Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Cannot reach Vigor 2962 from vlans behind pfSense

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 2 Posters 551 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AlanesiA Offline
      Alanesi
      last edited by

      Hello,

      I have been using pfSense for a long time, but this issue confused me.

      So I have a new Vigor 2962 router.

      Vigor 2962 is connected as a WAN to my pfSense.
      PfSense is connected to LAN port 6 on Vigor 2962; both ports are on the same subnet (20.1.10.X)

      On pfSense, I have multiple VLANs.

      WAN port, gateway, and firewall are configured correctly. (because I have 2 WAN connections on pfSense, one is working fine on a Huawei router from the ISP).

      The issue:

      1. PfSense can see Vigor 2962 and is showing online, but the VLANs behind PfSense cannot see Vigor 2962.
      2. Vigor 2962 can see PfSense, but cannot see the VLANs behind PfSense (I added a static route on Vigor 2962, and it worked).
      3. VLANs can ping 20.1.10.2 on pfSense, but cannot ping 20.1.10.1 on Vigor 2962.

      I really appreciate any help you can provide.

      stephenw10S 1 Reply Last reply Reply Quote 0
      • stephenw10S Online
        stephenw10 Netgate Administrator @Alanesi
        last edited by

        @Alanesi said in Cannot reach Vigor 2962 from vlans behind pfSense:

        VLANs can ping 20.1.10.2 on pfSense, but cannot ping 20.1.10.1 on Vigor 2962.

        Sounds like a missing outbound NAT rule. The Vigor likely blocks connections from outside it's own subnet.

        If the WAN is configured statically does it have a gateway defined on the interface itself? That should trigger an auto-outbound NAT rule.

        Of course if outbound NAT is not set to automatic you would need to add a rule.

        AlanesiA 1 Reply Last reply Reply Quote 0
        • AlanesiA Offline
          Alanesi @stephenw10
          last edited by Alanesi

          @stephenw10
          Thank you for your response

          Just one thing to add: there was a different WAN connection before, and it worked fine until we switched to this one. So on the same interface, I only changed the name, IP address, and added the new gateway.

          Kindly check the pics below

          969d8e96-12fb-484e-81f6-28ff1edc243b-image.png

          45917860-2525-48aa-8fc7-e2a74f670694-image.png

          1 Reply Last reply Reply Quote 0
          • stephenw10S Online
            stephenw10 Netgate Administrator
            last edited by

            Hmm, OK that looks good.

            Are you using policy based routing? You could be forcing traffic via the other WAN from LAN side clients.

            I assume pfSense itself can ping 20.1.10.1?

            AlanesiA 1 Reply Last reply Reply Quote 0
            • AlanesiA Offline
              Alanesi @stephenw10
              last edited by

              @stephenw10

              Yes, pfSense can ping 20.1.10.1.

              All vlans configurations are set default.

              d3a803ef-a736-4122-a023-108b8ad8fb0c-image.png

              1 Reply Last reply Reply Quote 0
              • stephenw10S Online
                stephenw10 Netgate Administrator
                last edited by

                But do you have firewall rules with a gateway set to route traffic via a articular WAN?

                Normally those would be bypassed for a locally connected subnet like this but that can also be disabled.

                AlanesiA 1 Reply Last reply Reply Quote 0
                • AlanesiA Offline
                  Alanesi @stephenw10
                  last edited by

                  @stephenw10

                  bebd3d76-5c5c-4702-8510-a48aeecabd57-image.png

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Online
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, then I would start a continuous ping from client in the 'data' subnet to the Vigor then check the state table in pfSense. You should see a state on DATA and a state with NAT on WAN_5G.

                    If those look good try a pcap on WAN_5G for that traffic to be sure it's actually leaving there. The monitoring pings will also show but should be distinguishable.

                    AlanesiA 2 Replies Last reply Reply Quote 0
                    • AlanesiA Offline
                      Alanesi @stephenw10
                      last edited by

                      @stephenw10 OK I'll check it.

                      1 Reply Last reply Reply Quote 0
                      • AlanesiA Offline
                        Alanesi @stephenw10
                        last edited by

                        @stephenw10 said in Cannot reach Vigor 2962 from vlans behind pfSense:

                        pcap

                        This is what I got this

                        9073874d-db4c-4adb-816b-6f457e5bb236-image.png

                        ce6b1963-4090-4d3a-8001-ec875b69d8a8-image.png

                        ae3a5997-0f93-4b9a-b8fa-2bb1cf66dd1b-image.png

                        3d80627e-97bc-4f19-88a8-5bdfc8ab06b7-image.png
                        Looks like it does not leave!

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Online
                          stephenw10 Netgate Administrator
                          last edited by

                          So that pcap was taken on WAN_5G? If so it looks like it leaves there without being NAT'd for some reason.

                          If you filter the states for all interfaces do you see the state for that on WAN_5G? Does it show NAT on the state?

                          The other curious thing there is that the monitoring pings, that you see are working, are coming from 20.1.10.5. Is that a new IP you're using on WAN_5G?

                          Those pings are probably leaving via the wrong interface. Potentially something defined in IPSec could be grabbing it.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                          Privacy Policy · Cookie Policy