<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LAN to LAN Setup - I think i&#x27;m missing something.]]></title><description><![CDATA[<p dir="auto">Network</p>
<p dir="auto">192.168.20.0 &lt;–--&gt; PFSense LAN 192.168.20.212/24 |------| 192.168.70.254/24 Pfsense WAN &lt;------&gt; 192.168.70.0</p>
<p dir="auto">On the 20 network I have a router also sitting on 192.168.20.254 this has a rule in it telling anything on the 20 network which tries to go to the 70 network should do so via 192.168.20.212</p>
<p dir="auto">The 20 Network is our Main lan with 100 servers and users on it<br />
The 70 Network is about 40 developers with thier own servers etc</p>
<p dir="auto">I can ping across from 20 to 70<br />
I can ping across from 70 to 20</p>
<p dir="auto">If i run a traceroute from the 20 lan to a 70 lan IP address i get</p>
<p dir="auto">Hop 1 = 192.168.20.254<br />
Hop 2 = 192.168.20.212<br />
Hop 3 = 192.168.70.20<br />
Sucess</p>
<p dir="auto">If i run a trace route from the 70 lan onto the 20 lan i get</p>
<p dir="auto">Hop 1 = 192.168.70.254<br />
Hop 2 = 192.168.20.1<br />
Sucess</p>
<p dir="auto">I can connect to a Windows Server on the 70 lan fine from the 20 lan using UNC</p>
<p dir="auto">Locally on the 70 Lan All works well Intranet pages open, UNC Windows paths open..<br />
Howver from the 70 lan i cannot open up an Intranet page, or connect to a server on the 20 lan from the 70 Lan</p>
<p dir="auto">I have a single firewall rule in WAN and LAN which both is to PASS ANY FROM ANY TO ANY<br />
I set the NAT to Manual in the Outbound Tab<br />
I've got no default routes, not static routes, no gateways setup</p>
<p dir="auto">To start with i'd like to be able to connect from the 70 network to the 20 network as well...<br />
Once i have complete connectivity, then i'll firewall it up..</p>
<p dir="auto">Where am I going wrong, i'm losing sleep and hair over this.. It's something stupid, and i need another set of eyes</p>
<p dir="auto">There is no need for anything on the 70 lan to go over the router at 192.168.20.254 and get out to the internet, this is a 2 lan system, which when i have working will use firewall rules to lock down..</p>
<p dir="auto">Can anyone please help me with this? It's Late on a sunday..</p>
]]></description><link>https://forum.netgate.com/topic/43281/lan-to-lan-setup-i-think-i-m-missing-something</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 03:38:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/43281.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 25 Mar 2012 16:11:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to LAN to LAN Setup - I think i&#x27;m missing something. on Tue, 27 Mar 2012 13:22:59 GMT]]></title><description><![CDATA[<p dir="auto">If you are NAT'ing out to your developer network then you would have to have a Static NAT for every service or for every server to get in to the server network from the developer network.<br />
So add a static and test it. Then add all the other statics, or don't NAT just route. If you remove NAT'ing then everything should work.<br />
Have the developers got a gateway? If so, and it isn't this box then you would need a route on the gateway for the server network.<br />
Make sure that the Block Private Networks is not checked for the WAN interface.</p>
<p dir="auto">Don't the developers have Internet access?</p>
]]></description><link>https://forum.netgate.com/post/327116</link><guid isPermaLink="true">https://forum.netgate.com/post/327116</guid><dc:creator><![CDATA[mibovrd]]></dc:creator><pubDate>Tue, 27 Mar 2012 13:22:59 GMT</pubDate></item></channel></rss>