• Hello everyone,

    My current setup is Internet-CableModem-Pfsense-Switch-Devices

    Pfsense gets the wan's ip from dhcp. The lan is

    What  I would like to do is setup another network using a Cisco 2621. I would want to do Internet-CableModem-Pfsense-Switch<-PC's on 192.168.1.x
                                                                                                                                                                                Cisco 2621XM-Switch-PC's on another subnet. (I am open to any address and subnet)

    Does anyone know if this is possible? I have tried setting up the 2621 using Dhcp on the side connected to 192.168.1.x (dhcp is on windows server and it received an ip address fine.  Then I set the other interface to

    The router is able to ping everything on 192.168.1.x and is able to ping internet websites. However the devices in the 172.16.1.x network cannot ping past the 2621. (but can ping the router

    If anyone can point me in the right direction, that would be extremely helpful. Thanks in advance!


  • pfSense needs:

    • a firewall rule allowing traffic from the in on the LAN interface
      -  a route added to - that needs you to add a gateway 192.168.1.x (x is the address of the Cisco on the pfSense LANnet) and add a route going to that gateway. Then it knows how to return packets.
    • add manual NAT rules to pfSense WAN to NAT as it goes out to the internet ( gets NAT done automatically in the default setup)
      Others please comment if I have missed a step here, but I think that is enough to get a subnet behind the pfSense LAN to talk through it to the internet.

  • Thank you so much! I did exactly as you implied and now 172 can reach 192 and the internet. Thanks again! :D