Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi LAN single WAN

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Albertus
      last edited by

      I have the following:

      1. WAN - 172.16.20.10/24
      2. LAN1 - 192.168.3.0/24 (192.168.3.254/24)
      3. LAN2 - 192.168.4.0/24 (192.168.4.254/24)

      WAN working great from both LAN's but i would like "connect" both LAN's as i would like to ping for instance:

      192.168.3.100 to 192.168.4.100 and
      192.168.4.100 to 192.168.3.100

      i used google to find solution but with no luck yet.

      Anyone who can guide me in correct direction?

      Thank you

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        This should really work out of the box - what are you rules on lan1 and lan2?  Your problem is most likely firewall on 4.100 blocking pings from 3.100, and vice versa

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • A Offline
          Albertus
          last edited by

          Thank you for reply my rules are:

          LAN1:

          Anti-Lockout Rule

          IPv4 * 192.168.3.0/24 * * * * none   ANY

          LAN2:

          IPv4 * 192.168.4.0/24 * * * * none   ANY

          –--------------------------------------------------

          3.100 and 4.100 are both windows 8 laptops, but no luck pinging each other.

          1 Reply Last reply Reply Quote 0
          • G Offline
            G.D. Wusser Esq.
            last edited by

            If you have some kind of antivirus or firewall running on host computers, they would normally block other subnets.

            1 Reply Last reply Reply Quote 0
            • A Offline
              Albertus
              last edited by

              So no routing to be set only firewall settings then 2 pc's on different ip ranges should ping each other?

              1 Reply Last reply Reply Quote 0
              • A Offline
                Albertus
                last edited by

                I tested firewall disabling and it works.

                Just another question:

                if i want pc's to see both ip ranges without disabling firewalls how would i do it?

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  The PCs can see both ranges but the PC firewall is blocking inbound traffic from other than the local network.  You would have to tell the PC firewall that 192.168.2.0/24 and 192.168.3.0/24 are both to be considered local, trusted networks.  How to do that is outside the scope of pfSense.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.