OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Can not ping OPNSense LAN Interface
« previous next »
  • Print
Pages: [1] 2

Author Topic: Can not ping OPNSense LAN Interface  (Read 6391 times)

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Can not ping OPNSense LAN Interface
« on: November 29, 2018, 11:49:26 am »
Hi all,

OPNSense runs fine but I have the Problem that I am not able to ping the FW LAN Interface (10.1.1.1) from within the local Network.

The Ping ist routed through the WAN Interface! Why?
Login in on the OPNSense Admin Interface at 10.1.1.1 works fine.

Here the traceroute:

traceroute to 10.1.1.1 (10.1.1.1), 30 hops max, 60 byte packets
 1  10.1.1.1 (10.1.1.1)  0.672 ms  0.446 ms  0.490 ms
 2  192.168.0.1 (192.168.0.1)  0.855 ms  0.877 ms  0.790 ms
 3  213-146-234-185.skytron.de (213.146.234.185)  3.467 ms  2.431 ms  2.202 ms
 4  10.255.2.116 (10.255.2.116)  3.402 ms  3.312 ms  3.223 ms
 5  10.255.7.97 (10.255.7.97)  3.156 ms !H  4.818 ms !H  4.734 ms !H

Any ideas?
Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #1 on: November 29, 2018, 03:07:57 pm »
Quote from: cyberganny on November 29, 2018, 11:49:26 am
Hi all,

OPNSense runs fine but I have the Problem that I am not able to ping the FW LAN Interface (10.1.1.1) from within the local Network.

The Ping ist routed through the WAN Interface! Why?
Login in on the OPNSense Admin Interface at 10.1.1.1 works fine.

Here the traceroute:

traceroute to 10.1.1.1 (10.1.1.1), 30 hops max, 60 byte packets
 1  10.1.1.1 (10.1.1.1)  0.672 ms  0.446 ms  0.490 ms
 2  192.168.0.1 (192.168.0.1)  0.855 ms  0.877 ms  0.790 ms
 3  213-146-234-185.skytron.de (213.146.234.185)  3.467 ms  2.431 ms  2.202 ms
 4  10.255.2.116 (10.255.2.116)  3.402 ms  3.312 ms  3.223 ms
 5  10.255.7.97 (10.255.7.97)  3.156 ms !H  4.818 ms !H  4.734 ms !H

Any ideas?
please provide more info so we can help.
are you on a VPN ?
10.1.1.1   ??? is this your lan ?
192.168.0.1  ??? what is this ?
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #2 on: November 29, 2018, 03:10:46 pm »
I am not on VPN

LAN (10.1.1.0)  <-> 10.1.1.1 (LAN Interface) OPNSense (WAN Interface) 192.168.0.1
all other IPs in the traceroute are on Provider Site

I can not ping the 10.1.1.1 out of the LAN (10.1.1.0).
« Last Edit: November 29, 2018, 03:13:28 pm by cyberganny »
Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #3 on: November 29, 2018, 03:13:02 pm »
Can you describe your scenario ?
is opnsense between your ISP modem ?

ISP Router >>>>>> OPNSENSE >>>>>> LAN NETWORK ?

have you checked your firewall rules ? on the LAN ?

Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #4 on: November 29, 2018, 03:21:25 pm »

+----------+                 +-------------------------------------------+     +--------------+
| Client     |                  | Lan intf.  |                 | WAN intf.        |      | ISP Router  |
|              | -> ICMP -> | 10.1.1.1 | OPNSense | 192.168.0.100 | -> |  192.168.0.1| -> ISP Net
| 10.1.1.5 |                  |                                                         |      |                   |
+----------+                 +-------------------------------------------+     +--------------+

Logged

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #5 on: November 29, 2018, 03:23:01 pm »
I checked the firewall rules all traffic to LAN Interface ist allowed
Logged

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #6 on: November 29, 2018, 04:34:08 pm »
What are you outband rules ?
where are you ping to where ?
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

JasMan

  • Full Member
  • ***
  • Posts: 151
  • Karma: 7
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #7 on: November 29, 2018, 04:38:33 pm »
I guess the IP range 10.0.0.0/8 is something in your providers network or some kind of management network of your modem. Because in the tracerout we can see your WAN address and after that you get an answer from 10.255.x.x. This address is also an part of 10.0.0.0/8.

Do you see any dynamic or static route on your OPNsense for 10.x.y.z networks? Any policy-based routing?
« Last Edit: November 29, 2018, 08:53:37 pm by JasMan »
Logged
Duck, Duck, Duck, Duck, Duck, Duck, Duck, Duck, Goose

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #8 on: November 29, 2018, 04:44:36 pm »
Yes my Provider seems also to you use 10.x.x.x Network.
10.255.7.97 is an IP of my provider.

How can I stop routing of 10.x.x.x target adresses out of my internal Network.
Logged

JasMan

  • Full Member
  • ***
  • Posts: 151
  • Karma: 7
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #9 on: November 29, 2018, 05:02:02 pm »
Normaly this should not happen because 10.1.1.1 is in your LAN and the next hop from your clients view.
Please check and post the routing and also the subnet masks of your client and OPNsense LAN interface.
Logged
Duck, Duck, Duck, Duck, Duck, Duck, Duck, Duck, Goose

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #10 on: November 29, 2018, 05:11:25 pm »
find attached the screenshot of the LAN interface config
Logged

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #11 on: November 29, 2018, 05:16:48 pm »
find attached the screenshot of the recent routing table
« Last Edit: December 07, 2018, 10:34:55 am by cyberganny »
Logged

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #12 on: November 29, 2018, 05:47:07 pm »
Subnetmask of the clients is always /24
Logged

JasMan

  • Full Member
  • ***
  • Posts: 151
  • Karma: 7
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #13 on: November 29, 2018, 08:55:09 pm »
Mmhh, looks fine  :)

Do you have any firewall rule for ICMP on the LAN interface where you've select an gateway?
Logged
Duck, Duck, Duck, Duck, Duck, Duck, Duck, Duck, Goose

cyberganny

  • Newbie
  • *
  • Posts: 22
  • Karma: 0
    • View Profile
Re: Can not ping OPNSense LAN Interface
« Reply #14 on: November 29, 2018, 09:02:45 pm »
Nope no Rules for ICMP in general
Logged

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Can not ping OPNSense LAN Interface
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2