• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

PFSense VLANs & Internet Trouble

AnotherUser

Limp Gawd
Joined
Oct 7, 2011
Messages
137
Alright, so I have a vlan setup for a "guest" network. I have that vlan assigned to an interface (this is all in VMWARE). VMware network and vlans, interface assignments.

I can get a DHCP address on the VMWare machine and can ping the gateway.

I cannot however, ping anything on the internet. client ping 8.8.8.8

Here are the guest interface firewall rules, wan fiewall rules and 2

Guest Interface Config 1

client ipconfig

firewall logs for client after pinging 192.168.250.1 and 8.8.8.8 . As you can see it does not show the pinging to 8.8.8.8 so here is a packet capture of it doing so.

Diagnostics Ping

NAT Mappings

I'm fresh out of ideas, what stupid thing am I missing?
 
1. Delete your WAN firewall rules. you are leaving your entire network exposed to internet.

Do a running ping to 8.8.8.8 -t on the client and then look at the firewall logs. See what the results are.
 
1. Delete your WAN firewall rules. you are leaving your entire network exposed to internet.

Do a running ping to 8.8.8.8 -t on the client and then look at the firewall logs. See what the results are.

It's already gone, I forgot I had that in as a test. As you can see from here and here they do not show up in the log, it's very odd.

I can get to the PF interface from that machine, it can get a DHCP address but no internet traffic can be captured.
 
Have you set any iptable rules? It sounds like possibly a prerouting rule?

iptables -t nat -L -n -v (should show you all the rules set).
 
Are you by chance running the 2.2 RC? I had a similar issue, but it disappeared on me. Not sure exactly if it happened during an upgrade to the latest nightly, or because I specifically added a rule on my HOME interface to allow traffic to port 53. Still learning the setup myself.

How I found DNS for me was being blocked, check out the Status > System Logs > Firewall. Look for things being blocked that you don't think should be. Easy to add a rule to allow said traffic to pass.
 
Back
Top