<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[WiFiOPT1 interface cant reach internet]]></title><description><![CDATA[<p dir="auto">I want to allow a wireless AP net access from OPT1</p>
<p dir="auto">This is the rule for the WiFiOPT1 interface I want this to go straight to the internet not to the LAN</p>
<p dir="auto">What am i doing wrong?</p>
<p dir="auto">FIREWALL RULES fir WiFiOPT1<br />
TCP  WiFiOPT1 net  *  ! LAN net  *  *</p>
<p dir="auto">WAN</p>
<p dir="auto">*  RFC 1918 networks  *  *  *  *  Block private networks</p>
<p dir="auto">TCP  *  *  192.168.1.1  80 (HTTP)  *  NAT Opening Remote GUI access for PFS</p>
<p dir="auto">TCP  *  *  192.168.2.1  25 (SMTP)  *  NAT NAT allow smtp to mail server</p>
<p dir="auto">TCP  *  *  192.168.2.1  80 (HTTP)  *  NAT NAT allow http to GEARNET</p>
<p dir="auto">TCP  *  *  192.168.2.5  80 (HTTP)  *  NAT Forwarded to SugarCRM</p>
<p dir="auto">LAN<br />
*  LAN net  *  *  *  *</p>
<p dir="auto">Firewall: NAT: Port Forward</p>
<p dir="auto">WAN  TCP  22 (SSH)  192.168.2.239<br />
(ext.: 66.74.666.999) 22 (SSH) NAT allow SSH to NSLU server</p>
<p dir="auto">WAN TCP 80 (HTTP) 192.168.2.239<br />
(ext.: 66.74.666.999) 80 (HTTP) NAT allow http to NSLU  server</p>
<p dir="auto">WAN TCP 8080  192.168.2.5<br />
(ext.: 66.74.999.999) 80 (HTTP) Forwarded to SugarCRM</p>
]]></description><link>https://forum.netgate.com/topic/3898/wifiopt1-interface-cant-reach-internet</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 08:11:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/3898.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 23 Mar 2007 04:07:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Tue, 27 Mar 2007 19:22:38 GMT]]></title><description><![CDATA[<p dir="auto">Yes that probably had something to do with it.  In the configuration I had in the past bridged some interfaces.  It is possible that I did not unbridge them.  Who knows I thought that I did?</p>
]]></description><link>https://forum.netgate.com/post/151933</link><guid isPermaLink="true">https://forum.netgate.com/post/151933</guid><dc:creator><![CDATA[sloan]]></dc:creator><pubDate>Tue, 27 Mar 2007 19:22:38 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Tue, 27 Mar 2007 05:20:46 GMT]]></title><description><![CDATA[<p dir="auto">sounds like you had made a bridge somewhere<br />
but dit not had all conections of the bridge pluged in<br />
so then the bridge is broken and will not work</p>
]]></description><link>https://forum.netgate.com/post/151887</link><guid isPermaLink="true">https://forum.netgate.com/post/151887</guid><dc:creator><![CDATA[jeroen234]]></dc:creator><pubDate>Tue, 27 Mar 2007 05:20:46 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Mon, 26 Mar 2007 22:02:39 GMT]]></title><description><![CDATA[<p dir="auto">Here is what I did to fix this.  I reinstalled pf in a live production environment.  I had live hosts attached to all 4 NIC ports.  When I tried to implement the firewall rule as listed in the monowall DMZ tutorial without live hosts attached the NIC would not allow any traffic to the NET.  the NIC's would allow traffic from the pf ssh console to the LAN'S not the other way.  I would normally say pf would not need a live host but this is the third time I tried I fresh install.  The third was a charm.  And only on the third time did i have a live host attached,  so who knows?<br />
I started with allowing all to all on the LAN2 and LAN3  NIC'S.  Once I knew they were allowing traffic to the net and each other I tightened them down with allow any traffic to the NET and not the other LAN'S.  Similar to a DMZ.</p>
<p dir="auto">Right before the new install I was getting some strange firewall errors in the log.  I tried to correct and then went for a fresh install.</p>
<p dir="auto">Now I can have WiFi on its own LAN straight to the net,  no access to the other LAN'S.  ;D 8)</p>
]]></description><link>https://forum.netgate.com/post/151872</link><guid isPermaLink="true">https://forum.netgate.com/post/151872</guid><dc:creator><![CDATA[sloan]]></dc:creator><pubDate>Mon, 26 Mar 2007 22:02:39 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Sat, 24 Mar 2007 03:09:32 GMT]]></title><description><![CDATA[<p dir="auto">I could be more clear, so here goes.    Here is what i stated above      "I want to allow a wireless AP net access from OPT1"</p>
<p dir="auto">I can't ping out of the OPT1 interface to the internet.  I can ping from pf through the OPT1 interface to the DMZ server.  So the nic works.</p>
<p dir="auto">I read the monowall tutrorial for DMZ's and implemented the firewall rules to allow access to the DMZ to the net.  But they are not working in my implementation.</p>
<p dir="auto">Thanks in advance for any help and for the above replies.</p>
]]></description><link>https://forum.netgate.com/post/151693</link><guid isPermaLink="true">https://forum.netgate.com/post/151693</guid><dc:creator><![CDATA[sloan]]></dc:creator><pubDate>Sat, 24 Mar 2007 03:09:32 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Sat, 24 Mar 2007 01:25:54 GMT]]></title><description><![CDATA[<p dir="auto">you haven't stated what the problem is.</p>
]]></description><link>https://forum.netgate.com/post/151685</link><guid isPermaLink="true">https://forum.netgate.com/post/151685</guid><dc:creator><![CDATA[sai]]></dc:creator><pubDate>Sat, 24 Mar 2007 01:25:54 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Sat, 24 Mar 2007 00:26:27 GMT]]></title><description><![CDATA[<p dir="auto">oops  that was really set to any, as it is now.  I copied it when I was testing switching it around, testing other options etc..</p>
<p dir="auto">I can ping VIA pfsense ssh to the server in the DMZ.  so I know the NIC  works.  But some other config is messed up.</p>
<p dir="auto">I read the monowall tutorial on DMZ'S that is where I got that firewall rule from.</p>
<p dir="auto">Do you have any other suggestions?</p>
]]></description><link>https://forum.netgate.com/post/151681</link><guid isPermaLink="true">https://forum.netgate.com/post/151681</guid><dc:creator><![CDATA[sloan]]></dc:creator><pubDate>Sat, 24 Mar 2007 00:26:27 GMT</pubDate></item><item><title><![CDATA[Reply to WiFiOPT1 interface cant reach internet on Fri, 23 Mar 2007 18:57:00 GMT]]></title><description><![CDATA[<p dir="auto">Are you sure you only want to allow tcp but not icmp, udp and so on? Change the protocol to any in your optwifi rule. Guess you just have issues pinging as you don't allow icmp and with nameresolution as you not allow udp.</p>
]]></description><link>https://forum.netgate.com/post/151643</link><guid isPermaLink="true">https://forum.netgate.com/post/151643</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Fri, 23 Mar 2007 18:57:00 GMT</pubDate></item></channel></rss>