OPNsense Forum

English Forums => General Discussion => Topic started by: mercuryin on June 12, 2020, 09:44:48 pm

Title: Two subnets
Post by: mercuryin on June 12, 2020, 09:44:48 pm
Hello,

I hope you can help me please.

I have two interfaces, wan and lan. Lan subnet is 10.20.30.0.

I have a bt smart hub 2 that I´m not using anymore because now I use opnsense on Unraid with a quad nic and I would like to repurpose that router and all the wifi disk attached a wireless access points within my 10.20.x.x network.

The problem is BT do not allow you to modify the subnet, so I have to stick with the one configured 192.168.1.254. So I have disable the DHCP on this router and connected one of it lan ports to my switch and all the wireless devices are working getting DHCP from OPNsense within the range 10.20.X.X.

But as I can´t change the range on the BT router and the interface ( gui ) is on 192.168.1.254, is there any way I can access from my network on 10.20.X.X to this interface without having to configure for a few minutes one pc in the network to that subnet ? I know is just for a few minutes but I would like to be able to connect to that subnet without touching anything.

Thanks !
Title: Re: Two subnets
Post by: anicoletti on June 12, 2020, 10:26:53 pm
I could be wrong, but I believe you just need to add an additional Virtual IP to your LAN interface. This is done under Firewall \ Virtual IPs \ Settings. Add 192.168.1.1/24 and it should allow routing between the two networks for you.
Title: Re: Two subnets
Post by: mercuryin on June 12, 2020, 10:43:20 pm
Thanks for replying.

I already tried that, but doesn´t work. No ping, nothing between one subnet to other.
Title: Re: Two subnets
Post by: marjohn56 on June 13, 2020, 07:03:34 am
You should be able to put the BT Modem/Router into pass-through mode and just let Opnsense handle the  PPPoE etc, thus not needing your PC to talk to the BT unit at all; it also means there is no double NAT. What model is the BT Modem/Router?
Title: Re: Two subnets
Post by: mercuryin on June 13, 2020, 08:28:37 am
Opnsense is already doing everything here from ppoe to dhcp, everything. I just want to use the bt smarthub 2 for the wireless part, and no double nat is involved here because the dhcp is disabled, the wireless client are receiving dhcp from opnsense within 10.x.x.x as the cable lan clients and are able to communicate within them is just that the Bt router do not allow you to assign a different subnet otherwise I just change and that's it, you can't. No bridge mode, you even can't disable the wan part of that router and all the time I can hear an small rely inside of the router trying to do ppoe.  But well that doesn't matter, the router take for it own interface web a ip within 192. and as I said you can't change that so just wanted to be able to access that interface within my main and only lan 10.x.x without the hassle of modifying my client dhcp for a few minutes and then reconfigure. I think that this should be easy peasy for this distro, i did it in the past but don't remember how to achieve that. Thanks for your help
Title: Re: Two subnets
Post by: mercuryin on June 13, 2020, 01:07:13 pm
Any idea ?  :) Thanks !
Title: Re: Two subnets
Post by: marjohn56 on June 13, 2020, 01:31:29 pm
Apart from adding the Alias IP to the LAN, have you added a gateway for the 192.168* address with the gateway being the address of the modem. You'll also need a firewall rule that allows access to the 192* subnet from the LAN.
Title: Re: Two subnets
Post by: mercuryin on June 13, 2020, 02:27:09 pm
I have tried all that but I should be doing something wrong because I can´t get it fixed. Thanks
Title: Re: Two subnets
Post by: anicoletti on June 15, 2020, 04:08:49 pm
Do you have a firewall rule allowing the traffic on LAN? If not, then it won't pass that traffic across since normal LAN traffic just chats to each other, but since the firewall is acting as the bridge between these networks you need to allow it.
Title: Re: Two subnets
Post by: curioustech on June 15, 2020, 04:18:55 pm

Do you have a firewall rule allowing the traffic on LAN? If not, then it won't pass that traffic across since normal LAN traffic just chats to each other, but since the firewall is acting as the bridge between these networks you need to allow it.

This is correct. Can you post a screenshot of Firewall: Rules: LAN?