Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense behind a locked ISP router

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      TMS
      last edited by

      Ok i have set up a pfsense box and am having problems with the WAN. My box is behind a locked Simens Gigaset Router that i cant change since the ISP pretty much makes it mandatory to use that router since the also provide Internet TV over the same thing.

      The router does not have bridged mode or pretty much anything that is unlocked. The ISPs custom firmware has got everything locked down.

      So how do i get my pfsense box assess to the internet to make a captive portal hotspot.

      I have been trying lots of different settings and nothing is helping me.

      And i know most of you will say change your ISP but others are even more crappy.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        If you are using pfSense primarily to provide a captive portal you can just put it behind your ISP router. Doing that does mean that clients behind pfSense will be behind double NAT which can cause problems for some services.
        You may have to change the pfSense LAN subnet to avoid it conflicting with the existing subnet provided by your ISP router.
        What is the exact modem/router you have? What ISP are you using? Someone else here may have already solved this.

        Steve

        1 Reply Last reply Reply Quote 0
        • T Offline
          TMS
          last edited by

          Siemens Gigaset SX 763 is the router.

          My router is 192.168.1.1 so i need to put my lan on lets say 192.168.2.1.

          The problem is that i do not know how to setup pfsense wan behind the router and that is why im asking for some help here.

          Thx for the reply.

          What im planing to do is in attachment

          netdiag1.png
          netdiag1.png_thumb

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            Just set the pfSense wan to dhcp and it will receive it's IP details from the router as any other client would.

            If your ISP is providing your TV using vlans there are other users here who have configured pfSense to replicate that. It's a lot more work and you'd have to get a different modem though. Maybe not worth it for your situation.

            Steve

            1 Reply Last reply Reply Quote 0
            • T Offline
              TMS
              last edited by

              I have it set to DHCP and it is still not working. The pfsense box has no internet assess. I connected a cable from the router lan port to the pfsense wan port. The cable seams to be ok as i used it already on other stuff.

              The uplink shows as being up with a ip on the same subnet as the router.

              Thx.

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Hmm, ok so pfSense is receiving IP details correctly via dhcp, that would include IP address, subnet, gateway and DNS server(s)? But you have no internet access from it. How are you testing that?

                I assume you have access to the pfSense webgui from its LAN side. Have a look at the routing table in Diagnostics: Routes: Is the default route set as your ISP router?

                Steve

                1 Reply Last reply Reply Quote 0
                • T Offline
                  TMS
                  last edited by

                  Im testing it by the ability to see packages. If it does not find packages it has no connection right.

                  Yes i can assess the webgui and il take a look at the routes when i get home tomorrow. Thx for the suggestion.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Ah, the boxes ability to see packages is certainly proof it has internet access but there are a few things that can prevent that whilst general internet is working.
                    Try the Diagnostics: Ping: page instead. Pinging from the console command line gives an even better result as it uses the system routing table instead of specifying a gateway.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.