Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    XG-7100: multiple VLAN interfaces on single physical port

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    22 Posts 3 Posters 4.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      I don't see a pfSense interface for WAN2 (4092).

      It is normal to see checksum errors when checksum offloading is enabled because at the point of the pcap the checksum has not been calculated yet since it's done by the ethernet hardware.

      You might have to explain what exactly isn't working at this point if you want more directed feedback.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • M
        maliaga
        last edited by

        Yes, WAN2 is not being used yet.

        What exactly isn't working? None of the VLAN (11-14) interfaces can reach the net, in any direction. On those interfaces, any traffic originated on the host or directed to it seems to die on the physical port. Looks like a disconnected port.

        On SG-8860, with the same setup (4 VLANS on a physical port), with the same rules and same configuration on the switch port it's connected to (tried 2 different switchs so far), it works as expected.

        I never had this problem before. Just setting up XG-7100 to be a CARP backup node, the other interfaces work just fine, but can't get VLAN interfaces to work. I don't know if I'm missing something about how the new "switch interfaces" work, just not sure what else to try.

        Thanks

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Can you ping the closest interface address?

          Did you add firewall rules? Did you check outbound NAT?

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            What is the configuration of the switch connected to port 4?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • M
              maliaga
              last edited by

              Yes, all that. I also captured traffic but nothing shows on those interfaces. Examples:

              Host A (8860) 192.168.14.10 (VLAN14)
              Host B (7100) 192.168.14.11 (VLAN14)

              • If I ping from host A to B, I can see icmp traffic coming out from A, and nothing getting to B (it works OK with any other host on the net)
              • If I ping from host B to A, I can only see ARP traffic coming out from B, asking for B's MAC (it doesn't work pinging any other host on the net)
              • If I capture packets on VLAN interface 14 on B, I don't get any broadcast from the network either. I see VRRP coming out, but not getting to B or the net

              Config on the switch: it's a trunk port, PVID 1, tagging all VLAN's. I use the same switch port configuration with the physical port I use for VLAN's on 8860, and it works!

              Also tried setting port ETH5 as untagged VLAN 14, on an untagged switch's port, and works OK. So it's not a switch trunking or firewall rules issue

              1 Reply Last reply Reply Quote 0
              • M
                maliaga
                last edited by

                Just for the record. I finally found the cause of this: the interface was connected to the wrong switch port. It's hard to spot things like this when working remotely, but that was the problem.

                Thanks anyway for your help

                1 Reply Last reply Reply Quote 2
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Thanks for letting us know.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • N
                    nick.loenders @maliaga
                    last edited by

                    @maliaga Hi, how can you have vlan 4091 AND vlan 11 on the same ETH2 port?

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @nick.loenders
                      last edited by

                      @nick-loenders said in XG-7100: multiple VLAN interfaces on single physical port:

                      @maliaga Hi, how can you have vlan 4091 AND vlan 11 on the same ETH2 port?

                      Tagged or untagged?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      N 1 Reply Last reply Reply Quote 0
                      • N
                        nick.loenders @Derelict
                        last edited by

                        @derelict I don't fully understand the difference.

                        Basically I want one network cable connected on one port , eg ETH2 and pass two vlans on it, the 4091 (LAN) with DHCP 10.0.0.0/24 and the vlan 70 (VLAN) with DHCP 192.168.70.0/24

                        Problem is, I could connect the LAN on ETH2 and the VLAN 70 on ETH8 so with two cables to the first switch, but there is only 1 cable going from the first switch to the second at this time :(

                        DerelictD 1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate @nick.loenders
                          last edited by

                          @nick-loenders But you need to say whether you want one VLAN untagged and one tagged or both tagged (both cannot be untagged on the same port so that is not an option). It depends on how the device you are connecting to that port is configured.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          N 1 Reply Last reply Reply Quote 0
                          • N
                            nick.loenders @Derelict
                            last edited by

                            @derelict
                            HI I have now:

                            f2c8be1e-9afe-4b93-9a32-3f736753a52b-image.png

                            d623fd65-ca63-4597-bd08-5e7500a8d622-image.png

                            So how should I set it up, so it would work then?

                            N DerelictD 2 Replies Last reply Reply Quote 0
                            • N
                              nick.loenders @nick.loenders
                              last edited by

                              @nick-loenders And then it went quiet :)

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate @nick.loenders
                                last edited by

                                @nick-loenders Considering this is in Off-Topic and Non-Support Discussion I would expect it to get lost.

                                You still didn't specify what you wanted tagged and untagged and where.

                                How is the switch port connected configured?

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                N 1 Reply Last reply Reply Quote 0
                                • N
                                  nick.loenders @Derelict
                                  last edited by

                                  @derelict Well as far as I understand tagged and untagged I would say the vlan 4090 (which is the normal LAN) is untagged and vlan70 is tagged??

                                  DerelictD 1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate @nick.loenders
                                    last edited by

                                    @nick-loenders VLAN 70 is untagged on port 8. The switch port on the 7100 needs to match the switch port it is patched to. It's just like any other external switch with a pfSense lagg connected to it as a "trunk" link.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.