Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Proxy and land subnets

    Scheduled Pinned Locked Moved Routing and Multi WAN
    10 Posts 3 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Getit
      last edited by

      Hi, first greetings for your work.

      I have a pfsense firewall,  Dual Wan + Load Balancer + Packages(Squid+Spamd)

      The lan segment have another network segments with a gateway on lan.

      Example:

      PfSense Lan IP: 192.168.0.13
      Lan Router Gateway: 192.168.0.21
        This gateway allow access to : 192.168.10.0/24 to 192.168.16.0/24 networks

      I add the routes on pfsense and i can ping any host on that neworks from pfsense, but if i try a ping from a host on that network to the pfsense 192.168.0.13 lan  ip, i dont get a response.

      We want allow proxy internet access to that networks not direct access.

      Sorry for my bad english.
      Thanks in advance.

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Try to tick the following box at system>advanced:

        Bypass firewall rules for traffic on the same interface

        This option only applies if you have defined one or more static routes. If it is enabled, traffic that enters and leaves through the same interface will not be checked by the firewall. This may be desirable in some situations where multiple subnets are connected to the same interface.

        1 Reply Last reply Reply Quote 0
        • J
          jeroen234
          last edited by

          Lan Router Gateway: 192.168.0.21
            This gateway allow access to : 192.168.10.0/24 to 192.168.16.0/24 networks

          i miss 1 thing in this list
          dit you make a route to the pfsense server on the lan gateway so that that trafic can go to the 192.168.0.0/24 network ?

          and dit you make on pfsense a rule to allow imcp (ping,echo enz) from the lan

          1 Reply Last reply Reply Quote 0
          • G
            Getit
            last edited by

            I make a static route for the lan subnets 192.168.10.0/24 to 192.168.16.0/24 and as i say, can ping from pfsense to remote network host.

            I make your change hoba and nothing changes. I have many entries on system log as this

            "kernel: arpresolve: can't allocate route for 192.168.1.21"

            "kernel: arplookup 192.168.1.21 failed: host is not on local network"

            I add a entry on firewall rules->lan  to allow all traffic from any to pfsense firewall ip with loggin and nothing logs in firewall log for remote subnet traffic.

            I can ping from a host on remote networks to another host in lan net but not to the firewall lan ip  ???

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              Looks like you have a typo somewhere and use 192.168.1.21 as gateway instead of 192.168.0.21. With these log entries it's quite obvious.

              1 Reply Last reply Reply Quote 0
              • G
                Getit
                last edited by

                routes are ok hoba, i can ping from pfsense to remote subnet hots via subnet gateway.

                @Getit:

                I make a static route for the lan subnets 192.168.10.0/24 to 192.168.16.0/24 and as i say, can ping from pfsense to remote network host.

                I make your change hoba and nothing changes. I have many entries on system log as this

                "kernel: arpresolve: can't allocate route for 192.168.1.21"

                "kernel: arplookup 192.168.1.21 failed: host is not on local network"

                I add a entry on firewall rules->lan  to allow all traffic from any to pfsense firewall ip with loggin and nothing logs in firewall log for remote subnet traffic.

                I can ping from a host on remote networks to another host in lan net but not to the firewall lan ip  ???

                sorry i type 1.21 and is 0.21 , typing mistake.

                1 Reply Last reply Reply Quote 0
                • G
                  Getit
                  last edited by

                  i think find the problem, i see on diagnostic->routes an ipv4 destination 192.168.0.21 with gateway on a remote subnet but in system->static routes i dont see any mistake.

                  How can i delete that static route?

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by

                    Not sure how that ends up there. Everything is generated on bootup/change form the config.xml. Did you try to reboot? What version are you on?

                    1 Reply Last reply Reply Quote 0
                    • G
                      Getit
                      last edited by

                      fixed, thanks hoba, the main windows technical solution works "reboot", i think the problem was a mistake making static routes for the lan subnets.

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        Good to hear  :D

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.