Here’s the IP A output… I’m sorry I’m not a networking expert so I’m just trying to figure this out as I go along…
To restate my problem for clarity:
2 NICs on TrueNAS:
- One should be for WebUI (admin network)
- One should be for SMB (trusted user network)
Both live on separate subnets/vlans.
I have an additional VLAN (for example an untrusted wifi network) that certain trusted devices can live on but can also access the trusted user network from. This routing is done via router/firewall rules.
I think what I am learning now is that the issue is that the third untrusted network has a different subnet than either admin or trusted and so the packets are being dropped unless I create a specific static route just for that network. Is that correct?
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: enp2s0f0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
3: enp2s0f1: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
4: enp3s0f0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
inet 192.168.10.35/24 brd 192.168.10.255 scope global enp3s0f0
valid_lft forever preferred_lft forever
inet6 fe80::7ae7:d1ff:fe7d:5016/64 scope link
valid_lft forever preferred_lft forever
5: enp3s0f1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
inet 192.168.20.35/24 brd 192.168.20.255 scope global enp3s0f1
valid_lft forever preferred_lft forever
inet6 fe80::7ae7:d1ff:fe7d:5018/64 scope link
valid_lft forever preferred_lft forever
12: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
inet 172.16.0.1/24 brd 172.16.0.255 scope global docker0
valid_lft forever preferred_lft forever
inet6 fdd0::1/64 scope global nodad
valid_lft forever preferred_lft forever
384: br-XXXXXXXXXXXX: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff
inet 172.16.1.1/24 brd 172.16.1.255 scope global br-XXXXXXXXXXXX
valid_lft forever preferred_lft forever
inet6 fdd0:0:0:1::1/64 scope global nodad
valid_lft forever preferred_lft forever
inet6 fe80::42:58ff:fe16:450e/64 scope link
valid_lft forever preferred_lft forever
5568: vethXXXXXXXX@if5567: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-XXXXXXXXXXXX state UP group default
link/ether XX:XX:XX:XX:XX:XX brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet6 fe80::6c7a:43ff:fe69:9c1b/64 scope link tentative
valid_lft forever preferred_lft forever