Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN with external addresses not working

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 124 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Direwolf
      last edited by Direwolf

      My router WAN address is 144.160.10.228/24
      ISP Gateway address is 144.160.10.1

      LAN1 10.10.4.1/24 VLAN1
      LAN2 144.160.9.200/29 VLAN2
      LAN3 192.168.1.1/24 VLAN3

      As things are set up, LAN1 and LAN3 work as expected. The nodes can all reach everything on LAN1 and LAN3, and connect to the internet through the ISP gateway.

      LAN2 behaves strangely. The nodes on LAN2 can't reach the outside, and LAN1 and LAN3 can't reach any of the nodes on LAN2. LAN2 addresses are static and assigned by the ISP, and worked when I had my Cisco router in use.

      I've tried setting the LAN2 interface to 144.160.9.201, and also with no IP address. I can't set the IPv4 upstream gateway to the ISP gateway because it's outside the scope of the LAN2 subnet. I added a static route for 144.160.9.200/29 to the WAN gateway 144.160.10.1. Pinging a node on the LAN2 network gives this result:

      PING 144.160.9.206 (144.160.9.206): 56 data bytes
      92 bytes from 144.160.10.228: Time to live exceeded
      Vr HL TOS Len ID Flg off TTL Pro cks Src Dst
      4 5 00 0054 7b80 0 0000 01 01 8224 144.160.10.228 144.160.9.206

      The firewalls are setup to pass the traffic. No NAT is necessary on LAN2 as all addresses are statically assigned.

      How can I set this up so LAN2 works properly, reachable from outside and inside? What should the gateway address be on the devices on LAN 2?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Direwolf
        last edited by

        @Direwolf

        https://docs.netgate.com/pfsense/en/latest/recipes/route-public-ip-addresses.html

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        D 1 Reply Last reply Reply Quote 0
        • D
          Direwolf @johnpoz
          last edited by

          @johnpoz I think that has everything I need. Thanks! I need t get more familiar with the documentation.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.