How to turn off Firewall on OPT1 side


  • Here is the problem:
    Clients from LAN network can see the OPT1 network, but clients from OPT1 network can't se users from LAN network  :(
    Here is my pfsense configuration:

    And that's the problem

    Please help!!!


  • This rule at OPT allows only the single IP 192.168.18.92 to establish connections to the lan-subnet. Have you tried from the client with this IP? If you want a larger range to be allowed change the source of that rule. Also make sure all Clients at OPT have the OPT IP of the pfSense as gateway.

  • LAYER 8 Moderator

    @hoba: That was my first thought, too.

    Another point: is the pfsense device the default gateway for both networks on LAN and OPT1?


  • It should be. If not you need static routes so the clients find their way to LAN and OPT at the clients or their default gateway.

  • LAYER 8 Moderator

    Indeed, that's what I mean. And 'cause it has .5 on the OPT-side but .2 on the LAN-side, there's the possibility another (default) router is in the game. If not, looking at the pflog is next, finding out the reason why a packet is blocked when travelling from OPT to LAN.

    Greets
    Grey


  • It's all rigt with configuration of computers on both sides of GATEWAY (my computer 18.92). Routes are all rigt too. Pfsense blocks all packets from OPT1 network (only VPN can pass) and I can't do nothing with it  :( There is even no ping from OPT1 network:
    –-----------------------------------
    Pinging 192.168.18.5 with 32 bytes of data:

    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.

    Ping statistics for 192.168.18.5:
        Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

    But VPN works great  ???
    pfsense firewall block all packets on OPT1 side (only VPN connection pass), can I turn it off?


  • show me a tracert from this opt client to a lan IP. I'm using pfSense with multiple interfaces and firewalling between them even with aliases and it works like expected. Do you really see blocks at status>systemlogs, firewall? if yes, what rule does cause the block (click the small block icon in front of the line).