<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cannot access Router&#x2F;Internet]]></title><description><![CDATA[<p dir="auto">Hey,<br />
I managed to set up the DHCP Server so far but I cannot reach the Router, maybe it is a problem with the static route?</p>
<p dir="auto">The network architecture is as follows:</p>
<p dir="auto">WWW–--ROUTER----PFSENSE----LAN<br />
The router is a cheap Zyxel but has static route.</p>
<p dir="auto">IP adresses:<br />
Zyxel Router 192.168.1.1/24<br />
pfs-router 192.168.1.2/24 (WAN) - Gateway 192.168.1.1<br />
pfs-client 192.168.2.1/24 (LAN) - DHCP Server 192.168.2.100 - 192.168.2.200</p>
<p dir="auto">The static route in the Zyxel looks as follows<br />
Target: 192.168.2.0<br />
SUBNET: 255.255.255.0<br />
Gateway: 192.168.2.1 (PF-Sense)</p>
<p dir="auto">If I ping from a client (192.168.2.100), I can reach the pfsense 192.168.2.1 and also 192.168.1.2, but not the Zyxel.<br />
When I try to ping the Zyxel the output is as follows:<br />
PING 192.168.1.1 (192.168.1.1): 56 data bytes<br />
36 bytes from pfsense.XXX (192.168.2.1): Destination Host Unreachable<br />
Vr HL TOS  Len  ID Flg  off TTL Pro  cks      Src      Dst<br />
4  5  00 5400 150c  0 0000  40  01 e0e7 192.168.2.100  192.168.1.1</p>
<p dir="auto">Vice versa, from the router net (192.168.1.100), I even cannot ping the pfs-server which should be in the same subnet (192.168.1.2):<br />
Request timeout for icmp_seq 0</p>
<p dir="auto">Does anyone have an idea where I could have made a mistake?</p>
<p dir="auto">thx, a Nobody</p>
]]></description><link>https://forum.netgate.com/topic/52919/cannot-access-router-internet</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 08:38:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/52919.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 Feb 2013 10:08:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Cannot access Router&#x2F;Internet on Tue, 12 Feb 2013 19:27:39 GMT]]></title><description><![CDATA[<p dir="auto">Ok, many thanks, it works now!<br />
I don't know why, but as soon as I set up the static route again, it worked. Even the Zyxel does NAT, the route was obviously necessary!</p>
]]></description><link>https://forum.netgate.com/post/378567</link><guid isPermaLink="true">https://forum.netgate.com/post/378567</guid><dc:creator><![CDATA[franzenobody]]></dc:creator><pubDate>Tue, 12 Feb 2013 19:27:39 GMT</pubDate></item><item><title><![CDATA[Reply to Cannot access Router&#x2F;Internet on Sun, 10 Feb 2013 16:12:50 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">ifconfig -a; /etc/rc.banner; netstat -r -n<br />
vr0: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:88<br />
inet 192.168.2.1 netmask 0xffffff00 broadcast 192.168.2.255<br />
inet6 fe80::20d:b9ff:fe2b:e088%vr0 prefixlen 64 scopeid 0x1<br />
nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (100baseTX &lt;full-duplex&gt;)<br />
status: active<br />
vr1: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:89<br />
inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255<br />
inet6 fe80::20d:b9ff:fe2b:e089%vr1 prefixlen 64 scopeid 0x2<br />
nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (100baseTX &lt;full-duplex&gt;)<br />
status: active<br />
vr2: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:8a<br />
inet6 fe80::20d:b9ff:fe2b:e08a%vr2 prefixlen 64 scopeid 0x3<br />
nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (none)<br />
status: no carrier<br />
lo0: flags=8049 &lt;up,loopback,running,multicast&gt;metric 0 mtu 16384<br />
options=3 &lt;rxcsum,txcsum&gt;inet 127.0.0.1 netmask 0xff000000<br />
inet6 ::1 prefixlen 128<br />
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4<br />
nd6 options=43 &lt;performnud,accept_rtadv&gt;pfsync0: flags=0&lt;&gt; metric 0 mtu 1460<br />
syncpeer: 224.0.0.240 maxupd: 128 syncok: 1<br />
enc0: flags=0&lt;&gt; metric 0 mtu 1536<br />
pflog0: flags=100 &lt;promisc&gt;metric 0 mtu 33200<br />
*** Welcome to pfSense 2.0.2-RELEASE-nanobsd (i386) on pfsense ***</p>
<p dir="auto">WAN (wan)                -&gt; vr1        -&gt; 192.168.1.2<br />
  LAN (lan)                -&gt; vr0        -&gt; 192.168.2.1<br />
  OPT1 (opt1)              -&gt; vr2        -&gt; NONE Routing tables</p>
<p dir="auto">Internet:<br />
Destination        Gateway            Flags    Refs      Use  Netif Expire<br />
default            192.168.1.1        UGS        0    1548    vr1<br />
127.0.0.1          link#4            UH          0      58    lo0<br />
192.168.1.0/24    link#2            U          0      257    vr1<br />
192.168.1.2        link#2            UHS        0      216    lo0<br />
192.168.2.0/24    link#1            U          0      449    vr0<br />
192.168.2.1        link#1            UHS        0      216    lo0</p>
<p dir="auto">Internet6:<br />
Destination                      Gateway                      Flags      Netif Expire<br />
::1                              ::1                          UH          lo0<br />
fe80::%vr0/64                    link#1                        U          vr0<br />
fe80::20d:b9ff:fe2b:e088%vr0      link#1                        UHS        lo0<br />
fe80::%vr1/64                    link#2                        U          vr1<br />
fe80::20d:b9ff:fe2b:e089%vr1      link#2                        UHS        lo0<br />
fe80::%vr2/64                    link#3                        U          vr2<br />
fe80::20d:b9ff:fe2b:e08a%vr2      link#3                        UHS        lo0<br />
fe80::%lo0/64                    link#4                        U          lo0<br />
fe80::1%lo0                      link#4                        UHS        lo0<br />
ff01:1::/32                      fe80::20d:b9ff:fe2b:e088%vr0  U          vr0<br />
ff01:2::/32                      fe80::20d:b9ff:fe2b:e089%vr1  U          vr1<br />
ff01:3::/32                      fe80::20d:b9ff:fe2b:e08a%vr2  U          vr2<br />
ff01:4::/32                      ::1                          U          lo0<br />
ff02::%vr0/32                    fe80::20d:b9ff:fe2b:e088%vr0  U          vr0<br />
ff02::%vr1/32                    fe80::20d:b9ff:fe2b:e089%vr1  U          vr1<br />
ff02::%vr2/32                    fe80::20d:b9ff:fe2b:e08a%vr2  U          vr2<br />
ff02::%lo0/32                    ::1                          U          lo0&lt;/promisc&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum&gt;&lt;/up,loopback,running,multicast&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;&lt;/full-duplex&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;&lt;/full-duplex&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;</p>
</blockquote>
<p dir="auto">Sorry, I hope these are the data you need!</p>
]]></description><link>https://forum.netgate.com/post/378140</link><guid isPermaLink="true">https://forum.netgate.com/post/378140</guid><dc:creator><![CDATA[franzenobody]]></dc:creator><pubDate>Sun, 10 Feb 2013 16:12:50 GMT</pubDate></item><item><title><![CDATA[Reply to Cannot access Router&#x2F;Internet on Sun, 10 Feb 2013 15:51:04 GMT]]></title><description><![CDATA[<p dir="auto">The output from /etc/rc.banner was truncated so I can't see some of the settings it would normally display. Please provide output of pfSense shell command:```<br />
/etc/rc.banner ; netstat -r -n</p>
<pre><code>
You should be able to ssh to the pfSense box from your MAC client, capture the command output in the ssh window and paste it into reply. (Please post all the output this time.)</code></pre>
]]></description><link>https://forum.netgate.com/post/378136</link><guid isPermaLink="true">https://forum.netgate.com/post/378136</guid><dc:creator><![CDATA[wallabybob]]></dc:creator><pubDate>Sun, 10 Feb 2013 15:51:04 GMT</pubDate></item><item><title><![CDATA[Reply to Cannot access Router&#x2F;Internet on Sun, 10 Feb 2013 15:11:06 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for your fast answer, I restarted everything and I still could not ping the Zyxel (I deleted the static route) FROM THE CLIENT-PC (from the WAN Interface I can now, see below).</p>
<p dir="auto">I ran the command on the serial interface, here is the outcome:</p>
<blockquote>
<p dir="auto">ifconfig -a; /etc/rc.banner<br />
vr0: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
        options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:88<br />
        inet 192.168.2.1 netmask 0xffffff00 broadcast 192.168.2.255<br />
        inet6 fe80::20d:b9ff:fe2b:e088%vr0 prefixlen 64 scopeid 0x1<br />
        nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (100baseTX &lt;full-duplex&gt;)<br />
        status: active<br />
vr1: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
        options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:89<br />
        inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255<br />
        inet6 fe80::20d:b9ff:fe2b:e089%vr1 prefixlen 64 scopeid 0x2<br />
        nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (100baseTX &lt;full-duplex&gt;)<br />
        status: active<br />
vr2: flags=8843 &lt;up,broadcast,running,simplex,multicast&gt;metric 0 mtu 1500<br />
        options=8280b &lt;rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;ether 00:0d:b9:2b:e0:8a<br />
        inet6 fe80::20d:b9ff:fe2b:e08a%vr2 prefixlen 64 scopeid 0x3<br />
        nd6 options=43 &lt;performnud,accept_rtadv&gt;media: Ethernet autoselect (none)<br />
        status: no carrier<br />
lo0: flags=8049 &lt;up,loopback,running,multicast&gt;metric 0 mtu 16384<br />
        options=3 &lt;rxcsum,txcsum&gt;inet 127.0.0.1 netmask 0xff000000<br />
        inet6 ::1 prefixlen 128<br />
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4<br />
        nd6 options=43 &lt;performnud,accept_rtadv&gt;pfsync0: flags=0&lt;&gt; metric 0 mtu 1460<br />
        syncpeer: 224.0.0.240 maxupd: 128 syncok: 1<br />
enc0: flags=0&lt;&gt; metric 0 mtu 1536<br />
pflog0: flags=100 &lt;promisc&gt;metric 0 mtu 33200<br />
*** Welcome to pfSense 2.0.2-RELEASE-nanobsd (i386) on pfsense ***&lt;/promisc&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum&gt;&lt;/up,loopback,running,multicast&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;&lt;/full-duplex&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;&lt;/full-duplex&gt;&lt;/performnud,accept_rtadv&gt;&lt;/rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate&gt;&lt;/up,broadcast,running,simplex,multicast&gt;</p>
</blockquote>
<p dir="auto">From the serial interface, I can ping the router and also google.de, when I ping from the terminal (Mac), still the same outcome. [EDIT: Pinging the Internet/Zyxel from the WAN was not possible yesterday. But it still seems that the LAN-&gt;WAN routing doesn't work?]</p>
]]></description><link>https://forum.netgate.com/post/378121</link><guid isPermaLink="true">https://forum.netgate.com/post/378121</guid><dc:creator><![CDATA[franzenobody]]></dc:creator><pubDate>Sun, 10 Feb 2013 15:11:06 GMT</pubDate></item><item><title><![CDATA[Reply to Cannot access Router&#x2F;Internet on Sun, 10 Feb 2013 13:10:04 GMT]]></title><description><![CDATA[<p dir="auto">The you have NAT enabled (the default if I recall correctly) the static route <a class="plugin-mentions-user plugin-mentions-a" href="/user/franzenobody">@<bdi>franzenobody</bdi></a>:</p>
<blockquote>
<p dir="auto">The static route in the Zyxel looks as follows<br />
Target: 192.168.2.0<br />
SUBNET: 255.255.255.0<br />
Gateway: 192.168.2.1 (PF-Sense)</p>
</blockquote>
<p dir="auto">is unnecessary since everything going out the pfSense WAN interface will appear to come from the pfSense WAN IP address.</p>
<p dir="auto">If you don't have NAT enabled in the pfSense box then the route is wrong: the gateway should be an IP address on the same subnet as the Zyxel LAN interface. In this case it should be the IP address of the pfSense WAN interface.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/franzenobody">@<bdi>franzenobody</bdi></a>:</p>
<blockquote>
<p dir="auto">If I ping from a client (192.168.2.100), I can reach the pfsense 192.168.2.1 and also 192.168.1.2, but not the Zyxel.<br />
When I try to ping the Zyxel the output is as follows:<br />
PING 192.168.1.1 (192.168.1.1): 56 data bytes<br />
36 bytes from pfsense.XXX (192.168.2.1): Destination Host Unreachable<br />
Vr HL TOS  Len   ID Flg  off TTL Pro  cks      Src      Dst<br />
4  5  00 5400 150c   0 0000  40  01 e0e7 192.168.2.100  192.168.1.1</p>
</blockquote>
<p dir="auto"><em>Destination host unreachable</em> suggests EITHER pfSense thinks its WAN interface is not "running" OR the pfSense routing table is "messed up" (perhaps you have been changing IP addresses or subnet or firewall rules or some combination; I have found a pfSense reboot is sometimes needed to clear things up after "major changes" in IP subnets.)</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/franzenobody">@<bdi>franzenobody</bdi></a>:</p>
<blockquote>
<p dir="auto">Does anyone have an idea where I could have made a mistake?</p>
</blockquote>
<p dir="auto">I suggest you reboot, try your pings again and if you don't get a ping response from the Zyxel, post the output of the pfSense shell command```<br />
ifconfig -a; /etc/rc.banner</p>
<pre><code class="language-and"></code></pre>
]]></description><link>https://forum.netgate.com/post/378107</link><guid isPermaLink="true">https://forum.netgate.com/post/378107</guid><dc:creator><![CDATA[wallabybob]]></dc:creator><pubDate>Sun, 10 Feb 2013 13:10:04 GMT</pubDate></item></channel></rss>