Multi wan- multi vlan nao pinga



  • Ola pessoal, tenho as seguintes regras no meu pfsense:

    2 WAN e 4 VLANs sendo que a WAN1 atende as vlans 3, 4 e 5 e a WAN2 atende a vlan70. Gostaria de isolar o trafego entre as vlans.  Mas quero que a vlan70 tenha acesso as outras. Eu consigo pingar o ip das vlans3, 4 e 5 pela vlan70 mas nao consigo pingar nenhuma maquina na vlan. Por exemplo, estou conectado em uma estacao com ip da vlan70(192.168.70.10). Consigo pingar a vlan3, vlan4 e vlan5 do firewall (172.16.100.1, 192.168.7.1, 192.168.3.1) mas nenhuma maquina depois (172.16.100.x) . O mesmo acontece com as outras vlans. Quando pingo um endereco interno da vlan3, 4, 5 meu pacote sai pela WAN e se perde.

    WAN1:
    Proto Source Port Destination Port Gateway Queue Schedule Description

    • RFC 1918 networks * * * * *   Block private networks
    • Reserved/not assigned by IANA * * * * * * Block bogon networks
      IPv4 TCP/UDP * * 172.16.100.150 80 (HTTP) * none   NAT HTTP

    WAN2:
    Proto Source Port Destination Port Gateway Queue Schedule Description

    • RFC 1918 networks * * * * *   Block private networks
    • Reserved/not assigned by IANA * * * * * * Block bogon networks

    VLAN3:
    Proto Source Port Destination Port Gateway Queue Schedule Description
    IPv4 * VLAN3 net * VLAN70 net * * none   block 3 > 70 
    IPv4 * VLAN3 net * VLAN5 net * * none   block 3 > 5 
    IPv4 * VLAN3 net * VLAN4 net * * none   block 3 > 4 
    IPv4 * VLAN3 net * * * * none                   pass

    VLAN4:
    Proto Source Port Destination Port Gateway Queue Schedule Description
    IPv4 * VLAN4 net * VLAN70 net * * none   block 4 > 70 
    IPv4 * VLAN4 net * VLAN5 net * * none   block 4 > 5 
    IPv4 * VLAN4 net * VLAN3 net * * none   block 4 > 3 
    IPv4 * VLAN4 net * * * * none                   pass

    VLAN5:
    Proto Source Port Destination Port Gateway Queue Schedule Description
    IPv4 * VLAN5 net * VLAN3 net * * none   block 5 > 3 
    IPv4 * VLAN5 net * VLAN70 net * * none   block 5 > 70 
    IPv4 * VLAN5 net * VLAN4 net * * none   block 5 > 4 
    IPv4 * VLAN5 net * * * * none                   pass

    VLAN70:
    Proto Source Port Destination Port Gateway Queue Schedule Description
    IPv4 * VLAN70 net * * * WAN2 none             pass