• Three VLAN, unmanaged switch, one interface config questions

    11
    0 Votes
    11 Posts
    1k Views
    johnpozJ
    If your running the connection from pfsense to a vm host… Then you don't need a switch even and you can do tagging and use vswitches with port groups to accomplish what you want. But if your going to break this out into the real world network and connect to a switch and send use multiple layer 3 networks.. Then yes your going to want to isolate said networks at layer 2 with vlans. Don't be that guy - forgo that pizza or that case of beer and get a switch that can do tags.. I mean really its 30 freaking $'s - shit you can drop that in after work beers on a tuesday..  Which I am sure I will prob do tonight ;) Don't be that guy [image: wrong-tools2.jpg] Your switch may or may not pass the tags… But that is really not the point..  Its not going to teach you anything, and all it does is promote bad habits... There is one thing when hey this needs to be up and running in 30 minutes, and all I have is this dumb switch and production is down.. Can we connect using this dumb switch and run multiple layer 3 on the same layer 2 until the replacement switch comes in. And then there is oh lets save $5 and just use this dumb switch.. You get a pat on the back for scenario 1, you get fired and ridiculed by your peers in scenario 2.. So there is knowing that it "can" be done.. And then there is being smart enough to know that nobody should do that.. Your not using duct tape to save yourself on Apollo 13 here.. What your doing is breaking out your hack saw to cut the pizza because your tool lazy to open the drawer and pull out the pizza cutter.
  • Problem using WiFi Hotspot for Failover

    1
    0 Votes
    1 Posts
    359 Views
    No one has replied
  • Static Route Not Being Followed

    1
    0 Votes
    1 Posts
    231 Views
    No one has replied
  • IPSec Site-to-Site | Routing

    1
    0 Votes
    1 Posts
    205 Views
    No one has replied
  • Routing / it's a bug or my mistake?

    5
    0 Votes
    5 Posts
    579 Views
    R
    Thanks a lot for replying.
  • First multi wan configuration

    2
    0 Votes
    2 Posts
    463 Views
    S
    I think I got it. The key word is 'internal interface': it means the LAN interface. So I have to edit the default LAN rule and set the gateway group instead of tge default gw. Yesyerday I've done that but something unexpected happened: all hosts on lan was unable to comunicate (ping each other). Some like that happens in case of loop in the switch. Monday I'll double check my configuration. My pfsense is installed on an alix (so physical, no virtual). All 3 nic are connected to the switcn amd I had no problem till I set the gateway group on the lan default rule. Any hint is wellcome.
  • [SOLVED]Help with routes on múltiples pFsense

    6
    0 Votes
    6 Posts
    475 Views
    _neok_
    @johnpoz: yeah can be done with just 1.. Not sure why you think it couldn't? Your using a reverse proxy from the outside into your dmz. I realised that is more easy to do this whith only one pfSense in HA clúster. Thankls for help.
  • Gateway is down

    9
    0 Votes
    9 Posts
    1k Views
    L
    For egas_tt only It was a design issue. Basically 2 interface DGs cannot be set to point at each other. 1 of the 2 need have no if-dg. Osfp helps avoiding to create default routes. Wonderful Pfsense ! :o 8) ::)
  • DUAL WAN LOAD BALANCE NOT CONSISTENT

    4
    0 Votes
    4 Posts
    357 Views
    J
    I have managed to get 8.5Mbps. :) :) :) the problem was on squid!!!!
  • Firewall Rules - Can't select Gateway

    4
    0 Votes
    4 Posts
    793 Views
    F
    i think i found the problem. my pfsense interface is displayed in french. i try to change the language to english to take screenshots and surprise, the gateway choice is back. so there is a bug with some foreign language interface.
  • MOVED: CONFIGURAÇÃO ISSABEL PABX PFSENSE

    Locked
    1
    0 Votes
    1 Posts
    198 Views
    No one has replied
  • Need help setting up L3 switch w/Multi vlans behind pfsense

    4
    0 Votes
    4 Posts
    452 Views
    johnpozJ
    I think he means the switches SVI is 10.1.10.1?? If your switch is L3 and doing the routing between your downstream vlsns, then it would need an interface with IP in each of these vlans.  This SVI becomes the gateway devices in these vlans. The network between pfsense and this downstream router now is just transit. A /24 is a huge transit - you do not have hosts on these network do you.  If so you going to have asymmetrical routing unless you create routes on each host. For pfsense to be an upstream router the interface that is the transit needs to allow for the downstream networks.  And if you changed the outbound nat rules from auto you will have to adjust those after you create your gateway and route(s) on pfsense telling it which networks are downstream.
  • 0 Votes
    2 Posts
    310 Views
    D
    It was idle OpenVPN connection from third machine from the LAN keeping tunnel and packets going!!
  • WAN vs VPN Routing

    1
    0 Votes
    1 Posts
    419 Views
    No one has replied
  • ISP Static IP Internet Issues after reboot

    1
    0 Votes
    1 Posts
    290 Views
    No one has replied
  • Connecting two networks without sharing internet access

    15
    0 Votes
    15 Posts
    2k Views
    DerelictD
    As an aside I would still be tempted to IPsec the traffic even though the wireless might be encrypted. You could use IPsec transport mode for that.
  • DLNA over Subnets, IGMP Proxy, Multicast Routing

    8
    0 Votes
    8 Posts
    12k Views
    F
    I just updated to latest 2.4 hoping to use the brand new IGMP proxy. But unlukly I'm facing the same problems. Same errors of m4rv1n. I read that in the past was possible to use IGMP proxy. Is there any chance to get it working again?
  • Routing between 2 WAN network(s)

    2
    0 Votes
    2 Posts
    422 Views
    C
    Anyone? If you don't understand my question, feel free to ask.
  • BGP and LAN routable IP

    3
    0 Votes
    3 Posts
    564 Views
    S
    you may be also like it k-12 tool is a free online tool which provides help to college and school district technology directors, state leader who can view broadband services and bandwidth information for school. All IP Address ranges are technically routable. that a private network with an RFC 1918 IP range can reach the public internet without needing these private network routers to be published. You can use them with routing protocols like OSPF, BGP. https://babasupport.org/routers/tp-link-customer-service/778 provide you best solution for all technical issues that may be the router, software etc.
  • Failover doesn't fail-back… how to fix?

    9
    0 Votes
    9 Posts
    3k Views
    I
    try: System -> Advanced -> Miscellaneous : [v] Enable default gateway switching  - check on works for me 2.2.5-RELEASE (i386) built on Wed Nov 04 15:50:18 CST 2015 FreeBSD 10.1-RELEASE-p24
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.