Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot access lan from wan

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      joshfokis
      last edited by

      I am trying to setup a lab but i want to be able to reach the lan side from the wan. The lab is virtual with pfsense in vbox and all other devices are virtual behind pfsense. I have set firewall rules to to any any on both wan and lan. All traffic comes out of the lan as far as I can tell. I can reach the internet from behind pfsense but I cannot ping from the wan side to the lan. The wan IP is 192.168.0.x and the lan is 192.168.1.x. Not sure what else to do. Any help would be highly appreciated and if theres any info I need to post please let me know. Sorry in advance if this post does not have enough info.

      1 Reply Last reply Reply Quote 0
      • P
        podilarius
        last edited by

        If you are trying to access using the direct IP, you muyst remember that NAT is on by default and you must set to manual and delete all rules. Then you must set a route to the Lab network from your default gateway. Then it would work. That or you are going to have to setup a bridge (which is far more complex).

        1 Reply Last reply Reply Quote 0
        • J
          joshfokis
          last edited by

          @podilarius:

          If you are trying to access using the direct IP, you muyst remember that NAT is on by default and you must set to manual and delete all rules. Then you must set a route to the Lab network from your default gateway. Then it would work. That or you are going to have to setup a bridge (which is far more complex).

          I have set NAT to manual but I have not set a route yet. Now that I have done that I get TTL exceeded when I ping one of the boxes, and the TTL comes from the physical lan ip for the fw. Thanks for your help now I am getting closer.

          1 Reply Last reply Reply Quote 0
          • J
            joshfokis
            last edited by

            I am at my wits end. I cannot figure this out for the life of me. when I remove NAT my lan cannot go out but when I ping the .102 box I get for the first line host unreachable from the gateway but then get pings back from the box. I am attaching my rules and nat images. please if any more info is need feel free to request it.

            2012-11-12_22-37-05.png
            2012-11-12_22-37-05.png_thumb
            2012-11-12_22-37-15.png
            2012-11-12_22-37-15.png_thumb
            2012-11-12_22-37-30.png
            2012-11-12_22-37-30.png_thumb
            2012-11-12_22-39-06.png
            2012-11-12_22-39-06.png_thumb

            1 Reply Last reply Reply Quote 0
            • P
              podilarius
              last edited by

              In some virtual environments, you need to set the NICs on the host to allow permiscious mode. I think you have to do something like that for vBOX. It sounds like it is working, but there is a momentary hiccup in coms. Do you have any kind of power saving turned on?

              1 Reply Last reply Reply Quote 0
              • J
                joshfokis
                last edited by

                Thanks for the response. I don't think I have any power savers on. I did have them set as promiscuous but I believe i changed them back so I will have to change back and check hoping that works.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.