Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Cannot connect to LAN servers apart from the pfSense LAN Interface IP address

    Scheduled Pinned Locked Moved OpenVPN
    8 Posts 4 Posters 286 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dave1968
      last edited by

      Just revisiting pfSense again after a few years.

      WAN Interface IP is 192.168.3.100
      LAN Interface IP is 192.168.3.100

      I've followed many different instructions and the problem I have is I can connect with a client and can PING 192.168.4.100 but not any other clients (VM's) on my LAN network such as 192.168.4.101 etc. It's not just ping, it's no go for HTTP/HTTPS etc

      Doing a "7" from the pfSense console allows me to ping any of my LAN IP's

      Firewall rules as setup by the wizard are all ok and in place.

      Do I need a NAT rule for this to work?

      Dave

      the otherT 1 Reply Last reply Reply Quote 0
      • the otherT Offline
        the other @dave1968
        last edited by

        @dave1968 said in Cannot connect to LAN servers apart from the pfSense LAN Interface IP address:

        Just revisiting pfSense again after a few years.

        WAN Interface IP is 192.168.3.100
        LAN Interface IP is 192.168.3.100

        Are you sure?
        WAN and LAN interface both with same IP?? Looks wrong, feels wrong...probably is wrong. :) Just a typo or your actual settings?

        the other

        pure amateur home user, no business or professional background
        please excuse poor english skills and typpoz :)

        D 1 Reply Last reply Reply Quote 0
        • D Offline
          dave1968 @the other
          last edited by dave1968

          @the-other

          sorry yes - a typo, have rectified. LAN is 192.168.4.100

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @dave1968
            last edited by johnpoz

            @dave1968 pfsense has nothing to do with devices on the same network talking to each other, ie if your device on the 192.168.4 network pinging another device on the 192.168.4 network.

            Your going to have to give us more to go on.. Are you vpning into pfsense from remote or something?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 26.03 | Lab VMs 2.8.1, 26.03

            D 1 Reply Last reply Reply Quote 0
            • D Offline
              dave1968 @johnpoz
              last edited by

              @johnpoz

              I'm saying my internet connected client ( 10.8.0.x) can ping my LAN address for the pfSense server which is 192.168.4.100 - but cannot ping or connect with any protocol to other addresses on the 192.168.4.x network.

              In the setup the LAN subnet for the OpenVPN clients is 192.168.4.0/24 which should allow it.

              The route print (as done in the Window's client, seems valid.

              GertjanG johnpozJ 2 Replies Last reply Reply Quote 0
              • GertjanG Offline
                Gertjan @dave1968
                last edited by

                @dave1968 said in Cannot connect to LAN servers apart from the pfSense LAN Interface IP address:

                my internet connected client ( 10.8.0.x)

                What are the firewall rules on the OpenVPN interface ?

                @dave1968 said in Cannot connect to LAN servers apart from the pfSense LAN Interface IP address:

                In the setup the LAN subnet for the OpenVPN clients is 192.168.4.0/24 which should allow it.

                That rule will allow traffic from LAN device (192.168.4.1 => 254) - to enter the LAN interface.
                Your OpenVPN (a server, right ? ) connected devices will use their own interface ( 10.8.0.x ) and their own firewall rule(s) for that interface.

                No "help me" PM's please. Use the forum, the community will thank you.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator @dave1968
                  last edited by

                  @dave1968 said in Cannot connect to LAN servers apart from the pfSense LAN Interface IP address:

                  but cannot ping or connect with any protocol to other addresses on the 192.168.4.x network.

                  And do these other devices have firewalls? Just because you route the traffic through pfsense and pfsense allows it, doesn't mean their firewalls do.

                  Do these devices you are trying to ping even use pfsense as their gateway.

                  Is the mask for their networks /24, or something else. For example if the device your trying to ping has a /16 - then no they wouldn't answer because they would think 192.168.8 is local for them.

                  Those are 3 reasons off the top of my head.. Like I said your going to have to provide more info.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 26.03 | Lab VMs 2.8.1, 26.03

                  1 Reply Last reply Reply Quote 0
                  • the otherT Offline
                    the other
                    last edited by

                    okay,
                    thought it might be just a typo...
                    Is your openVPN server running on pfsense itself?
                    What are your rules for the openVPN Interface?
                    Your openVPN tunnel IP range is 10.8.0.0/24 (?)), so your vpn client gets some out of there...
                    As @Gertjan said: make sure your openVPN inteface has the rules needed to ping and reach your LAN (192.168.4.0/24)...
                    Also as @johnpoz said...do you have your vms and servers and other stuff behind another firewall? VMs i.E with proxmox server and there firewall active? NAS running with its own firewall active? Then go there and allow either your VPN tunnel net or (better imho) give your VPN client a static IP (iE 10.8.0.2/24) and allow just that one...(and others, if needed).
                    :)

                    the other

                    pure amateur home user, no business or professional background
                    please excuse poor english skills and typpoz :)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.