Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    How to turn off Firewall on OPT1 side

    Firewalling
    3
    7
    6772
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      masters last edited by

      Here is the problem:
      Clients from LAN network can see the OPT1 network, but clients from OPT1 network can't se users from LAN network  :(
      Here is my pfsense configuration:

      And that's the problem

      Please help!!!

      1 Reply Last reply Reply Quote 0
      • H
        hoba last edited by

        This rule at OPT allows only the single IP 192.168.18.92 to establish connections to the lan-subnet. Have you tried from the client with this IP? If you want a larger range to be allowed change the source of that rule. Also make sure all Clients at OPT have the OPT IP of the pfSense as gateway.

        1 Reply Last reply Reply Quote 0
        • JeGr
          JeGr LAYER 8 Moderator last edited by

          @hoba: That was my first thought, too.

          Another point: is the pfsense device the default gateway for both networks on LAN and OPT1?

          Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

          If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

          1 Reply Last reply Reply Quote 0
          • H
            hoba last edited by

            It should be. If not you need static routes so the clients find their way to LAN and OPT at the clients or their default gateway.

            1 Reply Last reply Reply Quote 0
            • JeGr
              JeGr LAYER 8 Moderator last edited by

              Indeed, that's what I mean. And 'cause it has .5 on the OPT-side but .2 on the LAN-side, there's the possibility another (default) router is in the game. If not, looking at the pflog is next, finding out the reason why a packet is blocked when travelling from OPT to LAN.

              Greets
              Grey

              Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

              1 Reply Last reply Reply Quote 0
              • M
                masters last edited by

                It's all rigt with configuration of computers on both sides of GATEWAY (my computer 18.92). Routes are all rigt too. Pfsense blocks all packets from OPT1 network (only VPN can pass) and I can't do nothing with it  :( There is even no ping from OPT1 network:
                –-----------------------------------
                Pinging 192.168.18.5 with 32 bytes of data:

                Request timed out.
                Request timed out.
                Request timed out.
                Request timed out.

                Ping statistics for 192.168.18.5:
                    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

                But VPN works great  ???
                pfsense firewall block all packets on OPT1 side (only VPN connection pass), can I turn it off?

                1 Reply Last reply Reply Quote 0
                • H
                  hoba last edited by

                  show me a tracert from this opt client to a lan IP. I'm using pfSense with multiple interfaces and firewalling between them even with aliases and it works like expected. Do you really see blocks at status>systemlogs, firewall? if yes, what rule does cause the block (click the small block icon in front of the line).

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post