Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Guide to setting up Atheros AP with pfsense?

    Scheduled Pinned Locked Moved Wireless
    21 Posts 7 Posters 13.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      GoldServe
      last edited by

      I've tried several things and set up a WLAN interface. Got it to associate with WPA but unable to get DHCP from pfsense. I had it working for a brief moment and i did not touch anything but it stopped working. Currently, I have it bridged to LAN.

      What configuration do I need for this thing to act like an AP and more importantly, what FIREWALL settings do I need to make this thing work?

      1 Reply Last reply Reply Quote 0
      • G
        GoldServe
        last edited by

        I am seeing something that was discussed before.

        I am bridging with LAN and if a device is connected to LAN, THEN i get an IP on WLAN. If nothing is connected to LAN, DHCP doesn't respond on WLAN.

        ???

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by

          For a bridge to work all interfaces of the bridge have to be uplinked.

          1 Reply Last reply Reply Quote 0
          • G
            GoldServe
            last edited by

            Right now, I call my ath0 lan so it is always up and lan bridged to it. Is this a good idea?

            Is there a way to achieve the same thing but I want captive portal to work on the ath0 but now it won't work on a bridged interface.

            Are there some easy steps to make two networks bridged but manually using firewall rules, etc?

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              @GoldServe:

              Right now, I call my ath0 lan so it is always up and lan bridged to it. Is this a good idea?

              This confuses me a bit. if ath0 is LAN what is the other LAN that you are talking about and what is ath0 then bridged to?

              1 Reply Last reply Reply Quote 0
              • G
                GoldServe
                last edited by

                I call ath0 lan and the wired ports as LAN2, bridged to LAN.

                1 Reply Last reply Reply Quote 0
                • G
                  GoldServe
                  last edited by

                  It doesn't seem like it is going to work. Lan (ath0) is giving out an IP but Wired (Lan2 bridged to lan) is not giving out an IP.

                  Is there an official and clean up to set up an AP bridged to LAN on pfsense?

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by

                    I haven't tried that kind of setup. I usually bridge the wireless interface to the wired lan in such scenarios which works fine. I know there are some limitations when bridging a wireless interface (you only can bridge a wireless interface to another one if it's in AP mode).

                    1 Reply Last reply Reply Quote 0
                    • G
                      GoldServe
                      last edited by

                      I can't believe pfsense doesn't work when I bridge the WLAN with the LAN with no LAN device plugged in. I'm not understanding why that is a problem? How do other platforms overcome this issue?

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        Afaik it's a freebsd issue.

                        1 Reply Last reply Reply Quote 0
                        • G
                          GoldServe
                          last edited by

                          Really…I'm surprised no one tried to fix this. How much would a bounty do?

                          1 Reply Last reply Reply Quote 0
                          • S
                            sullrich
                            last edited by

                            This is a kernel issue not a pfSense issue.

                            1 Reply Last reply Reply Quote 0
                            • G
                              GoldServe
                              last edited by

                              One more problem. I've got the wireless not bridged and on a seperate subnet from the wired now. Two clients connected and can ping the gateway of own and lan but can not ping another wireless client. Anything required in the firewall rules? Seems like it's doing AP isolation.

                              1 Reply Last reply Reply Quote 0
                              • GruensFroeschliG
                                GruensFroeschli
                                last edited by

                                you need set the checkbox "Allow intra-BSS communication"

                                We do what we must, because we can.

                                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                                1 Reply Last reply Reply Quote 0
                                • G
                                  GoldServe
                                  last edited by

                                  Thanks for the response. Works like a charm.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    sokar311
                                    last edited by

                                    Hi, i also have a PfSense configuration with 2 Nics and 1 Wireless Card set as an access point (infrastructure gives me "no carrier"!?), i also have the "Allow Intra-BSS", but seems that the firewall rules don't apply between the wireless clients anymore!, any help?, thanks.

                                    1 Reply Last reply Reply Quote 0
                                    • GruensFroeschliG
                                      GruensFroeschli
                                      last edited by

                                      Infrastructure = Client
                                      Access Point = Access Point

                                      Firewall-rules are and were never applied for traffic between clients.

                                      We do what we must, because we can.

                                      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        sokar311
                                        last edited by

                                        Thak you, but do you know any way to control the traffic between wireless clients with the firewall?

                                        1 Reply Last reply Reply Quote 0
                                        • L
                                          lsf
                                          last edited by

                                          Vlans might do the trick. I never tested this tho.

                                          -lsf

                                          1 Reply Last reply Reply Quote 0
                                          • H
                                            hoba
                                            last edited by

                                            @lsf:

                                            Vlans might do the trick. I never tested this tho.

                                            How should tat work? The only option that we provide is to seperate the clients from each other meaning they completely can't talk to each other. Besides that there is no way that I can think of to do that.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.