• make pfsense box a 10GbE switch

    21
    0 Votes
    21 Posts
    4k Views
    johnpozJ

    Oh I see he was put on a time out ;) I would of made it longer.. Maybe he can go demand info on how to do something that makes no sense on facebook or reddit.. But with such a demanding attitude he won't get much help over there either..

  • pfSense SSH connection between 2 different LAN's dropping after 1 minute

    4
    0 Votes
    4 Posts
    548 Views
    chippey5C

    Solved

    It was a layer 8 issue - between the chair and the monitor. Static routing on LAN2 was incorrect. Reconfigured the static route (as per the settings in my previous reply) and connections are not dropping anymore.

  • Routing out to Internet through pfSense HW

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD

    Using LAN is OK as long as you understand that you almost certainly shouldn't put anything but other routers with full infrastructure routing knowledge on LAN.

  • Convert Current Network to VLANs

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD

    If you tell pfSense to tag on VLAN 5, and the switch port connected to that has tagged VLAN 5, then your workstation needs to be connected to an untagged VLAN 5 port on the switch to have layer 2 connectivity to pfSense.

    That's the whole point.

  • LAGG (LACP) - UniFi Switch (16XG)

    43
    0 Votes
    43 Posts
    15k Views
    DerelictD

    OK then the MAC address should be spoofed. The MAC address on the LAGG should also be the spoofed MAC. That is exactly what would be expected.

  • Access for one host to VLAN

    6
    0 Votes
    6 Posts
    655 Views
    DerelictD

    Please post your rule set not a summary of what you think is there. You left out a lot of key information.

  • 7100-1U - Switch ports LAGG problem

    3
    0 Votes
    3 Posts
    972 Views
    RicoR

    @Asamat: Your 'this Bug' URL is this thread here. ☺

    -Rico

  • Losing connection

    5
    0 Votes
    5 Posts
    786 Views
    D

    @derelict Thank you for pointing us in the right direction. Eventually found in the switch a different ARP the in the pfsense. Eventually followed those issue around in the network and solved the issue.

    Thank you for the advice.

  • 0 Votes
    2 Posts
    607 Views
    B

    Two things that I forgot to mention are that I already have OpenVPN set up successfully for my normal network and that since I'm new to the pfSense concept, I've never worked with VLANs on it before. I do, however, understand the VLAN broad concept since I've taken a Principles of Networking class as a computer systems administration student at my university.

  • Trouble creating LAGG - no parent interfaces

    4
    0 Votes
    4 Posts
    2k Views
    M

    Thank you for pointing me in the right direction, I am brand new to pfsense. I wasn't expecting the SG-3100 to have it's built in little switch.

    I am finding conflicting information regarding the SG-3100 being able to support LACP on a LAGG.

    This post indicates the SG-3100 seems to not support LACP
    https://forum.netgate.com/topic/131207/lagg-on-switched-ports-on-sg-3100

    and this Netgate article has LACP described for the SG-3100 has LACP listed as a protocol for the SG-3100.

    I am still have difficulty created a 2 port LAG to a Cisco switch using LACP and trunking multiple VLANs over it.

    Has anyone here been successful at this?

    Thank you.

  • Accessing DSL modem

    8
    1 Votes
    8 Posts
    1k Views
    K

    Now if only I could edit the topic, I could change it to solved!

  • 0 Votes
    5 Posts
    742 Views
    S

    @jknott thanks for your help,
    finely i got it to work, i needed to add the VLAN to the switch and then tag the ports i want to transfer the VLAN with

  • VLAN over openvpn

    5
    0 Votes
    5 Posts
    2k Views
    DerelictD

    @johnsed said in VLAN over openvpn:

    so I have 11 vpns on each router

    Certainly not how I would do it. I'd have a central site feeding all of those. I would have redundancy at the central site so no one failure took everything down. That site would route between the "spokes." Everything necessary to all of the "spokes" would be accessible via the central site.

    They way you have done it is take the number of sites you have and the number of problems that might ring your phone is sites^2 instead of sites/2.

  • New VLAN won't route to other VLANs

    6
    0 Votes
    6 Posts
    970 Views
    johnpozJ

    Did you put a gateway on your vlan 5 rules? This is common mistake where users set a gateway on the rule, this forces traffic out that gateway vs allowing pfsense to use it routing table.

    Post up your rule(s) you put on vlan 5 interface

    Blocking rfc1918 on the interface have seen as well.

  • kernel arp moved from

    3
    0 Votes
    3 Posts
    1k Views
    M

    Hello
    Completely true, IP duplicated in the LAN segment.

    Thank you so much.

  • How can I verify VLAN support for my NIC?

    18
    0 Votes
    18 Posts
    4k Views
    stephenw10S

    Ah, well then it shouldn't be required through the edge router either. Just a matter of getting it to pass the traffic.

    Steve

  • Camera VLAN Configuration

    5
    0 Votes
    5 Posts
    1k Views
    johnpozJ

    @sccmadmin said in Camera VLAN Configuration:

    The DVR will need to have access to both VLANs to access the cameras and to be accessed from user computers to login to web interface to view the camera feed/recordings.
    How can I accomplish this?

    That is called routing.. And yes that is how any device in vlan X gets access to devices not on vlan X.. Be they are vlan (tagged) or just different physical networks.

    That is what pfsense does out of the box.

    You can set the rules to be any any on both networks/vlans or you can restrict traffic to the specific ports needed.

    I would NOT recommend dual homing your DVR.. Unless your going to isolate all your camera's behind the DVR itself on different vlan that doesn't even have to touch pfsense. And then another nic on the DVR will give the DVR access to the rest of your network, etc.

  • Connecting two edge switches together

    Moved
    3
    0 Votes
    3 Posts
    508 Views
    johnpozJ

    What needs to be done is all the vlans that you want on the downstream switch need to be tagged and allowed on the port that connects the switches on both switches.. Cisco calls that a trunk port yes.

    edit: BTW moving this to the L2 section.

  • VLAN Trunking over multiple ports

    2
    0 Votes
    2 Posts
    1k Views
    dotdashD

    Create a LAGG on pfsense and on the switch stack. Use the LAGG as the vlan parent.

  • MAC Y VLAN

    2
    0 Votes
    2 Posts
    320 Views
    NogBadTheBadN

    If your talking about changing the vlan interface mac addresses, you can’t you need to change the mac on the parent interface.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.