• Setting up VLAN ;segmenting the network using PFSENSE

    5
    0 Votes
    5 Posts
    3k Views
    G
    @johnpoz: And what are these AP.. support of multiple SSIDs does not always mean they support vlan tagging of the SSID if your using what amounts to a user wifi router as AP, etc.. As to procedural help for you d-link switches.. Your going to be better off RTFM for your switch or via dlink forums, etc.  What is the make and model of these switches?  Maybe someone uses them. Here is a example drawing I did up for another user that PM about their network.. This should help as an overview. So in this example pfsense has 3 interfaces used on the "local" side of pfsense. Lan and VPN would be two layer 2 networks (vlans on the switch - not in pfsense) Where the switch would isolate this traffic but its not tagged.  While the wlan interface in this drawing has a native untagged network just like lan and vpn, it also does vlan tagging on that interface and handles your wifi tagged ssid based vlans. So in a wired network you can do tagged or untagged "vlans" with wifi your going to have to do tagging of the vlans.  This is can be confusing to new vlan users. In the example there are 2 switches, this can be expanded to as many switches as you have, etc.  The term "trunk" here reflects the cisco use of the term to man a port that carries tagged vlans.  The color coding of the ports reflects what the native vlan of that port is, etc. This is pretty good overall example of how in a very simple network how you could isolate different networks from each other some tagged and others untagged "vlans"  So in pfsense you would have setup of interface of wlan, and then on top of that physical interface you would create the "vlans" for your wifi networks. Hope that helps. In our PFSense , we just have to cards , LAN & WAN.under the LAN interface as the parent I have created a sub interface for the guest vlan, logically…. will this work or is it advisable to add one extra NIC card on the pfsense machine, and this extra NIC card i configure it to serve new Guest VLAN i intend to create
  • Loopback interfaces revisited

    1
    0 Votes
    1 Posts
    632 Views
    No one has replied
  • NUT and Windows

    3
    0 Votes
    3 Posts
    817 Views
    L
    Thanks for the reply! I have used the official port off of the NUT website. It is the one that has no GUI.
  • I would like to see my logs a bit more… clear and understandable

    3
    0 Votes
    3 Posts
    995 Views
    A
    There is a pre-made pfELK virtual machine you could try: https://www.reddit.com/r/PFSENSE/comments/4dymci/i_made_a_simple_bare_bones_simple_elk_vm_for/
  • MOVED: Which system am I running?

    Locked
    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • [solved] Unable to generate external CSR with custom subject

    9
    0 Votes
    9 Posts
    7k Views
    X
    thank you, it works ! good job :)
  • Security question

    6
    0 Votes
    6 Posts
    1k Views
    J
    It sounds like I need to turn packet filtering back on and make some rules. Thanks…Jim
  • Manually add second NIC

    3
    0 Votes
    3 Posts
    724 Views
    L
    Somehow I missed that yesterday! Thanks. Unfortunately there are no interfaces displayed in the GUI or using ifconfig.
  • DHCP my fail

    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • Distinction between traffic on port 443

    17
    0 Votes
    17 Posts
    5k Views
    P
    @tazzler: @Panja: What did you end up with? Are you living with decreased https-performance? I ended up changing the ports. I could not live with the decreased speed.
  • 2.3.2 - Delete NAT rule - bug?

    2
    0 Votes
    2 Posts
    1k Views
    N
    Confirmed. Bug report filed: https://redmine.pfsense.org/issues/6676 Fix pull request submitted: https://github.com/pfsense/pfsense/pull/3089 Thanks for reporting this bug.
  • New to this world

    3
    0 Votes
    3 Posts
    908 Views
    C
    Given what you describe, either you will need one interface per network or you will need switch with VLAN support. "home Wifi" means that you will connect your wifi access point to your home LAN, that's it… if you don't want to isolate wifi network. However, depending on your location, you should think about isolating wifi from "home LAN". Well, it depends on what you have on your home LAN but risk is higher with wifi than cable to have some unwanted connection. you could also implement WPA2-enterprise with Radius for authentication so that wifi access is under better control. Anyway, whatever solution you select, keep in mid that merging LAN and Wifi might not be a very good idea. With either VLAN or real NIC, you will isolate "server LAN" and "home LAN" with FW in the middle so yes, you can control which IP is authorized to access your "server LAN". Traffic redirection to your Apache servers is not clear to me. Do you mean internal traffic from home LAN to server LAN or traffic from internet to internal Apache servers. Are you sure you have 2 different domains here? (why not but I suspect you mix-up "domain" and fqdn In any case, pfSense DNS feature should be used only for internal devices. If you need to resolve internal services exposed to internet, do this using external (public) DNS.
  • Pfsense hangs randomly

    1
    0 Votes
    1 Posts
    649 Views
    No one has replied
  • Packet loss stats

    3
    0 Votes
    3 Posts
    763 Views
    J
    Sweet and simple! Thank you :)
  • Old ATH driver?

    8
    0 Votes
    8 Posts
    3k Views
    S
    Hello, I ve the same issue ( ath0: stuck beacon; resetting (bmiss count 4)  ) Is there another Wifi hardware out there that works fine with the PC Engines AMD APU1D4?
  • Pfsense bloced after apply changes

    2
    0 Votes
    2 Posts
    747 Views
    jimpJ
    The only way that happens is if you have a gateway down and you also have the firewall set to kill states on gateway failure. System > Advanced, Miscellaneous tab, uncheck the box for state killing on gateway failure. That, or fix the gateway that must be showing as down under Status > Gateways. Either change the monitor IP address under System > Routing or disable gateway monitoring for the down gateway.
  • IPhones causing excess latency on Gateway when charging

    1
    0 Votes
    1 Posts
    522 Views
    No one has replied
  • Different Behaviour - 32bit vs 64bit - tcpdump pflog0

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    As I asked on the other thread but never saw an answer for: Why are you using tcpdump on pflog directly? That isn't how you watch for log messages on 2.2 or 2.3.
  • Alert when new (WiFi) clients come onto the network

    1
    0 Votes
    1 Posts
    475 Views
    No one has replied
  • Gateway Status Reported Incorrectly - 2.3.2-RELEASE (amd64)

    1
    0 Votes
    1 Posts
    422 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.