Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN to LAN allow rules

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      itam1212
      last edited by

      I'm having a problem with traffic between my VLAN40 (192.168.40.0/24) and my main LAN (192.168.2.1)
      I'm able to ping machines from both LAN or VLAN to other side and get reply.

      I have a print server (192.168.2.250) on my main LAN which I need to access from a computer belongs to VLAN40.

      I have the following firewall rules:
      LAN

      VLAN40

      but I am unable to print and my firewall logs are full of these:

      Any ideas what am I doing wrong?
      I've read about Asymmetric Routing and tried few of the tips (Bypass firewall rules for traffic on the same interface) without luck.

      Thanks a lot for your time

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        1st thing- think of all the tabs as gates at their interface.

        On LAN get rid of the rule with "source" as VLAN40 net.

        and

        On VLAN40  get rid of the rule with "source as LAN net.

        Truthfully the first rule on each of them would allow the traffic to the other. So both rules following it would not be needed.
        And the first rule would also allow traffic to all your other VLANs as well.

        2nd try this-  Go to NAT and on outbound hit save.  Screen shot of that page would be nice.

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • chpalmerC
          chpalmer
          last edited by

          LAN is also a /24?

          Triggering snowflakes one by one..
          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

          1 Reply Last reply Reply Quote 0
          • I
            itam1212
            last edited by

            Thank you chpalmer appreciate the help.

            I've tried your suggestions but same error in the log.

            and yes I believe 192.168.2.1 / 255.255.255.0 for my main LAN. is this a problem?
            Here is the screenshot of NAT > OutBound

            1 Reply Last reply Reply Quote 0
            • I
              itam1212
              last edited by

              another interesting thing is that in the firewall log I only see 192.168.2.250 appears as the Source IP, when I try to filter is as Destination I get no results.
              is it just picking up on the acknowledgment and not initial request?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Nothing to do with outbound NAT.

                If you expect some sort of auto-discover to work across the router you're probably going to be disappointed.

                Add the printer directly, don't try to browse for it.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • I
                  itam1212
                  last edited by

                  I don't expect Auto Discovery.
                  I am able to find and add the printer but when trying to print it fails.

                  I can ping the print server or telnet over port 9100 (blank screen) but the test prints fail and the FW log shows me those entries.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Out of state - totally normal. Check the default gateway in the printer / print server.  Hmm. Being able to ping it probably means that's not the problem.

                    Something in the print server that prevents printing from "foreign" networks, perhaps?

                    The bottom two rules on both LAN and VLAN40 are useless.  Delete them.

                    https://doc.pfsense.org/index.php/Firewall_Rule_Basics

                    https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

                    https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Out of state traffic can also point to a problem with asyncronous routing..  Since the firewall never saw the syn to setup the state, but just sees the syn,ack like what your traffic is showing.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • I
                        itam1212
                        last edited by

                        @Derelict:

                        Something in the print server that prevents printing from "foreign" networks, perhaps?

                        Thanks you are correct.
                        my network setting on the print server were wrong.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.