Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN -> DMZ don't work

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      johbra
      last edited by

      I have a computer with 1.2-RC3 and four NICs:
      WAN = DHCP
      LAN = 192.168.110.1/24
      DMZ = 192.168.111.1/24
      WLAN = 192.168.109.1/24

      I've added the following pass-rule to the top of the list of rules for the LAN interface:
      Proto  Source  Port  Destination  Port  Gateway  Schedule Description 
      *          *        *        *          *        *          *            *

      I have one accespoint with ip 192.168.109.2 and one laptop with ip 192.168.109.151 on the WLAN interface. When i try to ping either one of them, I get no response. What could be wrong?
        I can ping the WLAN-address of pfsense (192.168.109.1) by the way…

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Do you have a rule on the WLAN interface that allows traffic?
        Got a firewall on the WLAN client that might block the pings?

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • J
          johbra
          last edited by

          1. I have the same rule on the WLAN interface.
          2. The laptop on the WLAN-interface can ping the accespoint so…pinging from LAN should not be a problem, right?
          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            to 2:
            ping is not bidirectional.
            If you have a firewall on the Laptop that blocks pings the laptop cannot be pinged :)

            Can you ping the laptop if you use the ping-utility on pfSense?
            If not then the problem is definitly on the laptop end. (since the laptop is able to ping the pfSense)

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • J
              johbra
              last edited by

              I can ping the accesspoint from the pfSense tool, but i can't ping the accespoint from my computer on the LAN.

              1 Reply Last reply Reply Quote 0
              • P
                Perry
                last edited by

                Proto  Source  Port  Destination  Port  Gateway  Schedule Description   
                *          *        *        *          *        *          *            *

                Proto    Source      Port  Destination  Port  Gateway  Schedule Description   
                *      Lan subnet      *        *          *        *          *            *

                Proto    Source          Port  Destination  Port  Gateway  Schedule Description   
                *      Wlan subnet        *        *          *        *          *            *

                /Perry
                doc.pfsense.org

                1 Reply Last reply Reply Quote 0
                • J
                  johbra
                  last edited by

                  I've added the rules you sudjested Perry, to both my LAN and my WLAN interface. I still can't ping the access-point from my computer on my LAN-interface.

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    you're writing about pinging the AP.
                    what kind of AP is that?
                    somehow i suspect your AP is doing NAT and you have on the AP the WLAN subnet on WAN and WLAN side.

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • J
                      johbra
                      last edited by

                      I only use the LAN-ports of the "AP" but…you got me thinking Gruens. I just changed in the AP configuration and got it up and running. Now i can reach the LAN from the WLAN.
                        I but i can't reach the WLAN from the LAN though, but that's not important enough for me to continue messing with the AP for  :) And besides...my primary aim is to learn how to manage the pfsense box, not the AP  ;D

                      Thanks for the help everyone!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.