Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New Interface Can't Access Internet

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 818 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jmarcum
      last edited by

      My pfSense server has 3 NIC's. I've been using only two of them for awhile and everything is fine. I setup a new interface (domain) on the third NIC. I need machines that are connected to the two internal interfaces to access the internet and machines on the other interface internally. On the new interface I added two firewall rules, one for IPv4 another for IPv6, that allows all LAN net traffic on any port to any destination on any port. From the diagnostics I can ping google.com with the domainB interface selected. From a Windows machine on domainB I cannot ping google by name nor by IP. The IP address of the domainB interface is set as the default gateway on the windows machine. Is there something else that I need to do so that machines on domainB can access the Internet?

      1 Reply Last reply Reply Quote 0
      • P Offline
        phil.davis
        last edited by

        The new interface/subnet is going to be OPT1. The firewall rules on OPT1 need to specify source OPT1net.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • J Offline
          jmarcum
          last edited by

          Got it figured out. The FW rule didn't like me using "LAN Net". Instead I specified a network and it's working fine now.

          1 Reply Last reply Reply Quote 0
          • P Offline
            phil.davis
            last edited by

            Yes, LAN net is only the subnet on the LAN interface.

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.