Routing From Router To Firewall to another Fail



  • Hi

    I Would Like to asking about my issue is this

    Router To > Pfsense Then To Another Router

    Router IP=192.168.0.1/24
    WAN IP=192.168.0.50
    Lan IP=10.10.10.1/23

    Router Bandwith To Pfsense (WAN)then from Pfsense Out (LAN)

    My Question Is From Lan communicate to WAN 10.10.10.1 ping to 192.168.0.1 can

    but from 192.168.0.1 ping to 10.10.10.1 can't

    How can i solve it?



  • You would need to pass ping on the WAN of the box that currently can't be pinged.

    Sounds like you have 2 or more layers of NAT.



  • Ya~

    so that im thinking ~

    how to make it~~

    because i want to connect to my CCTV

    how about if i set DDNS

    but i try set DDNS at Pfsense after connect back using the url it direct jump to my router~

    so how can i make routing?



  • 我也不知道…  也许我还不清楚你的网路怎么样.

    Maybe draw a picture of your network?



  • @kejianshi:

    我也不知道…  也许我还不清楚你的网路怎么样.

    Maybe draw a picture of your network?

    哦~你说中文~
    容易多了~
    我的问题是,
    我有个router1有互联网的 192.168.0.1/24
    然后我的pfsense就弄个
    WAN(192.168.0.50)(wan就是在我的router放internet进去~)
    LAN(10.10.10.1/23)(lan就是接出来放另外一个router2限制下载之类)

    我想这样》我的电脑连接我的router然后能直接连接LAN的CCTV

    我一直想不通的就是,我电脑连接LAN能ping 到 192.168.0.1~
    但是我连接router1 就不能ping 10.10.10.1

    明白?



  • 明白

    internet > router1 LAN 192.168.0.1/24 > pfsense wan 192.168.0.50 + LAN 10.10.10.1/23

    From 10.10.10.x you can ping anything on 192.168.1.0/24

    but from 192.168.1.0/24 you can't ping anything on 10.10.10.0/24 (LAN side)

    对不对?

    This is very normal.  NAT will prevent it

    I'm pretty sure you have 2 layers of NAT.

    Make things simple.  Get rid of all the routers EXCEPT pfsense if possible.

    I could tell you how to forward a bunch of ports, but better to simplify your network first.



  • @kejianshi:

    明白

    internet > router1 LAN 192.168.0.1/24 > pfsense wan 192.168.0.50 + LAN 10.10.10.1/23

    From 10.10.10.x you can ping anything on 192.168.1.0/24

    but from 192.168.1.0/24 you can't ping anything on 10.10.10.0/24 (LAN side)

    对不对?

    This is very normal.  NAT will prevent it

    I'm pretty sure you have 2 layers of NAT.

    Make things simple.  Get rid of all the routers EXCEPT pfsense if possible.

    I could tell you how to forward a bunch of ports, but better to simplify your network first.

    对对对,要怎样做呢?


Log in to reply