(Re)Installation Issues with WAN Gateway (and maybe ISP)
-
In January 2026 I had my ISP (AIS in Thailand) set their modem/router to bridged mode, and I installed pfSense (from the inteltechnics tutorial) onto a Protectly Vault FW4C and it worked great.
In March 2026 I moved house and also had to change my ISP due to logistics (also had them set up their modem/router to bridged mode). I changed the PPPoE in pfSense to the new account # (for username and password), and it worked great.
About mid June 2026, the internet went down for about 4-5 hours for scheduled maintenance per the ISP. When the internet came back on, no matter what I did, I couldn't get any active internet connection through the pfSense.
I called the ISP (AIS-3bb in Thailand) who mentioned that the PPPoE username was now 'account-number@3bb'. Prior to the internet outage, I didn't have to add the @3bb after the PPPoe account-number/username, so they obviously made some changes.
However, I still couldn't get an internet connection through pfSense. Due to various priorities, I went back to using my personal router with a VPN running on it.
I recently contacted the ISP to have their modem set to bridged mode again and reinstalled pfSense onto the Vault FW4C.
Once pfSense was installed, the WAN Interface showed connected, but the WAN Gateway would not connect.
I called the ISP who would only say that the internet is active.-
Could the ISP block my access from using pfSense and a VPN?
-
Is there any way to set up pfSense onto the Vault FW4C without requesting bridged mode from the ISP?
-
Is there another step that's missing from the inteltechnics tutorial that isn't listed?
I've gone back to my router/vpn set up again, and it now appears that the ISP is throttling my vpn connection. It's so slow now with the vpn active......
Any suggestions?
Thanks for your time. -
-
@jg2003 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
I called the ISP who would only say that the internet is active.
Calling them ? you don't have to do that.
Afaik, every ISP has a web site where you can login to see the bills, details about the email(s) they gave you, the passwords that come with it, your mails with a web interface, etc and how and with what and what 'mode' 'the' box is connected.
Normally, this is 'their box', the one hey gave you when you subscribed. this box knows how to connect to 'their' network. It could be :
Very rare : a Ethernet RJ45 plug.
A phone cable plug => so the connection coming in over a phone line, and the connection is most probably ADSL or VDSL.
A phone line : it could also be (now ancient) : ISDN.
You could also have small box on the wall with fiber optic plug, and your ISP box has a fiber plug also. This ISP box will convert the fiber connection to an Ethernet connection : it's this Ethernet (one off the) port(s) you connect your devices or pfSense to.
Starlink : that's an Ethernet plug.
Etc. More connection methods exist.And there is the 'identification' : normally your ISP box handles this. It contains a login code and password. This could be PPPOE or whatever your ISP box uses as an identification method.
When you change the operation of the ISP box mode from 'router' to 'bridge' then it's the device (must be a router => pfSense ) that handles the identification. Most often, this would be pppoe and your IPS gives you this info on their web site, login to your account and you'll find them ?
Any other 'normal' or 'special' things hat are needed are mentioned their.Normally (again) when you subscribe with an ISP, you receive a box, and a letter. This letter contains your email adresses with your ISP, and the mail password. And the login credentials for the box. These could be the pppoe credentials.
@jg2003 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
Could the ISP block my access from using pfSense and a VPN?
pfSense is just a router (firewall) : it gets packets from it's LAN interface(s) and sends them out over another interface. Let's call it the WAN interface.
Packets that come back are send to the device that as requesting the info.
pfSense as router doesn't add or remove anything.
There is no such 'because the router is TPLINK or DLINK or Cisco or pfSense' that your info will flow faster or slower. In theory, your ISP doesn't even know you use a pfSense. They don't care.
If your VPN is slow : get a bigger bandwidth with your ISP.
Or pay your VPN more ^^
Or get another VPN .... as they all say that they reserve 'just for you' their entire bandwidth, which is - you knew it - pure BS.
At a given moment, on the same VPN server, if there are thousands of user connected, and this VPN server has a massive 10 G/bis/sec interface (bigger NICs don't exist) then you bandwidth is 10 Gbit/sec / 1000 (lets presume 1000 VPN users) then you have 10 Mbit/sec and nothing more.
Knowing that most VPN users use their connection 'to the max' (streaming, downloading the latest Disney etc) everybody is fight for some bandwidth.
You don't want a VPN that guarantees the max (but not more as your ISP) because : it would be very expensive.
Connection are actualized among all (1000+) users.Btw : when you use pfSense with pppoe : go here : Status > System Logs > System > General and have a look at the logs (is there a ppp or pppoe log ?) and have a look.
If there is an issue, it's - as always - logged, so you can see what the issue is, and thus correct it.
If you see 'Unknown or wrong User ID' then you kow the user ID is wrong.
Same thing for the password etc. -
@jg2003 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
Once pfSense was installed, the WAN Interface showed connected, but the WAN Gateway would not connect.
How was the gateway showing as failing to connect?
It could just be the gateway monitoring failing because the ISPs gateway doesn't respond to pings. In which case just set an external monitoring IP to use instead:
https://docs.netgate.com/pfsense/en/latest/routing/gateway-configure.htmlCommonly used IPs for that are 8.8.8.8 or 1.1.1.1
-
Afaik, every ISP has a web site where you can login to see the bills, details about the email(s) they gave you, the passwords that come with it, your mails with a web interface, etc and how and with what and what 'mode' 'the' box is connected.
Whether I'm on their website or using their app, I can only see my account # (which is my PPPoE#), I can change plans and adjust internet speeds.
Normally, this is 'their box', the one hey gave you when you subscribed. this box knows how to connect to 'their' network. It could be :
Very rare : a Ethernet RJ45 plug.'Their box' has worked well for several months. It only slowed down after I had it changed to bridged mode, and then had them remove bmode when I couldn't get pfSense to connect.
When you change the operation of the ISP box mode from 'router' to 'bridge' then it's the device (must be a router => pfSense ) that handles the identification. Most often, this would be pppoe and your IPS gives you this info on their web site, login to your account and you'll find them ?
I had the correct PPPoE username and password entered in pfSense.
If your VPN is slow : get a bigger bandwidth with your ISP.
My plan is 1000/500 and has always been very fast until about a week ago.
Or pay your VPN more ^^
I use ProtonVPN. It's always been fast no matter what country I connected to until a week ago. I could stream shows from England or US (from my location in Thailand) without any buffering.
Now, I can barely stream shows using a Thailand VPN server now. The speedtests are depressing. The ISP (AIS) definitely seems to be throttling my VPN connection.
Regardless of my internet speeds, I just want to get pfSense working again. I will sort out the slower speeds with my ISP at a later date.Btw : when you use pfSense with pppoe : go here : Status > System Logs > System > General and have a look at the logs (is there a ppp or pppoe log ?) and have a look.
If there is an issue, it's - as always - logged, so you can see what the issue is, and thus correct it.
If you see 'Unknown or wrong User ID' then you kow the user ID is wrong.
Same thing for the password etc.Thanks for this info
-
How was the gateway showing as failing to connect?
From the Dashboard Gateway widget.
It could just be the gateway monitoring failing because the ISPs gateway doesn't respond to pings. In which case just set an external monitoring IP to use instead:
https://docs.netgate.com/pfsense/en/latest/routing/gateway-configure.htmlCommonly used IPs for that are 8.8.8.8 or 1.1.1.1
I didn't have to do what you've suggested in the past. However, I have read through the link you provided and will look into that, if I continue to have issues when I attempt to get pfSense connected again (which will be about a week).
-
Something I didn't previously mention is that during the pfSense installation, I assume I had an internet (PPPoE) connection as I was able to update pfSense during the installation process.
Should I wait on the update until after pfSense is up and running?
Also, after I added the WAN, LAN, OPT1, and OPT2 ports in 'Interface', there was an additional port available. The Protectly Vault FW4C only has the four ports I mentioned above. I don't remember this happening when I originally set up pfSense 7-months ago.
I wasn't sure whether of not to add this port and what it would be used for?
Thanks again
-
@jg2003 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
Also, after I added the WAN, LAN, OPT1, and OPT2 ports in 'Interface', there was an additional port available.
It's normal that you see an extra interface.
Your WAN is a normal Ethernet connection, and 'inside' the WAN connection, to the modem, is an new connection : pppoe, as pppoe is tunneled over a standard Ethernet connection. That's why you also have a 'pppoe' type interface. -
@jg2003 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
I didn't have to do what you've suggested in the past.
But your ISP recently made some infrastructure change that required you change the username used. It's entirely possible they also changed out the gateway servers or the rulesets used and now block pings to the gateway address,
That exact thing happened to me some years ago. My ISP uses PPPoE and it's gateway doesn't respond to pings. I have to set an external monitor IP to see an accurate gateway status. -
Your WAN is a normal Ethernet connection, and 'inside' the WAN connection, to the modem, is an new connection : pppoe, as pppoe is tunneled over a standard Ethernet connection. That's why you also have a 'pppoe' type interface.
In my previous install, I went to Interface > WAN > and changed the Configuration Type to PPPoE. Then under PPPoE Configuration, I entered the username and password amd I was able to connect.
Do I have to enter this same configuration in the extra PPPoE port as well?
-
But your ISP recently made some infrastructure change that required you change the username used. It's entirely possible they also changed out the gateway servers or the rulesets used and now block pings to the gateway address,
Ok I will keep this in mind during the install.
I'm curious though that if the gateway server or rulesets is blocking pings, will it definitely not have an internet connection, or does it connect but shows the gateway status as disconnected? -
I've read that I might have to request the ISP to clear the mac address of my previous connected device before installing the pfsense firewall.
Does this sound correct? -
Usually that's only for DHCP connections but it's possible. If it was locked to your old MAC though I wouldn't expect to see the WAN ever pull a valid IP address. And as I understand it you are seeing that. The PPPoE connection completes.
-
@stephenw10 said in (Re)Installation Issues with WAN Gateway (and maybe ISP):
Usually that's only for DHCP connections but it's possible.
I will keep this in mind as an option if I encounter issues with the gateway connection.
-
I have my ISP modem in bridged mode again just to test out the PPPoE connection.
I used a personal GL.iNet router and was able to successfully get an active and stable internet connection with a VPN set up on it.
Hopefully it will be just as easy to get pfSense connected with PPPoE as well......
Will give it a try in a couple of days.
Thanks to the both of you for your suggestions and expertise.
Privacy Policy · Cookie Policy