OPNsense Forum

Archive => 18.7 Legacy Series => Topic started by: cyberganny on November 29, 2018, 11:49:26 am

Title: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 11:49:26 am
Hi all,

OPNSense runs fine but I have the Problem that I am not able to ping the FW LAN Interface (10.1.1.1) from within the local Network.

The Ping ist routed through the WAN Interface! Why?
Login in on the OPNSense Admin Interface at 10.1.1.1 works fine.

Here the traceroute:

traceroute to 10.1.1.1 (10.1.1.1), 30 hops max, 60 byte packets
 1  10.1.1.1 (10.1.1.1)  0.672 ms  0.446 ms  0.490 ms
 2  192.168.0.1 (192.168.0.1)  0.855 ms  0.877 ms  0.790 ms
 3  213-146-234-185.skytron.de (213.146.234.185)  3.467 ms  2.431 ms  2.202 ms
 4  10.255.2.116 (10.255.2.116)  3.402 ms  3.312 ms  3.223 ms
 5  10.255.7.97 (10.255.7.97)  3.156 ms !H  4.818 ms !H  4.734 ms !H

Any ideas?
Title: Re: Can not ping OPNSense LAN Interface
Post by: Julien on November 29, 2018, 03:07:57 pm
Hi all,

OPNSense runs fine but I have the Problem that I am not able to ping the FW LAN Interface (10.1.1.1) from within the local Network.

The Ping ist routed through the WAN Interface! Why?
Login in on the OPNSense Admin Interface at 10.1.1.1 works fine.

Here the traceroute:

traceroute to 10.1.1.1 (10.1.1.1), 30 hops max, 60 byte packets
 1  10.1.1.1 (10.1.1.1)  0.672 ms  0.446 ms  0.490 ms
 2  192.168.0.1 (192.168.0.1)  0.855 ms  0.877 ms  0.790 ms
 3  213-146-234-185.skytron.de (213.146.234.185)  3.467 ms  2.431 ms  2.202 ms
 4  10.255.2.116 (10.255.2.116)  3.402 ms  3.312 ms  3.223 ms
 5  10.255.7.97 (10.255.7.97)  3.156 ms !H  4.818 ms !H  4.734 ms !H

Any ideas?
please provide more info so we can help.
are you on a VPN ?
10.1.1.1   ??? is this your lan ?
192.168.0.1  ??? what is this ?
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 03:10:46 pm
I am not on VPN

LAN (10.1.1.0)  <-> 10.1.1.1 (LAN Interface) OPNSense (WAN Interface) 192.168.0.1
all other IPs in the traceroute are on Provider Site

I can not ping the 10.1.1.1 out of the LAN (10.1.1.0).
Title: Re: Can not ping OPNSense LAN Interface
Post by: Julien on November 29, 2018, 03:13:02 pm
Can you describe your scenario ?
is opnsense between your ISP modem ?

ISP Router >>>>>> OPNSENSE >>>>>> LAN NETWORK ?

have you checked your firewall rules ? on the LAN ?

Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 03:21:25 pm

+----------+                 +-------------------------------------------+     +--------------+
| Client     |                  | Lan intf.  |                 | WAN intf.        |      | ISP Router  |
|              | -> ICMP -> | 10.1.1.1 | OPNSense | 192.168.0.100 | -> |  192.168.0.1| -> ISP Net
| 10.1.1.5 |                  |                                                         |      |                   |
+----------+                 +-------------------------------------------+     +--------------+

Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 03:23:01 pm
I checked the firewall rules all traffic to LAN Interface ist allowed
Title: Re: Can not ping OPNSense LAN Interface
Post by: Julien on November 29, 2018, 04:34:08 pm
What are you outband rules ?
where are you ping to where ?
Title: Re: Can not ping OPNSense LAN Interface
Post by: JasMan on November 29, 2018, 04:38:33 pm
I guess the IP range 10.0.0.0/8 is something in your providers network or some kind of management network of your modem. Because in the tracerout we can see your WAN address and after that you get an answer from 10.255.x.x. This address is also an part of 10.0.0.0/8.

Do you see any dynamic or static route on your OPNsense for 10.x.y.z networks? Any policy-based routing?
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 04:44:36 pm
Yes my Provider seems also to you use 10.x.x.x Network.
10.255.7.97 is an IP of my provider.

How can I stop routing of 10.x.x.x target adresses out of my internal Network.
Title: Re: Can not ping OPNSense LAN Interface
Post by: JasMan on November 29, 2018, 05:02:02 pm
Normaly this should not happen because 10.1.1.1 is in your LAN and the next hop from your clients view.
Please check and post the routing and also the subnet masks of your client and OPNsense LAN interface.
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 05:11:25 pm
find attached the screenshot of the LAN interface config
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 05:16:48 pm
find attached the screenshot of the recent routing table
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 05:47:07 pm
Subnetmask of the clients is always /24
Title: Re: Can not ping OPNSense LAN Interface
Post by: JasMan on November 29, 2018, 08:55:09 pm
Mmhh, looks fine  :)

Do you have any firewall rule for ICMP on the LAN interface where you've select an gateway?
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 09:02:45 pm
Nope no Rules for ICMP in general
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 09:50:36 pm
One thing is conspicuous in the routes overview
why is 10.1.1.1/32 mapped to Interface lo0 and not to the physikal interface em0 like 10.1.1.0/24
Title: Re: Can not ping OPNSense LAN Interface
Post by: Julien on November 29, 2018, 10:04:00 pm
Are you blocking Block private networks / Block begon networks on the WAN side ? this mostly the cause.
if you do, remove the block and stuff works.
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 29, 2018, 10:09:44 pm
yes I blocked Bogon Networks. Unchecked all blocks.
But no change in behavior, still not able to ping Lan interface
Title: Re: Can not ping OPNSense LAN Interface
Post by: Julien on November 29, 2018, 10:44:21 pm
yes I blocked Bogon Networks. Unchecked all blocks.
But no change in behavior, still not able to ping Lan interface

Can share a screenshot of your firewall rules on the WAN side ?
Title: Re: Can not ping OPNSense LAN Interface
Post by: cyberganny on November 30, 2018, 12:00:42 am
No rule on WAN Side