• Is this an Asymmetric Routing routing issue?

    27
    0 Votes
    27 Posts
    2k Views
    H
    Thanks so much to everybody involved here. I was entirely wrong in my initial suspicion, but the analysis helped me better understand how networks work, so I do not consider this as lost time. Some revelations: for incoming traffic, wireshark, tcpdump and packet capture (pfsense) are king for outgoing traffic, ip route get [host ip] helps to see in which direction traffic leaves (or doesn't leave) the host
  • multi-vlan on a port

    vlan sg-3100 switch
    1
    0 Votes
    1 Posts
    493 Views
    No one has replied
  • CARP support hardware

    3
    0 Votes
    3 Posts
    363 Views
    P
    @derelict Thanks. You made my day. I will try that
  • VLAN and Network Design Help!

    1
    0 Votes
    1 Posts
    237 Views
    No one has replied
  • SG-2100 DMZ for home cloud

    23
    0 Votes
    23 Posts
    3k Views
    S
    @SteveITS After isolating the vlan on the switch, I had to configure a static IP, and now must configure for the WAN access. Would you know anything about this?
  • Basic L2TP(v3) pseudowire ?

    4
    0 Votes
    4 Posts
    850 Views
    T
    I ended up just plugging a Raspberry PI into a port on the N3K-C3172 TOR, and configured the network stack to implement the L2TP pseudowire, so it ends up being the same number of hops, but it would have been nice to implement it either in the switch or the firewall and not have to live with a single function appendage... but that's life in technology.
  • LACP on virtual pfsense?

    1
    0 Votes
    1 Posts
    217 Views
    No one has replied
  • No VLAN 0?

    3
    0 Votes
    3 Posts
    466 Views
    JKnottJ
    @johnpoz Then I was just discussing it. I hadn't actually tried it on pfsense. Today, I thought I would, given I have so much time on my hands with the pandemic. I run openSUSE Linux on my network and it supports VLAN 0. In fact, it's what pops up when you create a VLAN. In my previous experiment with VLANs, I was using VLAN 5, which pfsense supports. I also have VLAN 3 for my guest WiFi. BTW, I just came across this. In reading it, I get the impression someone doesn't understand what VLAN 0 is for. The "reserved" purpose is for putting the CoS bits on a frame, without having a separate VLAN. That is a VLAN 0 frame should be treated identically to a native frame, other than CoS.
  • XG-7100 1U - Switching LAN from LAGG0 to IX0

    1
    0 Votes
    1 Posts
    235 Views
    No one has replied
  • New to VLAN's

    11
    0 Votes
    11 Posts
    975 Views
    JKnottJ
    @duvel If you have 4 NICs, there's likely not much use with using VLANs. If you want to learn about VLANs, you have to actually set them up and have something at the other end of the wire that can handle them. A managed switch will do that. You can create multiple subnets and put them on individual VLANs. Then use the managed switch to sort them out, so that when you plug a computer into the different ports, it will be on the different subnets. Depending on your WiFi situation, you might get a proper AP and use a VLAN to provide a guest WiFi. One other thing you can do with a managed switch is create a data tap, so you can monitor a connection with Wireshark. This is very handy when learning about networks. Again, small managed switches are cheap. Just avoid TP-Link.
  • SG-1100 OPT Port DMZ

    2
    0 Votes
    2 Posts
    531 Views
    DerelictD
    @jamesdav It's just a switch. If you must use the switch built into the SG-1100 for this and not an actual external outside switch, you can modify this procedure: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/switch-overview.html That puts two ports on the same LAN broadcast domain but it will work equally well for VLAN 4090 (WAN).
  • VLAN Tag not being passed

    32
    0 Votes
    32 Posts
    5k Views
    R
    @derelict & All Thanks for your help. The issue is resolved. The problem was the Netgear switch port was being blocked because of STP rules. Issue Resolved!
  • How to best incorporate Linksys Velop nodes

    2
    0 Votes
    2 Posts
    1k Views
    D
    I came up with this topology: [image: 1616531784069-210322-network-diagram.jpg] ![alt text](image url) I also set took these configuration steps: set up a bridge between the interfaces corresponding to the LAN and OPT ports in Interfaces→Bridges, set the OPT port to have the IP address 192.168.4.1, set up a DHCP server for the entire 192.168.4.0/24 subnet on the interface corresponding to OPT, with 192.168.4.1 as the gateway address, turned on the Avahi package to route mDNS traffic between the 192.168.4.1/24 and 192.168.1.1/24 subnets, turned off the Velops’ DHCP server, and set the LAN base address to 192.168.4.2, so as to not create a conflict with the OPT port. The second Ethernet connection on the master Velop node is purely for remote administration purposes. That’s how it communicates to the LinkSys configuration servers.
  • Tagged traffic on SG-2100 802.1q port

    13
    0 Votes
    13 Posts
    1k Views
    S
    @Derelict & @teamits : you were both right. Sorry, my bad: it was bad Ubiquity configuration. If anyone falls in the same trap, the solution is to set "Corporate" + "VLAN". Not "VLAN Only" + "VLAN": [image: 1616462963822-98a25145-0f81-4440-85e0-ab5af871da71-image.png] Thank you both very much!
  • VLAN Tagging on Tagged Integrated Switch

    1
    0 Votes
    1 Posts
    189 Views
    No one has replied
  • VLAN Tag not being passed - UPDATE

    1
    0 Votes
    1 Posts
    188 Views
    No one has replied
  • Inter VLAN Communication Blocked by Gateway

    3
    0 Votes
    3 Posts
    457 Views
    C
    @mcury Perfect, got it working as expected. Still curious about what causes the underlying issue wrt routing from the gateway but it's less of a concern since I can address the symptom.
  • Use one VLAN and forward/output the other on a different interface

    2
    0 Votes
    2 Posts
    248 Views
    P
    I eventually solved it by using the ISP modem/router for IPTV and but pfSense behind it. It's double NAT but that's ok for now.
  • Problem with Web Socket Connections Across Vlans...

    2
    0 Votes
    2 Posts
    173 Views
    No one has replied
  • I need help with VLAN

    vlan ping lan
    17
    0 Votes
    17 Posts
    3k Views
    S
    I solved the issue a while ago and forgot to answer here. After entering the IP in Captive Portal / Allowed IP Addresses, everything was perfect. As my CP is authenticated, so I believe that the question was precisely at that point. The other end had no way to authenticate itself to be able to pass and from the moment I released the IP there, he started to communicate. I even thought about doing a test of this type, taking the CP's authentication to see if it worked directly, but I ended up not having time. Anyway ... it's resolved. Thanks to everyone who was willing to try to help.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.