@Jarhead said in None of my firewall rules are working on VLANs:
So the trunk connected to the router won't need vlan 1 untagged but the trunks to the AP's will.
Exactly you can have more than 1 uplink from the switch that carry different networks/vlans - if you have free ports on your switch and router this actually good idea, now if you have intervlan traffic you don't have to worry about hairpin, as long as you don't put the uplink on the same physical.
So for example.
uplinks.jpg
So you can see vlans are on my igb2 interface, there is also an untagged vlan on this, this is vlan 2 on the switch.
igb actually goes thru my switch as well, this is vlan 99 on the switch untagged and from another port on the switch untagged in vlan 99 goes to my modem.
Lan is untagged goes to vlan 9 on my switch.
All the vlans that are tagged on on the switch igb2 plugs into. These are all wireless networks, and there is no intervlan traffic between them if talk to them, its from say my lan network.
Roku is also a wireless network but this is where all my media players are and no need to share bandwidth the other wireless networks and I had spare ports. Then dmz is another untagged network
if you have the ports on your router and switch, nothing really needs to be tagged, they can all be untagged native networks on pfsense. And then untagged in whatever vlan those networks are on your switch.
The only time you have to tag is when your going to carry more than one network/vlan over the same physical wire.