.168.1.0 to either pfsense IP on 192.168.1.x or your lan IP or if you have a any any rule than yeah you would be able to connect.
Problem could come from if you do policy routing.. But unless you are blocking traffic your 2nd lan should be able to talk to really any IP on pfsense.
What rules do you have on this 2nd lan? Do you have any floating rules, do you do any policy routing?
first native lan normally has a any any rule by default so you should be able to access no problem, and there is even a anti lockout rule to allow access to pfsense webgui.. You don't have 2 pfsense boxes do you?
Oh - you want to connect to pfsense wan IP from your isp lan, which is pfsense wan - just create a rule on pfsense wan to allow access to the port your gui is on.
-
@johnytb said in Connecting pfSense Web Interface GUI from different home LAN:
The first (native) LAN is 10.100.102.0/24
The second (pfsense) LAN is 192.168.1.0/24
pfSense WAN is 10.100.102.111That implies the WAN is in the LAN subnet. Do you mean pfSese just has two interfaces and the "WAN" in this case it just connected to a private subnet from an existing router?
But, yes, you just need a firewall rule to allow access. And makes sure 'block private networks' is not set on the WAN interface config.
-
internet -- isp device - 10.100.102.0/24 -- .111 pfsense --- 192.168.1.0/24
That's what I think he means to say.