• L2 VLAN on Pfsense

    4
    0 Votes
    4 Posts
    910 Views
    johnpozJ

    You can if you want to use the same ID, as long as one side connected to pfsense is untagged vs tagged., since they are isolated by by L3. But you would not use the same L3 network.

    Its not tricky.. Upstream and Downstream routers are used all the time everywhere. What think your misunderstanding is the difference between a vlan (layer 2 always) and a L3 network.

    What you use for the ID is only going to matter with devices on those L2 networks. Unless you want to use pfsense as a layer2/bridging firewall the vlan ID have zero to do with what is on 1 side of a L3 firewall/router and the other side.

    As to creating a vlan on pfsense. Its as simple as creating the vlan, assign an ID and put on your parent physical interface.

    https://www.netgate.com/docs/pfsense/interfaces/vlan-trunking.html

  • VLAN DHCP Lease Table

    3
    0 Votes
    3 Posts
    822 Views
    johnpozJ

    If your devices got an IP from the dhcp server, then yeah they are going to be in the dhcp lease table.. If your not seeing them, then they didn't get an IP from pfsense.

  • 10GBe Network vlan tagging issue in Windows NIC Teaming.

    1
    0 Votes
    1 Posts
    705 Views
    No one has replied
  • Is setting mac address setting in the bridge gui broken?

    Moved
    3
    0 Votes
    3 Posts
    620 Views
    jimpJ

    @someone0 said in Is setting mac address setting in the bridge gui broken?:

    I'm using pfsense version 2.4.3-RELEASE-p1 (amd64) and I have setup a bridge for the LAN side. But for some reason, when I have a valid fictitious mac address in the setting for the bridge GUI(interface > bridge0 > MAC Address), it won't take that. Every time I rebooted, I keep getting random mac address. Is this menu setting broken or am I doing something wrong? or is there a workaround?

    There is an open bug for this: https://redmine.pfsense.org/issues/8138

  • Not getting DHCP on VLAN, configuration issue?

    2
    0 Votes
    2 Posts
    430 Views
    DerelictD

    That all looks good. Whatever you connect to igb2 has to be tagged VLAN 20. After that any access port on the switch that is on VLAN 20 should get DHCP.

  • VLAN and MTU

    2
    0 Votes
    2 Posts
    816 Views
    No one has replied
  • This topic is deleted!

    9
    0 Votes
    9 Posts
    78 Views
  • Network strangeness with pfSense

    1
    0 Votes
    1 Posts
    635 Views
    No one has replied
  • Hardware switch or NIC brridge?

    Moved
    12
    0 Votes
    12 Posts
    2k Views
    johnpozJ

    @jknott said in Hardware switch or NIC brridge?:

    There used to be some cut through switches, that would start switching as soon as it learned the destination MAC, but those have disappeared

    And there still are, the cisco nexus 5000 line did/does it... The 9000 series nexus I believe default to cut through but can be put in store and forward, etc.

    So disappeared is not true... But cut through was never in the soho or budget lines of any switch maker..

  • VLAN tagging with untagged parent interface

    16
    0 Votes
    16 Posts
    4k Views
    jahonixJ

    @jknott said in VLAN tagging with untagged parent interface:

    You'll find that's typical when VoIP phones and computers share the same cable.

    Do I sound as if I needed this explained?
    Being able to remember the distant past but not 5 minutes ago is called Morbus Alzheimer. My mom suffers from it badly.

    Same with WiF access points and multiple SSIDs.

    Buy serious wireless APs with all traffic tagged, not consumer gear on steroids.

  • One L3 per VLAN across 2+ interfaces

    19
    0 Votes
    19 Posts
    3k Views
    DerelictD

    @braveben said in One L3 per VLAN across 2+ interfaces:

    Speaking of those sexy XG-7100’s 10Gbit SFPs, how would they respond to being a trunk with the same VLAN’s as one of the switch ports? Could I still share a L3 interface/IP on the single VLAN?

    You would, again, have to software bridge them. I would suggest using the 10G to an external switch instead.

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    39 Views
    No one has replied
  • VLAN setup

    8
    0 Votes
    8 Posts
    2k Views
    JKnottJ

    @pvn said in VLAN setup:

    my workstation will have eth0 in 10.1 (corporate network) and eth1 in 10.2 (my private network)

    You better be careful with that. You might wind up bypassing the corporate network security.

  • This topic is deleted!

    21
    0 Votes
    21 Posts
    424 Views
  • first steps with HA: where to put VLANs?

    Moved
    5
    0 Votes
    5 Posts
    779 Views
    JeGrJ

    @sgw As you were guessing: create the VLAN(s) on both nodes of the cluster, setup a CARP VIP for that VLAN and just treat it like another physical "LAN" interface in any regard, then you're good to go.

    Greets

  • VLAN: How do you assign/use the native/untagged VLAN

    Moved
    21
    0 Votes
    21 Posts
    19k Views
    jahonixJ

    @tlum:

    …What I'm hearing is that pfSense can't create a default interface dedicated exclusively to untagged traffic...

    Where do we lose you when saying:
    EM0 is your default interface and handles all untagged traffic.
    EM0_VLANxyz rides on top of that, tagged.

    You don't need to create it, it's there when you assign a network to a (physical) interface.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.