[pfSense Support] OPT1 and LAN cannot communicate

2010-06-13 Thread Josh

Here's my setup:
WAN - dhcp via cable modem
LAN - to switch with gigabit wired connections 192.168.1.x
OPT1 - to linksys WAP 192.168.2.x

Any devices on subnet 2 cannot access subnet 1, and vice versa, even 
though I have rules which allow it. The problem is that I have a print 
server on subnet 1 that devices on 2 need to access. Pings will not go 
through from either side, though from pfsense I can ping subnet 2 from 
the OPT interface, and can ping subnet 1 from the LAN interface. Devices 
of the same subnet see each other with no problems.


Here are my rules

LAN:
allow any from OPT subnet to LAN subnet
allow any from LAN subnet to OPT subnet --I tried adding this rule 
after I discovered my problem and it did not help.


OPT:
allow any from LAN subnet to OPT subnet
allow any from OPT subnet to LAN subnet --I tried adding this rule 
after I discovered my problem and it did not help.


Any suggestions? I'm sure it's something simple, but my networking 
knowledge is novice level.


Thanks!

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



Re: [pfSense Support] OPT1 and LAN cannot communicate

2010-06-13 Thread Chris Buechler
On Sun, Jun 13, 2010 at 8:52 PM, Josh anothernum...@atlanticbb.net wrote:
 Here's my setup:
 WAN - dhcp via cable modem
 LAN - to switch with gigabit wired connections 192.168.1.x
 OPT1 - to linksys WAP 192.168.2.x

 Any devices on subnet 2 cannot access subnet 1, and vice versa, even though
 I have rules which allow it. The problem is that I have a print server on
 subnet 1 that devices on 2 need to access. Pings will not go through from
 either side, though from pfsense I can ping subnet 2 from the OPT interface,
 and can ping subnet 1 from the LAN interface. Devices of the same subnet see
 each other with no problems.

 Here are my rules

 LAN:
 allow any from OPT subnet to LAN subnet

This is wrong.

 allow any from LAN subnet to OPT subnet --I tried adding this rule after I

This is the only rule you need on LAN.


 OPT:
 allow any from LAN subnet to OPT subnet

this is wrong.

 allow any from OPT subnet to LAN subnet --I tried adding this rule after I
 discovered my problem and it did not help.


That is the only rule you need on OPT.

I suspect your WAP is blocking it, or a host firewall. Use the Diag 
Packet capture screen to confirm traffic is entering and leaving the
appropriate interfaces, and as long as it is, you know the firewall is
ok and need to troubleshoot at the hosts and AP.

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



Re: [pfSense Support] OPT1 and LAN cannot communicate

2010-06-13 Thread Adam Thompson
(Going from memory here...)
Check the Block RFC1918 addresses checkbox on the Interface configuration 
pages.  It should be set on WAN but not OPT1 or LAN.
-Adam Thompson athom...@athompso.net

Sent from my BlackBerry device on the Rogers Wireless Network

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



Re: [pfSense Support] OPT1 and LAN cannot communicate

2010-06-13 Thread Gary Buckmaster
This won't be an issue if you're running 1.2.3-release, as the block 
RFC1918 option is only on the WAN interface. 


Adam Thompson wrote:

(Going from memory here...)
Check the Block RFC1918 addresses checkbox on the Interface configuration 
pages.  It should be set on WAN but not OPT1 or LAN.
-Adam Thompson athom...@athompso.net

Sent from my BlackBerry device on the Rogers Wireless Network

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org

  



-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org