Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    New PF Sense Setup with Netgear R8000 with Tomato

    Scheduled Pinned Locked Moved General pfSense Questions
    27 Posts 4 Posters 7.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      Builder
      last edited by

      Hello,

      I will do my best to lay out what I have completed for anyone that is able to assist in this manner for me please as I am very green to this firewall and hoping that someone has an idea on a tweak that can get things working.
      Thank you.

      I just purchased the FW4C with the core boot installed from PF sense directly and have followed Michael Bazzels instructions to the tee in setting it up from his book extreme privacy 5th edition.

      Everything is working now - vpn working now etc.
      The only setting that wasn't the same that he talked about in changing only had the option of selecting default.

      Not the attached pictures from his instructions that could not be changed. I am not sure if this is a big deal or not because it is working or maybe it is a necessary thing? Not sure because my next part of the conversation will talk about using my router.

      See attached images so far before we carry on to the next part.
      Note I am referring to the penciled marked ones at the bottom of each image as ones noted that you are suppose to change to those in which un able to - use default.
      PS - I am using version 2.7.2 release as mentioned in the book
      Instruction 1 of 2.jpg

      stephenw10S 1 Reply Last reply Reply Quote 0
      • B Offline
        Builder
        last edited by

        Continued with 2nd photo from conversation - Instruction 2 of 2.jpg.jpg

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          Builder @Builder
          last edited by

          Now next part of the conversation - so my isp router/modem that I have been using since before getting this firewall was already setup in bridge mode from the isp provider in advance as I have been using Netgear Router 8000 with Tomato Firmware successfully for years as the support is still there today.

          In my router I have 2 vpn profiles setup one for proton and one for nord and can select which ever wifi selection for those.
          I also have 2 other ports non vpn to choose from as well.With my current setup prior to the introduction of the new firewall - works absolutely perfect.

          Now I connected my firewall and then my router as mentioned in the book and everything works on the router - even internet. Except now when I want to connect wirelessly I am unable to do so?
          I realize that there may be an addtional change needed now in the router and I am not sure what that is to be able to use my current router still?
          I am thinking that maybe it is the dns settings in the router possibly as they are set on stubby along with cloudfare and quad9 as noted in the attached pictures. On the firewall I have used Michaels dns as he mentioned which are different. I am hoping I am I am making some sense. See additional photos from router. Tomato On R8000 Firmware Version.png tomato dns 1 of 4.png Tomato dns 2 of 4.png tomato dns 3 of 4.png tomato dns 4 of 4.png

          B 1 Reply Last reply Reply Quote 0
          • B Offline
            Builder @Builder
            last edited by

            I am not an expert in any means and feel free to email me if it is easier for any steps you may have - justicesl@protonmail.com - thank you

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator @Builder
              last edited by

              @Builder said in New PF Sense Setup with Netgear R8000 with Tomato:

              I just purchased the FW4C with the core boot installed from PF sense directly

              I will just point out that that device is probably a Protectli so definitely not from us dircetly. But that aside.....

              You are running the Tomato firmware on the ISP supplied router? Which is upstream of pfSense and in bridge mode?
              I would not expect to be able to use it's wi-fi if it's bridged.

              B 1 Reply Last reply Reply Quote 0
              • B Offline
                Builder @stephenw10
                last edited by

                @stephenw10 - PF Sense sent me to this forum?

                The router is my separate router and not the isp - I only have the modem/router combo from them and it is in bridge mode to allow me to use my separate router.

                The firewall would not have worked if it wasn't in bridge mode.

                Hope that clarifies things and hope you have any additional insight.

                Thank you

                B 1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Yes the pfSense software has a link to the support forum, here. But that hardware is a 3rd party seller. Nothing to do with us.

                  Ok so the tomato router is behind pfSense now? I'm unclear how you have these connected.

                  1 Reply Last reply Reply Quote 0
                  • B Offline
                    Builder @Builder
                    last edited by

                    Hello,

                    Yes it is connected in the lan port of the firewall.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      Hmm, well if it works wired to the router then it should also work using wifi. How exactly is it failing?

                      B 1 Reply Last reply Reply Quote 0
                      • B Offline
                        Builder @stephenw10
                        last edited by

                        @stephenw10 - After reviewing my original submission from above - it shows connected to wifi - however no websites come up? So back to my original submission above - looks to be addtional settings needed?

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Do wireless clients pull a dhcp lease? Can they ping local hosts by IP address? Can they resolve FQDNs?

                          B 1 Reply Last reply Reply Quote 0
                          • B Offline
                            Builder @stephenw10
                            last edited by

                            @stephenw10 - I do not know and dont know the steps to check what you are asking?

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S Offline
                              stephenw10 Netgate Administrator
                              last edited by

                              What are you testing with? You should be able to see if it has an IP address in the expected subnet at least.

                              This seems like a Tomato problem though. I'm not sure how much help we can be with that here.

                              B 2 Replies Last reply Reply Quote 0
                              • G Offline
                                giuliafw70
                                last edited by

                                One simple split is: first check whether a wireless client is getting a normal IP/gateway from Tomato. On the phone/laptop, look at the Wi-Fi details and compare the IP/subnet/gateway with a wired client on the Tomato side. If it has an address but only DNS fails, try temporarily disabling Stubby/custom DNS on Tomato and point clients at pfSense or a known resolver just to isolate it. If it gets no lease or a strange subnet, then Tomato is probably not acting as the AP/bridge you expect behind pfSense.

                                B 1 Reply Last reply Reply Quote 0
                                • B Offline
                                  Builder @stephenw10
                                  last edited by

                                  @stephenw10 - Hello I have not forgot about you on this - been working alot and not been able to get back to it. Was hoping today - simply ran out of time and it may be another week before I can get back it as weekends are only time I can hopefully get time on this. I am simply connecting my router that I had been already using prior to getting this firewall

                                  1 Reply Last reply Reply Quote 1
                                  • B Offline
                                    Builder @giuliafw70
                                    last edited by

                                    @giuliafw70 - Update - I turned off the stubby and the cloudfare and quad net in the router and kept the use internal dns on. Rebooted the router and then did a dns leak test and confirmed that it then was using the ISP dns. I was still able to connect wirelessly - but that was all - no internet though - so that tells me there is or are other settings that need to be modified in the router with tomato and I do not even know what those would be as I am very green with this. What I can say is that the factory defaults that Tomato uses is what is used in the router. You will see which version of Tomato I am using from the photos I attached at the very beginning of this post. Thank you

                                    1 Reply Last reply Reply Quote 0
                                    • B Offline
                                      Builder @stephenw10
                                      last edited by

                                      @stephenw10 Update - I turned off the stubby and the cloudfare and quad net in the router and kept the use internal dns on. Rebooted the router and then did a dns leak test and confirmed that it then was using the ISP dns. I was still able to connect wirelessly - but that was all - no internet though - so that tells me there is or are other settings that need to be modified in the router with tomato and I do not even know what those would be as I am very green with this. What I can say is that the factory defaults that Tomato uses is what is used in the router. You will see which version of Tomato I am using from the photos I attached at the very beginning of this post. Thank you

                                      16 out of 16
                                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.

                                      stephenw10S 1 Reply Last reply Reply Quote 0
                                      • stephenw10S Offline
                                        stephenw10 Netgate Administrator @Builder
                                        last edited by stephenw10

                                        @Builder said in New PF Sense Setup with Netgear R8000 with Tomato:

                                        I was still able to connect wirelessly - but that was all - no internet though

                                        Ok you need to narrow this down a bit to find out where the problem is.

                                        So when you connect to the wifi does that client get an IP address in the expected subnet?

                                        If so can that client ping local IP addresses? The Tomato router IP address for example? The pfSense internal interface IP address?

                                        Can it ping something external directly like 8.8.8.8?

                                        Can it ping pfsense.org?

                                        If you can find which step there is failing that will indicate where the problem is.

                                        B 1 Reply Last reply Reply Quote 0
                                        • B Offline
                                          Builder @stephenw10
                                          last edited by

                                          @stephenw10 ok and so how do I do these steps please so I can let you the answers to your questions? Thank you

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S Offline
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            What is the wireless client you're testing with? A laptop I assume? Windows?

                                            If so open a command prompt and run ipconfig to see what IP address it has.

                                            B 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.