• 0 Votes
    17 Posts
    118 Views
    johnpozJ
    @HidekiSenpai what does it show in your dns lookup diag..
  • Netgate 4200 : Multiple VLANs Coming from Multiple APs

    6
    0 Votes
    6 Posts
    365 Views
    C
    Quick update that the advice above worked great. Stripped out those bridges and re-architected all APs and switches across one link. 5 total VLANs. Unexpected benefit was what seemed like at least a 20% bump in overall performance from the 4200. Note: Also took the opp to upgrade the 4200 w a SSD so that it's now a "Max"- maybe that helped w perf, too.
  • Take two at this a year and no replies later.

    2
    0 Votes
    2 Posts
    220 Views
    patient0P
    @piook said in Take two at this a year and no replies later.: But when I connect the LAN port to the switch and everything over that port is 1GB Full duplex Which port on the USW Pro Max 16 are you connection the LAN cable. Of course you are aware that only 4 ports are 2.5G on that switch (according to the product page) What speed selection does is show if you remove the LAN cable, still 1G the fastest speed selectable? What happens when you switch the ports from the pc and the LAN cable? In general you would have better support on the Unifi forum I think.
  • LAN IF uses different MAC than VLAN on LAN

    4
    0 Votes
    4 Posts
    259 Views
    T
    @patient0 VLAN 1 is a normal VLAN. 0 means untagged, which means that the packets don't have any VLAN information in it and the switch assignes the Primary VLAN (port in trunk mode)/assigned VLAN (port in access mode) to packets entering the switch port and sets the VLAN number on those packets.
  • VLAN without a smart switch possible?

    5
    0 Votes
    5 Posts
    263 Views
    C
    @keyser Thanks for the reply. I have a spare port on my router and I will use it to experiment with.
  • LAN 4 and LAN 3 of SG2100 can be use for VLAN 10 or VLAN 20?

    7
    0 Votes
    7 Posts
    341 Views
    S
    @chris.doldolia The 2100 has a 4 port switch. The documentation page I linked above will allow you to treat a given port as (change it to become) a separate network interface. In the default configuration the individual ports cannot have an IP address because they are all the same LAN. If you want to add a VLAN and have it work on all four ports then I think you need to add the VLAN to "port 5" which is the switch. You might post your Interfaces > Switches pages, and Interfaces > Assignments pages.
  • Config VLAN, Ports, Switches and Trunk?

    6
    0 Votes
    6 Posts
    399 Views
    M
    Now, I can start configure more rules on the FW + connecting the Netgate directly to my ISP Modem. Great Is there a recommende list of FW settings laying around? I saw several of the Youtube videos where they kind of had their own focus. Based on the description, this would be a GUEST network. Here’s an example for you: Note: GUEST users are not allowed to use pfSense’s DNS server. Instead, I’m using DHCP to provide a public DNS server for them. [image: 1753873577326-5f99a867-d081-4c33-ac6a-de697d0826fb-image.png] Internal network alias is an alias that contains all my local networks.
  • VLAN routing

    7
    0 Votes
    7 Posts
    346 Views
    B
    @SteveITS Yep. The address in that /29 was given by DHCP.
  • L3 switching with pfsense

    8
    0 Votes
    8 Posts
    580 Views
    C
    @johnpoz You just don't get the different in working on layer 3 and layer 2. It is why you have default gateways and default routes and they are different. ThAT SEEMS TO BE OVER YOUR HEAD. Your firewall to the world is going to be layer 3. You are lost in pfsense and you can't see the forest for the trees. Go away John please do not reply to my threads. I will try not to post any more here. And yes I ran a small team of network people a long time ago. I had over 4000 PCs and around 50 locations so get over it. You ran me off last time and I went back to Cisco over pfsense. Look back in the threads years ago. Plus pfsense was having routing issues or slowdowns on routing as I was doing layer 3 back then at home. Version 2.8 is fast now which is good. Having a connection of 10gig reduces your latency whether you run full 10gig or not. I have 1 gig of data on a 10gig connection. I think this is best you can do now for home. I have a Cisco 10gig layer 3 switch I plan to install soon. So I can push the extra data bandwidth.
  • 0 Votes
    5 Posts
    480 Views
    C
    @spickles I would think the easiest way to replace a Cisco ASA 5505 would be use pfsense as a firewall not a router. Keep using your Cisco L3 switch. I do that at my home. I use an Cisco L3 switch and route between my L3 switch and pfsense. You lose pfsense control over your local network. This would not be an issue with you as you will already have that with your L3 switch. Setup pfsense with no vlans and keep all the vlans on your L3 switch. Then set up your firewall rules and static routes to your L3 switch.
  • Two VLANs set up alike, one does not get Internet

    16
    0 Votes
    16 Posts
    2k Views
    D
    Indeed, I have to consult the community on how to configure the captive portal, too.
  • Surfshark Wireguard VPN on Guest VLAN Blocking Some Content

    3
    0 Votes
    3 Posts
    380 Views
    P
    Thanks! Surfshark does not support IPv6. DHCPv6 Server is not running on Guest Guest VLAN IPv6 Configuration Type is None. [image: 1751811989749-e300cdf0-d2f6-472a-bc37-67536aa7f008-image.png] Router Advertisement Router Mode is Disabled [image: 1751812258868-585e8e78-a12d-4437-8663-7ea80d8c1555-image.png] Added a Guest firewall rule at the top of the stack to block IPv6 traffic [image: 1751812578788-7cf2241b-4d32-4d08-9a25-75e272d7ae31-image.png] Also tested disabling IPv6 in the APN on my phone. Didn't help. We're still having problems with some apps/content on our phones.
  • Need help with transparent bridge DNS VLan setup

    1
    0 Votes
    1 Posts
    62 Views
    No one has replied
  • ACCESS DIFFERENT VLAN ON A DIFFERENT PORT OF PFSENSE

    11
    0 Votes
    11 Posts
    911 Views
    HHUBSH
    I managed to solve this myself today. The reason I can't ping the client directly connected to the igc1 of pfsense is because of the Bitdefender stealth mode setting. Once I turned it off, I can now ping the client. I came up with this solution because I tried Ubuntu on a flash drive, and I can ping it, so there is a problem with the firewall of the Windows machine. That's why I checked all the firewall settings one by one on the Windows client.
  • Best simple network

    25
    0 Votes
    25 Posts
    2k Views
    Y
    @Dobby_ Thought I'd be the only one who would ever use a number like 300 in an IP address.
  • static are not used when trying to communicate between 2 pfsense CE

    5
    0 Votes
    5 Posts
    230 Views
    U
    Ok I tried your solution, and it's ok. Really thank you, for the solution and for the explaination. I really don't like doing thing without understanding what I'm doing and why. One more time Thank you
  • CANNOT PING VLAN INTERFACE IP FROM SAME VLAN

    4
    0 Votes
    4 Posts
    435 Views
    HHUBSH
    @Bob-Dig said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN: @HHUBS said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN: Or I should ping it from the same VLAN even if no rules are added? No, it is the firewall and with that, it is able and will block the connection without rules. Different would be to ping a host on a switch, which is in the same LAN. Then the connection is not hitting the firewall in the first place and the firewall can do nothing about it. @johnpoz said in CANNOT PING VLAN INTERFACE IP FROM SAME VLAN: @HHUBS out of the box the only interface with default rule to allow is lan that defaults to an any any rule, anti-lockout.. If you create a new interface be it vlan or native you would have to add the rules you want. Yes by default no rules would hit the default deny and yes block ping, or any other access. Thank you so much for your help.
  • 0 Votes
    1 Posts
    174 Views
    No one has replied
  • communicating via vswitch from vms in bridges

    15
    0 Votes
    15 Posts
    918 Views
    C
    I got it to work. It had to do with not setting mtu of 1400. I can now do dns lookup and it works! Thank you for your suggestions.
  • 0 Votes
    1 Posts
    158 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.