• VLANs Multicast Isolation

    29
    0 Votes
    29 Posts
    4k Views
    johnpozJ

    Yeah what he is talking about is this

    https://en.wikipedia.org/wiki/Multicast_routing

    Completely different ball game to be honest ;) This is NOT what the OP was talking about.. not at all!!

  • SETUP trunks for failover

    3
    0 Votes
    3 Posts
    484 Views
    DerelictD

    HA+LACP.png

  • SMB - Windows share over vlans

    27
    0 Votes
    27 Posts
    6k Views
    M

    @mcury said in SMB - Windows share over vlans:

    Yes, run in the server, or in pfsense interface connected to the server.
    I presume those 10 networks are /27, /28 /29 right?

    A /26 or less would give you routing issues due to network overlap.

    Just realized that the networks are different, my mistake, disregard the quoted info.

    Nice, good that is now working.
    Even better, now you have more tools to troubleshoot problems in the future.

  • Disney Circle on it's own subnet - New to pfSense and Vlans in general

    6
    0 Votes
    6 Posts
    1k Views
    N

    Thanks for the feedback. I'm reading the "book" on pfSense as I go. I'm starting to get the way it works.

  • Stuck with super easy VLAN setup

    4
    0 Votes
    4 Posts
    582 Views
    U

    yeah indeed I just needed to tag the port on the switch to the corresponding vlan. I figured it must have been something super simple that I was missing 🤦

    thanks guys!

  • VLANs without a 'Smart' Switch?

    19
    0 Votes
    19 Posts
    2k Views
    johnpozJ

    Great - any questions just ask, here to help.

    Remember get those smart switch(es) on order! ;)

  • 0 Votes
    25 Posts
    2k Views
    johnpozJ

    Correct... If your sending it to switch sure just tag everything.. This common... But there is nothing saying 1 of those can't be untagged.. There is nothing wrong with it, you just need to understand what your doing.

    And it sure and the F is not less secure...

    Say for example was going to plug my AP into that port on the firewall.. And for its management network it has to be untagged.. How would it work if tagged everything on the port on the firewall.

    Switch don't care, port don't care - it just needs to know what it tags or doesn't tag... When you put more than one vlan on a port.. Only 1 can be untagged, rest tagged, or all of them tagged... Makes no difference.. You just can not expect to run more than 1 untagged network on a port..

  • XN driver support for 802.1q

    1
    0 Votes
    1 Posts
    370 Views
    No one has replied
  • able to nmap scan across vlans

    7
    0 Votes
    7 Posts
    3k Views
    G

    Got it. Once again thank you. I know what i need to do now.

  • Rogue device on the network?

    7
    0 Votes
    7 Posts
    824 Views
    S

    I don't know why you're getting 2 MAC addresses.

    Because of some weird issue in the firmware?

    Given they're sequential, they are likely from the same device.

    That has to be the case.

    What does Packet Capture show.

    I have not captured any packets so far, but I will.

    One thought, do you have a static mapping configured for that address, but with the wrong MAC?

    I do have a static mapping for MAC address: 50:c7:bf:3d:4b:48 .

    Also, that capture of the AP status shows modes b,g & n listed, which means you have all of those enabled. Mine shows n only. I have configured it that way, as all my devices are capable of using n. You can change the mode on the Wireless Settings page.

    Mea maxima culpa! Setting corrected now.

  • Can't reach my switch's management interface from my VLANs

    18
    0 Votes
    18 Posts
    2k Views
    johnpozJ

    Yeah that was there reasoning behind not being able to remove vlan 1 ;) Now that you can remove vlan 1 from ports - you should be able to limit from what network you can access the switch gui from.

  • 0 Votes
    1 Posts
    323 Views
    No one has replied
  • Random Websites slow under VLAN

    8
    0 Votes
    8 Posts
    905 Views
    idscommI
    UPDATE *
    I did more test today and I don't understand why pfblocker NG causes the issue on my VLAN but not my LAN since both networks are assigned to the same interface and screened by the same rules under pfblockerNG... The IP was white listed therefore it should not be an issue in my opinion...

    @BBcan177 Maybe you can shed some light on my issue if you have time, I would appreciate that. :)

    Thanks in advance!

  • Multiple interfaces, VLAN switching

    13
    0 Votes
    13 Posts
    1k Views
    M

    Okay I'll write what's causing this behaviour. It has nothing todo what the different masks, using pfsense as a wireless-bridge, using bridged interfaces, routing or whatever. Basically it because Linux hosts have default kernel-setting "reverse path filtering" enabled. This can be temporary disabled (untill next reboot) by sudo sysctl -w 'net.ipv4.conf.all.rp_filter=0. Now I understand why it happened. So you have to take that into account.

  • Problem Vlan with Vmware

    1
    0 Votes
    1 Posts
    513 Views
    No one has replied
  • Need help setting up Tagged Bridge Ports

    2
    0 Votes
    2 Posts
    322 Views
    M

    @boniface50 At a high level, typically, you'd have the LAN interface enabled but unconfigured, create tagged VLANs off the LAN interface, tag the VLANs you want to traverse the "trunk" between PFsense and your switch(s), then configure your access ports with the correct VLAN(s).

    The switch configuration will vary across the different vendors, but the above is an overview of what needs to happen. What make/model switch are you using? If you have a Cisco switch, I can offer some guidance. Otherwise, someone else may need to chime in.

    You only need 1 uplink (trunk) per switch unless you want to configure a port-channel for extra aggregate bandwidth. Also, that bridge is going to take a performance hit. I'd recommend removing the bridge, starting from scratch and get tagged VLANs working.

  • netgate XG7100U Intervlan, help please :c

    7
    0 Votes
    7 Posts
    624 Views
    M

    gracias por su atención, solucione mi problema ;)

  • [solved] VLAN and pfsense as KVM guest (no switch)

    2
    0 Votes
    2 Posts
    580 Views
    L

    Im not really sure exactly what was wrong...

    I've started from scratch, and came to the same or new issues. Doing troubleshooting, i found that the broadcast address was way off, which I did not really understood. I then found that the VLAN interface was created as /32 CIDR, which it defaults to, so its highly important to remember to change this. 😆

    Changed it to /24 CIDR, and then it started working.

  • Setting up a VLAN with pfSense, Ubiquiti, and ESXi

    66
    0 Votes
    66 Posts
    12k Views
    P

    @marvosa Now on to the next problem (which will be it's own post if I decide to continue) - HomeKit and WeMo don't talk to one another from the LAN to the VLAN. I found a few guides and attempted to open some ports but it's still not working.

    At this point, I don't know if it's still worth it. I'd love to be able to have the IoT devices on their own network to avoid them compromising my LAN but it seems like a PITA to get them to talk across networks.

  • Advice needed for SG-1100 configuration

    1
    0 Votes
    1 Posts
    186 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.