Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
(solved) Access Webgui from different subnet
« previous
next »
Print
Pages: [
1
]
Author
Topic: (solved) Access Webgui from different subnet (Read 3977 times)
xman111
Newbie
Posts: 7
Karma: 0
(solved) Access Webgui from different subnet
«
on:
November 10, 2023, 10:00:14 pm »
Hey guys, new here, coming from PFsense.
I am trying to access the webgui (192.168.10.1) from my laptop (192.168.20.14). Is there anything more i need than firewall rules from 192.168.20.0 to any? i cannot connect.
any help would be appreciated.
«
Last Edit: November 12, 2023, 04:58:46 pm by xman111
»
Logged
cookiemonster
Hero Member
Posts: 1823
Karma: 95
Re: Access Webgui from different subnet
«
Reply #1 on:
November 10, 2023, 10:49:28 pm »
if system > settings > administration > Listen interfaces is set to All (recommended) then yes.
Logged
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #2 on:
November 11, 2023, 04:04:16 am »
thanks for ther reply.. i do have that set and this is my rule for that subnet.. does this look right?
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: Access Webgui from different subnet
«
Reply #3 on:
November 11, 2023, 07:55:49 am »
That rule
- matches way more than the webGUI access (destination: WLAN address, TCP port 443 or whatever you are using)
- will only work if you are connecting to the WLAN IP and the webserver is listening there, as already said above.
- will not work anyway if IPv6 is used on your network
Not really anything different here from pfS. "Cannot connect" is not useful description of the problem. Look at the firewall logs at least.
Logged
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #4 on:
November 11, 2023, 05:30:16 pm »
i was just trying to make a wide open rule to at least let me ping between subnets. I also disabled all the ipv6 on my network as i thought that may be part of the problem. In pfsense, i thought i just made a rule that allowed my laptop to any and it worked right away. I literally worked on it for hours last night and couldn't get it working, lol.
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: Access Webgui from different subnet
«
Reply #5 on:
November 11, 2023, 05:39:22 pm »
Hmmm...
- firewall logs still missing
- rule on WLAN won't do any good if blocked by rules on another interface or floating
- disabling IPv6 on firewall does not disable it on any client. It only blocks all IPv6 traffic, if you mean the Firewall -> Settings -> Advanced -> Allow IPv6 checkbox. Certainly not a useful strategy at all. IPv6 has been preferred for ages by any reasonable OS out there.
Logged
cookiemonster
Hero Member
Posts: 1823
Karma: 95
Re: Access Webgui from different subnet
«
Reply #6 on:
November 11, 2023, 11:53:33 pm »
and you can connect successfully to it from a client on its LAN i.e. 192.168.10.0/24, right?
The rule looks very open but yes, that is all that should be needed in terms of rules.
But yes, I agree, turn on the logging of defaults temporarily to be sure.
Logged
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #7 on:
November 12, 2023, 12:55:32 am »
yes I can connect to it directly.
something very weird. I connected a laptop at 192.168.20.30 and setup a continuous ping to 192.168.10.1 and it was working. At the time I had my other laptop connected to the lan and it was getting an ip of 192.168.10.14. as soon as I disconnect my laptop from the Lan, the ping from the other laptop fails. when I plug my laptop back to the lan, the ping works again. its acting like I am pinging the other laptop but I am actually pinging the 192.168.10.1 ip.
what setting is wrong here?
«
Last Edit: November 12, 2023, 01:42:29 am by xman111
»
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: Access Webgui from different subnet
«
Reply #8 on:
November 12, 2023, 01:58:09 am »
Good that you did not post any logs ever, even after they've been requested at least 3 times. Outta here.
«
Last Edit: November 12, 2023, 02:08:15 am by doktornotor
»
Logged
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #9 on:
November 12, 2023, 03:06:17 am »
sorry man, have been out Christmas shopping for the kids and was on my phone, will try to post the log file. thanks for trying anyways.
Logged
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #10 on:
November 12, 2023, 03:29:48 am »
couldn't figure out how to download the logs so i just took a screenshot of it. This is the laptop continuously trying to ping the firewall. This is successful only when my other laptop is plugged into the lan.
«
Last Edit: November 12, 2023, 03:32:45 am by xman111
»
Logged
Patrick M. Hausen
Hero Member
Posts: 6820
Karma: 572
Re: Access Webgui from different subnet
«
Reply #11 on:
November 12, 2023, 12:52:52 pm »
Of course! If nothing is plugged into LAN the interface is down and the IP address not reachable. Most people have a switch plugged in there so the interface stays up.
If you don't need a switch because you need only one wired port and your access point, why do you use two different networks and not a LAN bridge? That would solve your problem and behave like most consumer routers do.
«
Last Edit: November 12, 2023, 02:41:56 pm by Patrick M. Hausen
»
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
xman111
Newbie
Posts: 7
Karma: 0
Re: Access Webgui from different subnet
«
Reply #12 on:
November 12, 2023, 04:56:32 pm »
Quote from: Patrick M. Hausen on November 12, 2023, 12:52:52 pm
Of course! If nothing is plugged into LAN the interface is down and the IP address not reachable
dude, that was it!! i didn't realize that the interface goes down if nothing is plugged into it.
I use all managed Cisco switches on my main network. I am just trying to slowly move my config from Pfsense to Opnsense. I have a mini pc running Opnsense with an old unifi AP connected to it. I just wanted to be able to wirelessly login to Opnsense wifi and slowly work on setting up all my stuff without having a wire dangling across my room for my kids or dog to trip on. I will just leave a switch plugged into it for the meantime.
thanks again, i am embarrased to say how much time i spent on this!!
«
Last Edit: November 12, 2023, 06:20:34 pm by xman111
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
(solved) Access Webgui from different subnet