Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dhcp gateway from server not from interface

    Scheduled Pinned Locked Moved DHCP and DNS
    12 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      karimwassim
      last edited by

      Actually on  PFsense v2.2.2
      my problem :
      I have lan dhcp managed from pfsense , on my lan network  I managed some computer without accessing internet and I put that computer with statut ip and don't set gateway but that computer steel get internet  what to do ??????

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        well if your setting static on a lan pc, you need to give it a gateway (normally this would be pfsense IP on that network segment - ie lan)

        yeah without that your not going anywhere other than other ips on that segment.

        This normally handled via dhcp, but if doing static

        Lets say your pfsense lan IP is 192.168.1.1/24

        So your pc you might make 192.168.1.19/24
        gateway 192.168.1.1
        dns 192.168.1.1

        And you should be good to go.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • K
          karimwassim
          last edited by

          Yes thanks for the answer.
          but I dont want internet for that computer.
          in my pfsense dhcp in lan i have computers that must access internet but for the other computer I don't want internet Just thé lan network I change the defaut gateway for that computer in pfsense not working I put statut ip in Windows without gateway but that computer get internet is it a bug or something I forget to do

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            if you don't have a gateway set on the pc then its NOT Possible for them to get to the internet, unless they are using a proxy that is on their local lan and that is what is giving them internet.  For example if you point to pfsense as proxy and your running proxy on pfsense then you could get internet that way.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • K
              karimwassim
              last edited by

              Thanks
              yes i'm using proxy squid and that computers are joined to windows domain who automatic generate script for that computers with gpo with proxy adress in browser .
              so if I disable the proxy adress from the browser and don't put the gateway with statut ip all will be ok ?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                if no proxy and no gateway then there is no way for them to get off their segment, so no internet.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • K
                  killmasta93
                  last edited by

                  couldn't the internet be blocked though the firewall for that IP 192.168.1.19/24?

                  Tutorials:

                  https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    not if using a proxy no..  Proxy is the one going to the internet not 192.168.1.19

                    Normally if you have a proxy you control internet access as the proxy with user auth, etc.  Not by removing the gateway.  And your firewall rules would only allow the proxy to go out anyway, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • K
                      killmasta93
                      last edited by

                      ooo gotcha thanks for clearing that up so proxy is first then firewall for LAN

                      Tutorials:

                      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                      1 Reply Last reply Reply Quote 0
                      • K
                        karimwassim
                        last edited by

                        thanks for every body

                        i resolved my situation with Schedules for all clients who i don't want to not accessing internet

                        the proxy server is enabled for all client , and the default gateway also ,  just make a rule reject in firewall with alias of the specified clients and enable Schedule for all the week for that clients and all working perfectly

                        thank you for help

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          so you denied them access at the proxy, and then rules at the firewall to block any non proxy traffic that might go out.

                          Normally in work place all direct traffic would be blocked from all clients, and only exceptions would be made for non proxy away applications or things that don't work with the proxy.  Proxy is where you content filtering would be done, if you allow clients to not use the proxy and direct go out the internet then very simple for them to bypass your content filtering and surf p0rn for example.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            @karimwassim:

                            just make a rule reject in firewall with alias of the specified clients and enable Schedule for all the week for that clients and all working perfectly

                            I don't get what's this "schedule" good for. Just set up a permanent block rule for those. Why are you scheduling something for 24/7?

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.