pfsense: interface sem tráfego TCP

0

Eu tenho uma instalação do pfsense runnning baseada em uma placa ALIX - tudo funcionou bem, mas a última interface adicionada não tem acesso à Internet.

Existe uma ponte sobre LAN1 + WLAN - > trabalho. Existe uma interface LAN2 - > trabalho Existe uma interface LAN3 - > ping ok (local e internet), rede local ok, internet não funciona.

LAN3 tem o "mesmo" confighuration como.

Não consigo ver por que isso não funciona.

<interfaces>
    <wan>
        <enable></enable>
        <if>vr0</if>
        <ipaddr>dhcp</ipaddr>
        <ipaddrv6>dhcp6</ipaddrv6>
        <gateway></gateway>
        <blockpriv>on</blockpriv>
        <blockbogons>on</blockbogons>
        <media></media>
        <mediaopt></mediaopt>
        <dhcp6-duid></dhcp6-duid>
        <dhcp6-ia-pd-len>0</dhcp6-ia-pd-len>
    </wan>
    <lan>
        <enable></enable>
        <if>vr1</if>
        <descr><![CDATA[LAN1]]></descr>
        <ipaddr></ipaddr>
        <subnet></subnet>
        <ipaddrv6></ipaddrv6>
        <track6-interface>wan</track6-interface>
        <track6-prefix-id>0</track6-prefix-id>
        <spoofmac></spoofmac>
        <gateway></gateway>
        <subnetv6></subnetv6>
        <gatewayv6></gatewayv6>
    </lan>
    <opt1>
        <if>vr2</if>
        <descr><![CDATA[LAN2]]></descr>
        <enable></enable>
        <spoofmac></spoofmac>
        <ipaddr>192.168.102.1</ipaddr>
        <subnet>24</subnet>
    </opt1>
    <opt2>
        <if>ath0</if>
        <descr><![CDATA[WLAN]]></descr>
        <enable></enable>
        <spoofmac></spoofmac>
        <wireless>
            <standard>auto</standard>
            <protmode>off</protmode>
            <channel>6</channel>
            <distance></distance>
            <regdomain></regdomain>
            <regcountry></regcountry>
            <reglocation></reglocation>
            <txpower></txpower>
            <mode>hostap</mode>
            <ssid>Pofficewifi</ssid>
            <authmode></authmode>
            <wpa>
                <macaddr_acl></macaddr_acl>
                <wpa_mode>2</wpa_mode>
                <wpa_key_mgmt>WPA-PSK</wpa_key_mgmt>
                <wpa_pairwise>CCMP</wpa_pairwise>
                <wpa_group_rekey>60</wpa_group_rekey>
                <wpa_gmk_rekey>3600</wpa_gmk_rekey>
                <passphrase>XXXXXXXXXXXXXXXXXXXXXXX</passphrase>
                <ext_wpa_sw></ext_wpa_sw>
                <enable></enable>
            </wpa>
            <auth_server_addr></auth_server_addr>
            <auth_server_port></auth_server_port>
            <auth_server_shared_secret></auth_server_shared_secret>
            <auth_server_addr2></auth_server_addr2>
            <auth_server_port2></auth_server_port2>
            <auth_server_shared_secret2></auth_server_shared_secret2>
        </wireless>
    </opt2>
    <opt3>
        <descr><![CDATA[PSECURE]]></descr>
        <if>bridge0</if>
        <enable></enable>
        <spoofmac></spoofmac>
        <ipaddr>192.168.92.1</ipaddr>
        <subnet>24</subnet>
    </opt3>
    <opt4>
        <descr><![CDATA[LAN3]]></descr>
        <if>ue0</if>
        <enable></enable>
        <spoofmac></spoofmac>
        <ipaddr>192.168.112.1</ipaddr>
        <subnet>24</subnet>
    </opt4>
</interfaces>

<nat>
    <outbound>
        <mode>automatic</mode>
    </outbound>
</nat>
<filter>
    <rule>
        <type>pass</type>
        <ipprotocol>inet</ipprotocol>
        <descr><![CDATA[Default allow LAN to any rule]]></descr>
        <interface>lan</interface>
        <tracker>0100000101</tracker>
        <source>
            <network>lan</network>
        </source>
        <destination>
            <any></any>
        </destination>
    </rule>
    <rule>
        <type>pass</type>
        <ipprotocol>inet6</ipprotocol>
        <descr><![CDATA[Default allow LAN IPv6 to any rule]]></descr>
        <interface>lan</interface>
        <tracker>0100000102</tracker>
        <source>
            <network>lan</network>
        </source>
        <destination>
            <any></any>
        </destination>
    </rule>
    <rule>
        <id></id>
        <tracker>1496909451</tracker>
        <type>block</type>
        <interface>opt1</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <any></any>
        </source>
        <destination>
            <network>opt3</network>
        </destination>
        <log></log>
        <descr></descr>
        <created>
            <time>1496909451</time>
            <username>[email protected]</username>
        </created>
        <updated>
            <time>1497285680</time>
            <username>[email protected]</username>
        </updated>
    </rule>
    <rule>
        <id></id>
        <tracker>1497285453</tracker>
        <type>pass</type>
        <interface>opt1</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt1</network>
        </source>
        <destination>
            <network>opt1ip</network>
        </destination>
        <descr></descr>
        <updated>
            <time>1497285453</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1497285453</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1497285593</tracker>
        <type>block</type>
        <interface>opt1</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt1</network>
        </source>
        <destination>
            <address>192.168.0.0/16</address>
        </destination>
        <descr></descr>
        <updated>
            <time>1497285593</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1497285593</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1496908992</tracker>
        <type>pass</type>
        <interface>opt1</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <any></any>
        </source>
        <destination>
            <any></any>
        </destination>
        <descr></descr>
        <dnpipe>LimitLAN2down</dnpipe>
        <pdnpipe>LimitLAN2up</pdnpipe>
        <created>
            <time>1496908992</time>
            <username>[email protected]</username>
        </created>
        <updated>
            <time>1496911481</time>
            <username>[email protected]</username>
        </updated>
    </rule>
    <rule>
        <id></id>
        <tracker>1496909483</tracker>
        <type>block</type>
        <interface>opt3</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt1</network>
        </source>
        <destination>
            <network>opt3</network>
        </destination>
        <log></log>
        <descr></descr>
        <created>
            <time>1496909483</time>
            <username>[email protected]</username>
        </created>
        <updated>
            <time>1497285652</time>
            <username>[email protected]</username>
        </updated>
    </rule>
    <rule>
        <id></id>
        <tracker>1497285844</tracker>
        <type>pass</type>
        <interface>opt3</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt3</network>
        </source>
        <destination>
            <network>opt3ip</network>
        </destination>
        <descr></descr>
        <updated>
            <time>1497285844</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1497285844</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1497285775</tracker>
        <type>block</type>
        <interface>opt3</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <any></any>
        </source>
        <destination>
            <network>opt1</network>
        </destination>
        <descr></descr>
        <updated>
            <time>1497285775</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1497285775</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1496908983</tracker>
        <type>pass</type>
        <interface>opt3</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt3</network>
        </source>
        <destination>
            <any></any>
        </destination>
        <descr></descr>
        <created>
            <time>1496908983</time>
            <username>[email protected]</username>
        </created>
        <updated>
            <time>1497270381</time>
            <username>[email protected]</username>
        </updated>
    </rule>
    <rule>
        <id></id>
        <tracker>1533385424</tracker>
        <type>pass</type>
        <interface>opt4</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <any></any>
        </source>
        <destination>
            <any></any>
        </destination>
        <descr></descr>
        <dnpipe>LimitLAN2down</dnpipe>
        <pdnpipe>LimitLAN2up</pdnpipe>
        <updated>
            <time>1533385424</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1533385424</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1533385408</tracker>
        <type>block</type>
        <interface>opt4</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt4</network>
        </source>
        <destination>
            <address>192.168.0.0/16</address>
        </destination>
        <descr></descr>
        <updated>
            <time>1533385408</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1533385408</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1533385387</tracker>
        <type>pass</type>
        <interface>opt4</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <network>opt4</network>
        </source>
        <destination>
            <network>opt4ip</network>
        </destination>
        <descr></descr>
        <updated>
            <time>1533385387</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1533385387</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <rule>
        <id></id>
        <tracker>1533385358</tracker>
        <type>block</type>
        <interface>opt4</interface>
        <ipprotocol>inet</ipprotocol>
        <tag></tag>
        <tagged></tagged>
        <max></max>
        <max-src-nodes></max-src-nodes>
        <max-src-conn></max-src-conn>
        <max-src-states></max-src-states>
        <statetimeout></statetimeout>
        <statetype>keep state</statetype>
        <os></os>
        <source>
            <any></any>
        </source>
        <destination>
            <network>opt3</network>
        </destination>
        <log></log>
        <descr></descr>
        <updated>
            <time>1533385358</time>
            <username>[email protected]</username>
        </updated>
        <created>
            <time>1533385358</time>
            <username>[email protected]</username>
        </created>
    </rule>
    <separator>
        <opt2></opt2>
        <opt3></opt3>
        <opt1></opt1>
        <opt4></opt4>
    </separator>
</filter>
<bridges>
    <bridged>
        <members>lan,opt2</members>
        <descr><![CDATA[PSecure]]></descr>
        <maxaddr></maxaddr>
        <timeout></timeout>
        <maxage></maxage>
        <fwdelay></fwdelay>
        <hellotime></hellotime>
        <priority></priority>
        <proto>rstp</proto>
        <holdcnt></holdcnt>
        <ifpriority></ifpriority>
        <ifpathcost></ifpathcost>
        <bridgeif>bridge0</bridgeif>
    </bridged>
</bridges>

Alguém pode ver, o que é necessário para que o LAN3 (opt4) funcione?

Atenciosamente Johannes

    
por Johannes C. Schulz 14.08.2018 / 10:38

0 respostas

Tags