• pfSense and Unifi basic config with vlans

    18
    0 Votes
    18 Posts
    905 Views
    P

    @Austin-0

    Ah ok. My first time playing with vlans so I thought that as long as a vlan capable switch was in the middle I could still feed multiple vlans down one cable.

    I’m currently setting up another client with windows. Once done I’ll change a port to each individual vlan only, assign it an IP from the respective pool and test then feed back. Would be great if this is working and it was just my understanding of it being lacking as I can then start asking my next questions in the appropriate threads.

  • Ipv6 Track interface and dot1q trunk wonkiness

    2
    0 Votes
    2 Posts
    209 Views
    B

    Looks like its more complicated, something in my configuration is causing other issues. I have another unit to test with but if I change the lan interface to get its address from dhcp then it exhibits the same issue, interface goes off and online over and over and never stops unless I reboot. Reboot and all id fine unless I unplug and then the issue repeats. So something is going on with that interface, if I change it back to static then all is well, so I know track interface causes issues even with a static IP, never comes back unless I reboot and if you unplug it never comes back online. I get the same results when I remove the track interface and select DHCP to configure the interface.

    I do know that in a default configuration I do not see the issue so it's something else going on with my configuration but not sure where or how to look, anyone have any suggestions let me know, thanks.

  • No Connection

    1
    0 Votes
    1 Posts
    154 Views
    No one has replied
  • Maximum number of vlans in 2.7 GUI

    5
    0 Votes
    5 Posts
    375 Views
    N

    Thats a web browser issue. I had the same problem with "Apply Changes" button missing. Resolved with cache cleaning.

  • Best approach to tie LAN and Opt1 together on a 4100?

    7
    0 Votes
    7 Posts
    765 Views
    S

    @johnpoz

    Thanks for that info! I'll put in a managed switch in between the 4100 and the 2 other managed switches, then.

  • 0 Votes
    2 Posts
    234 Views
    R

    @CyberTend Looks like you hit a bug or have a partially installed driver.

    If you're running ZFS I'd roll back to 23.05 or 23.01, if you're not go to https://go.netgate.com to open a ticket to get the 23.05.1 release image and reinstall.

  • Error adding VLAN's in pfSense 2.7 with ICE driver

    8
    0 Votes
    8 Posts
    742 Views
    X

    @Bruce74 My pleasure!

  • No VLAN traffic being seen with DDA NIC in Hyper-V

    3
    0 Votes
    3 Posts
    367 Views
    A

    Looks like I was missing something: no client on these VLANs were getting DHCP (IPv4) assignments. They did, however, have active IPv6 addresses. Apparently, DHCP snooping was enabled on all the switches, and disabling it solved the problem. I noticed this shortly after posting.

  • Port mismatch after adding VLANs

    2
    0 Votes
    2 Posts
    221 Views
    T

    @DaveinTN
    Without knowing how you setup the VLANS (at the console after installing PFSense fresh or from the web interface after completing a basic install and then running the first time wizard from the web interface and configuring a basic working LAN/WAN) it's hard to say what is happening.

    It sounds like it didn't finish the basic setup after install and is doing that over and over, or not saving changes... What I prefer to do is install PFSense, just the standard setup through the install wizard. Then in the console, I make sure that the correct network ports are selected for LAN/WAN and set the proper network for LAN. I then go into the web interface and complete the first time wizard (verify interfaces, change admin password...). With that complete, I verify I have internet connectivity. Then I reboot and configure any other packages such as SNORT or PFBlocker. Once I have those basics UP I then go into INTERFACES/ASSIGNMENTS to create my VLANS on the VLAN tab, then assign them to the correct ports on the INTERFACES ASSIGNMENTS tab.

    If you have a working PFSense already and are adding VLANS as a new feature- are you logged into the web interface, INTERFACES/ASSIGNMENTS, and does it appear to be saving the changes when you SAVE?

  • ARP packets "disappearing" on back to back link

    1
    0 Votes
    1 Posts
    258 Views
    No one has replied
  • Using pfsense as a switch

    2
    0 Votes
    2 Posts
    1k Views
    S

    @soultwist Nevermind. I solved it myself. This is what happens when you don't take a break. I was making it overcomplicated. When I thought about after my break I realized I need to skip all the bullshit with bridges and laggs and just give the free 10G port on pfsense a separate interface and put the Truenas on it's own vlan there and just give all other subnets access to it thru the rules instead.
    Just a smidge simpler and it works. :)

    Thanks anyway.

  • Configure LAN port as VLAN?

    7
    0 Votes
    7 Posts
    553 Views
    AndyRHA

    Same here, did it once to just learn a bit.
    To my knowledge bridging is the only way, but smarter people may point out some other way.

  • adding static arp entry fails after upgrade to 23.05.1

    2
    0 Votes
    2 Posts
    263 Views
    D

    ok, so spotted the issue... the 5G router is setting the netmask to /31 and then providing a gateway in the next /31 so obviously that won't work (I'm assuming here it is the router and not actually the ISP APN). Seems pfSense has actually fixed some issues in the last two versions to correct that behaviour as the IP assignment has been the same throughout. The 5G router has 2 options for the interface subnet selection in passthrough/bridge mode - PTP (/31) which I imagine would work if the IP and gateway were on appropriate subnet boundaries or auto which in my case uses /30 so that now works. Oddly though I now don't receive the public static IP via dhcp if I also have an alias IP in the dhcp interface config on pfSense (can add an IP alias instead - need this to be able to actually connect to the 5G router locally if required on it's rfc1918 address) but removing that then all works again. Will keep investigating

  • 7100 Wan access over VLAN

    1
    0 Votes
    1 Posts
    179 Views
    No one has replied
  • 0 Votes
    4 Posts
    773 Views
    johnpozJ

    @yfreiberger said in Configuring PFsense as transparent firewall over multiple interfaces between access points and vlan edge router subnets, With different filtering rules for each Existing interface:

    in the sense that it effectively blocks traffic originating from the internet.

    That is really any home, even a 20$ wifi router would do that..

    if your current device does not have the ability to filter between vlans the way you want, then replace it with pfsense. Putting in a in between your edge router and your devices is way more complex then just using pfsense as your router that is for sure.

    But you can can create multiple bridges on pfsense, one for each vlan on your network.

    Most smart or managed switches, other then the cheap entry level ones would allow for ACLs to filter traffic on vlans/ports as well. There would be no need for pfsense.. I filter traffic at my switch, mostly just for broadcast and multicast - but depending on your switch you could do your "filtering" there.

    But the simple solution is just use pfsense as your router..

  • VLAN using Microsoft DHCP server

    9
    0 Votes
    9 Posts
    3k Views
    dotdashD

    This shouldn't involve your firewall at all. Create the vlans on the switches, set the DHCP helper/relay on the switches to point to your DHCP server, and create the scopes on your dhcp server.

  • Interface gets stuck, only reboot helps IFDISABLED

    1
    0 Votes
    1 Posts
    210 Views
    No one has replied
  • LAGG in Bridge

    Moved
    13
    0 Votes
    13 Posts
    2k Views
    P

    @hkjarral Hey
    Thank you for your fast answer.
    I'm probably dumb, didn't see this thread is about PFsense...
    I tried to create the bridge via GUI, but of course it is different.
    Anyways, thank you.

  • 23.05 ATT Bypass

    2
    0 Votes
    2 Posts
    244 Views
    W

    Fixed by applying patches via system patches.

  • Configure VLAN over WAN

    1
    0 Votes
    1 Posts
    176 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.