@tkyead bump. Also, can't edit post, but re-written to shorten and for clarity:
Hi folks,
Having some issues getting VLANs set up. My end goal is to have internet routed through my PFSense box and a Unifi AP and 3 SSIDs connected to different VLANs.
Setup
- WAN -> PF -> Unmanaged switch -> to:
- Wired clients
- PiHole on the default LAN, for local DNS
- WAN -> PF -> Unmanaged switch -> Link port of managed switch
- Unmanaged switch -> Unifi AP w/3 SSIDs:
- SSID 1 - VLAN 10: trusted (192.168.20.0/24)
- SSID 2 - VLAN 30: untrusted smart home network (192.168.100.0/24)
- SSID 3 - VLAN 35: untrusted guest network (192.168.200.0/24)
- PFSense LAN default network - 192.168.10.0/24
In PFSense, I have all 3 VLANs defined & enabled with DHCP turned on. DHCP is working as when I connect to SSID 1 (trusted network) I'll get e.g. 192.168.20.5. I can also ping the PiHole from all wireless clients. Here's where it gets interesting - nslookups from wireless clients to the PiHole do not work (trusted & untrusted both), nor do I have internet connectivity. I do have port 53 allowed from any internal networks -> PiHole, and I'm not currently seeing any blocked firewall entries that would provide any clues either.
Troubleshooting steps taken
I thought the Unifi AP might be messing things up so I connected managed switch -> an old wireless router's LAN port and set all managed switch ports to VLAN 10 (so all wireless clients on the old router's network would get a 192.168.20.x). This surprisingly also does not work in the same way as above -- I can ping PiHole, I can somehow supposedly ping internet addresses (e.g. 1.1.1.1) but I do not have internet connectivity via e.g. web browser.
I'm not sure what else I can try here. Any help would be greatly, greatly appreciated!
Edited to shorten length & for clarity