• L3 switching with pfsense

    8
    0 Votes
    8 Posts
    256 Views
    C

    @johnpoz You just don't get the different in working on layer 3 and layer 2. It is why you have default gateways and default routes and they are different. ThAT SEEMS TO BE OVER YOUR HEAD. Your firewall to the world is going to be layer 3. You are lost in pfsense and you can't see the forest for the trees.
    Go away John please do not reply to my threads. I will try not to post any more here.

    And yes I ran a small team of network people a long time ago. I had over 4000 PCs and around 50 locations so get over it.

    You ran me off last time and I went back to Cisco over pfsense. Look back in the threads years ago.
    Plus pfsense was having routing issues or slowdowns on routing as I was doing layer 3 back then at home. Version 2.8 is fast now which is good. Having a connection of 10gig reduces your latency whether you run full 10gig or not. I have 1 gig of data on a 10gig connection. I think this is best you can do now for home. I have a Cisco 10gig layer 3 switch I plan to install soon. So I can push the extra data bandwidth.

  • 0 Votes
    5 Posts
    188 Views
    C

    @spickles I would think the easiest way to replace a Cisco ASA 5505 would be use pfsense as a firewall not a router. Keep using your Cisco L3 switch. I do that at my home. I use an Cisco L3 switch and route between my L3 switch and pfsense. You lose pfsense control over your local network. This would not be an issue with you as you will already have that with your L3 switch.

    Setup pfsense with no vlans and keep all the vlans on your L3 switch. Then set up your firewall rules and static routes to your L3 switch.

  • Two VLANs set up alike, one does not get Internet

    16
    0 Votes
    16 Posts
    2k Views
    D

    Indeed, I have to consult the community on how to configure the captive portal, too.

  • Surfshark Wireguard VPN on Guest VLAN Blocking Some Content

    3
    0 Votes
    3 Posts
    165 Views
    P

    Thanks! Surfshark does not support IPv6.
    DHCPv6 Server is not running on Guest

    Guest VLAN IPv6 Configuration Type is None.
    e300cdf0-d2f6-472a-bc37-67536aa7f008-image.png

    Router Advertisement Router Mode is Disabled
    585e8e78-a12d-4437-8663-7ea80d8c1555-image.png

    Added a Guest firewall rule at the top of the stack to block IPv6 traffic
    7cf2241b-4d32-4d08-9a25-75e272d7ae31-image.png

    Also tested disabling IPv6 in the APN on my phone. Didn't help.

    We're still having problems with some apps/content on our phones.

  • Need help with transparent bridge DNS VLan setup

    1
    0 Votes
    1 Posts
    35 Views
    No one has replied
  • ACCESS DIFFERENT VLAN ON A DIFFERENT PORT OF PFSENSE

    11
    0 Votes
    11 Posts
    611 Views
    HHUBSH

    I managed to solve this myself today. The reason I can't ping the client directly connected to the igc1 of pfsense is because of the Bitdefender stealth mode setting. Once I turned it off, I can now ping the client.

    I came up with this solution because I tried Ubuntu on a flash drive, and I can ping it, so there is a problem with the firewall of the Windows machine.

    That's why I checked all the firewall settings one by one on the Windows client.

  • Best simple network

    25
    0 Votes
    25 Posts
    2k Views
    Y

    @Dobby_ Thought I'd be the only one who would ever use a number like 300 in an IP address. 😂

  • static are not used when trying to communicate between 2 pfsense CE

    5
    0 Votes
    5 Posts
    155 Views
    U

    Ok I tried your solution, and it's ok. Really thank you, for the solution and for the explaination. I really don't like doing thing without understanding what I'm doing and why.

    One more time Thank you

  • CANNOT PING VLAN INTERFACE IP FROM SAME VLAN

    4
    0 Votes
    4 Posts
    213 Views
    HHUBSH

    @Bob-Dig said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN:

    @HHUBS said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN:

    Or I should ping it from the same VLAN even if no rules are added?

    No, it is the firewall and with that, it is able and will block the connection without rules. Different would be to ping a host on a switch, which is in the same LAN. Then the connection is not hitting the firewall in the first place and the firewall can do nothing about it.

    @johnpoz said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN:

    @HHUBS out of the box the only interface with default rule to allow is lan that defaults to an any any rule, anti-lockout.. If you create a new interface be it vlan or native you would have to add the rules you want.

    Yes by default no rules would hit the default deny and yes block ping, or any other access.

    Thank you so much for your help. 👍

  • 0 Votes
    1 Posts
    61 Views
    No one has replied
  • communicating via vswitch from vms in bridges

    15
    0 Votes
    15 Posts
    634 Views
    C

    I got it to work. It had to do with not setting mtu of 1400. I can now do dns lookup and it works! Thank you for your suggestions.

  • 0 Votes
    1 Posts
    120 Views
    No one has replied
  • 0 Votes
    4 Posts
    356 Views
    johnpozJ

    @scottlindner if the goal is leverage 2.5ge connection - yeah a small 2.5ge seems like a good solution.

    You could then if enough ports on this new switch - leverage lacp from the 1 gig switch to provide for more bandwidth to the router.

    This wont help with a single connection, but it would provide for more bandwidth for multiple devices on the 48 port to the router interface through the 2.5ge switch.

    Yeah a 48 port 2.5ge managed is prob not all that cheap ;)

    You could then also move a vlan or both off your current lan interface onto their own 2.5ge interface. Maybe a 16 port 2.5ge switch price is more budget friendly? This would give you plenty of ports to work with - you could have 3 different uplinks for your networks, and then 2 or more as lacp to your 1 ge switch, and leave plenty of ports for 2.5ge APs into the new switch. Or maybe 8 port is enough?

  • VLAN interfaces setup after changing network adapter

    1
    0 Votes
    1 Posts
    219 Views
    No one has replied
  • VLAN assignment to LAN and Ubiquiti switch

    9
    0 Votes
    9 Posts
    1k Views
    J

    @Gblenn
    I would have followed up earlier but have been busy with both the network and other stuff.
    I still appreciate your advice. And I have been reading more about the concept of VLANs.
    The old D-Link is still in the rack and I use it for a "backup" so I can go back to this if the Unifi switch does not work.
    Theres is another problem that I haven't been able to solve.
    The Unifi controller holds all the configured wired and wireless networks even if I use hardware reset on the switch. But no matter what I do, the switch appears to be offline after a few moments.
    And even if it still handles the traffic according to the configuration, it is offline in the sense that I can't ping it or log in with ssh.
    When I use the old switch and just connect the new one through a single cable, the switch can be adopted and configured.
    I have read a lot of post about similar issues at the Ubiquiti Forum. Some suggests to manually change the inform host like this set-inform http://ip-of-controller:8080/inform. This seems not to change anything.
    Other suggestions are to add an 43 option to the DHCP server (pfSense) or make a host override at the same place.
    Do you have any suggestions?

  • Unifi SSID/VLANs blocked from internet due to static IPs?

    14
    0 Votes
    14 Posts
    2k Views
    johnpozJ

    @dj_jc_jase glad to hear sorted.. Possible something got messed up with during the double change at same time? I don't have anything on poe switch from unifi - so not sure if AP might reboot on switch IP change because of loss of poe? And then possible loss of talking to the controller to get info.. Something was not right.

    But from a actual network pov - the management IP of the switch and ck has zero to do with anything.

  • Bridge LAN 2 nic, non comunicano

    7
    0 Votes
    7 Posts
    834 Views
    johnpozJ

    @Antonio1971 if you setup a bridge - then your firewall rules would have to allow the traffic over your bridge..

    While bridging can "some what" simulate the actions of a switch - it is not a switch.. A 20$ gig switch would solve your issue ;) shoot if your only after 3 connections a 10$ 5 port gig switch solve your problem

    The time you have spent on this clearly exceeds the cost of a switch - I can tell you for sure if I charged for my time in answering you could of gotten multiple smart switches, and I have spent only a couple of minutes - hehehe

    A bridge does have specific uses cases.. Trying to turn 2 discrete interfaces into a switch is not one of them. The only time I would even think of doing it would be if production was down and it needed to be up NOW.. And the switch won't be here til tmrw..

  • Unifi UDM Gateway Network Tagging With pFsense

    1
    0 Votes
    1 Posts
    210 Views
    No one has replied
  • My first VLAN - Not internet connectivity on the VLAN

    7
    0 Votes
    7 Posts
    809 Views
    D

    Got it sorted. For anyone reading, the main issue was I have manual outbound NAT rules setup. I had to set up a NAT rule for the VLAN IP address range and the WAN as the interface (thanks ChatGPT for correcting my mistake of putting the VLAN assignment as the interface). All is now working and bypassing NordVPN

  • VLAN Bandwidth Speed Issue

    5
    0 Votes
    5 Posts
    650 Views
    S

    @patient0

    Thank you very much for your help.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.