Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Only Single VLAN is Working Properly

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    20 Posts 5 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kindacorn @marvosa
      last edited by

      @marvosa

      Their setup / interface is a bit unintuitive . I removed all VLAN 1 (1-8) members, and the issue remained the same. I then did the opposite and added them all back to untagged (1-8), which also had no affect. I was still only able to operate on the WORK VLAN.

      I did notice that I was pulling an APIPA address 169xxx on the workstation tied to HOME VLAN. This made me think that it was a DHCP issue, but I re-verified my settings match WORK VLAN.

      I'm really scratching my head on this one. Thanks again for the help!

      1 Reply Last reply Reply Quote 0
      • K
        kindacorn @NOCling
        last edited by

        @nocling

        Thanks for the response!

        Here's a screencap of the interface assignments:
        ba4fd53c-ca7d-402d-81ec-8a0a1cf578d6-image.png

        Please let me know if I can post anything else that would be helpful!

        1 Reply Last reply Reply Quote 0
        • K
          kindacorn
          last edited by

          BTW, if needed. Here is my outbound NAT automatically created rules:

          036f8d77-51da-430c-95c1-9fd83bbad3bd-image.png

          1 Reply Last reply Reply Quote 0
          • N
            NOCling
            last edited by

            Ok the pfSense site looks good.

            The Switch Part is the other site that must match the pfSense VLAN Tagging.
            Ok you use on that Uplink VLAN 1 untagged, an all other VLANs Tagged.

            The PVID is another Problem, if it doesn’t match, you got a Warning in the Switch Log, but no error.
            If the VLANs up and running, then you have to go for the PVID and finishing the configuration.

            Netgate 6100 & Netgate 2100

            M 1 Reply Last reply Reply Quote 0
            • M
              marvosa @NOCling
              last edited by marvosa

              Unintuitive interface aside, while the TP-Link config looks like it "should" work, there are far too many posts on here stating TP-Link switches do not handle VLANs properly that I wouldn't trust that TP-Link as far as I could throw it though.

              I'll reserve judgment on the Dell since I haven't seen enough of the settings to determine if it's configured properly or not.

              Bottom line though, assuming your HOME interface is configured with 10.0.2.1/24, the interface is enabled and has an any/any rule on it... if you statically set a device in the 10.0.2.0/24 subnet and plug it into an access port configured with a PVID of 2... you should be able to ping 10.0.2.1. If you can't, I'm still heavily leaning towards the switch being the issue.

              You can do a capture on the HOME interface to verify that traffic is even making it to PFsense (I have a strong suspicion that it isn't) You could also run a capture on the switch to verify that the frame is tagged with the correct VLAN.

              If you've made several PFsense changes along the way troubleshooting this, one thing that I've seen magically fix things that don't make sense on occasion is... rebooting PFsense. I don't think your issue is on the PFsense side, but it's worth a shot at this point.

              1 Reply Last reply Reply Quote 0
              • the otherT
                the other
                last edited by

                Hey,
                I used the TP-Link switch as well and yes, it has some irritating stuff to offer. But it will work with VLANs and from what you posted, it seems allrite.

                What ist your setting on pfsense > dhcp server > Static ARP ??

                Is that one active?

                the other

                pure amateur home user, no business or professional background
                please excuse poor english skills and typpoz :)

                1 Reply Last reply Reply Quote 0
                • the otherT
                  the other
                  last edited by

                  But then again:
                  just looked at your tp link screenshot again...
                  it shows, that you have VLAN6 tagged on your trunk/upload/default VLAN1.
                  BUT you do NOT have your HOME VLAN5 tagged on VLAN1
                  (it says so anyways)

                  Change that and have a try! Should be reason for WORK VLAN6 is working and HOME VLAN5 isn't...

                  :)

                  the other

                  pure amateur home user, no business or professional background
                  please excuse poor english skills and typpoz :)

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mcury Rebel Alliance @the other
                    last edited by

                    I have two of those switches..

                    All you need is:

                    Switch:

                    Port1: (connected to pfsense's LAN interface)
                    Tagged VLAN2,3
                    Untagged VLAN1

                    Port5:
                    Untagged VLAN2

                    Port6:
                    Untagged VLAN3

                    dead on arrival, nowhere to be found.

                    the otherT 1 Reply Last reply Reply Quote 0
                    • the otherT
                      the other @mcury
                      last edited by the other

                      @mcury
                      you are absolutely right. And that's why I think it's not working, cause only one VLAN is tagged on Port 1 in the poster's screenshot...
                      I messed up the VLANs in my prior post:
                      Only VLAN3 WORK is tagged on VLAN1...(only Port 6). Port 5 carrying VLAN2 HOME is listed as untagged on VLAN1.

                      the other

                      pure amateur home user, no business or professional background
                      please excuse poor english skills and typpoz :)

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mcury Rebel Alliance @the other
                        last edited by

                        @the-other Indeed.. the switch is not carrying all the VLANs tags through the trunk..

                        dead on arrival, nowhere to be found.

                        1 Reply Last reply Reply Quote 0
                        • K
                          kindacorn
                          last edited by

                          @marvosa @mcury @NOCling @the-other

                          Thanks for the help!

                          The issue has been resolved. I'm still not totally sure what the setting was, but something was of with my pfBlockerNG settings. I was playing around with some settings in there, screwed up, and had to run the wizard again. All of a sudden my HOME VLAN began working properly. Tested on both the Dell and TPLink switches.

                          Thanks again everyone!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.