Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense+mikrotik switch=vlan on windows

    Scheduled Pinned Locked Moved General pfSense Questions
    23 Posts 3 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      That's pretty wide ranging, it could be very simple or quite complex.

      What have you tried? What happened? What did you expect to happen?

      https://docs.netgate.com/pfsense/en/latest/vlan/configuration.html#web-interface-vlan-configuration

      Steve

      L 1 Reply Last reply Reply Quote 0
      • L
        learn @stephenw10
        last edited by

        @stephenw10 thanks for replying.
        i created the vlans in the pfsense enabled them and give them rules
        i created the vlan in the mikrotik switch gives it an address but still the windows machine got the old ip address instead of the vlan address
        I read that i need to change the mikrotik to the SWOS instead of routerOS and now I can not access to it
        with the winbox

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          So the switch pulls an IP address from pfSense in the VLAN subnet when it's running as Layer3?

          If it fails when you change the switch to Layer2 it sounds like the VLAN is not correctly defined there.

          L 1 Reply Last reply Reply Quote 0
          • L
            learn @stephenw10
            last edited by

            @stephenw10 no it doesn't get any ip address wheteron L3 or L2

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              @learn said in pfsense+mikrotik switch=vlan on windows:

              i created the vlan in the mikrotik switch gives it an address

              So what exactly was working when you did that with the switch in layer3 mode?

              We're probably going to need to see some screenshots from pfSense and the switch.

              Steve

              L 2 Replies Last reply Reply Quote 0
              • L
                learn @stephenw10
                last edited by

                @stephenw10
                I created the vlan on pfsense
                23b4f779-44c8-4f20-9780-8be509ab73c2-image.png

                give it an address and enable it

                a3e1b602-d447-49f1-8006-5c0fed8c2f70-image.png

                gives it some rules for testing the connection
                1a6a2eb4-a061-4a3d-b76d-0e620ecc11b4-image.png

                that's the pfsense part

                1 Reply Last reply Reply Quote 0
                • L
                  learn @stephenw10
                  last edited by

                  @stephenw10 for the switch part

                  created the vlan on the interface that i want the vlan went from it which basically the Ethernet because the SFPs are all used
                  Screenshot 2022-08-26 114036.png
                  b9d485fe-f080-4d0f-ac9d-bbd565ad7d6d-image.png

                  that's all for the switch part am i missing something ??

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    That appears to be configured as a router.

                    If you using it as a switch I expect to see a list of the ports VLAN 50 is tagged or untagged on. And for a Windows client to be able to connect to pfSense at 172.168.100.1 that would have to be tagged to pfSense and untagged to the client.

                    Steve

                    L 1 Reply Last reply Reply Quote 0
                    • L
                      learn @stephenw10
                      last edited by

                      @stephenw10 I didn't understand tag and untagged thing can you please tell how and explain please!!

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        In order to connect a host device to a VLAN you would usually connect to the host to a switch that is configured with an access port for that VLAN.
                        That means the port the host is connected to must be an untagged member of that VLAN in the switch.
                        And that the port pfSense is connected to must be a tagged member of the VLAN so packets can pass tagged to pfSense.

                        So for example something like this:
                        Screenshot from 2022-08-26 14-54-28.png
                        In this setup pfSense is connected to port 25 and is configured with a VLAN 101 interface.
                        A host can connect to port 23 and will be on VLAN 101.

                        Steve

                        L 1 Reply Last reply Reply Quote 0
                        • L
                          learn @stephenw10
                          last edited by

                          @stephenw10 can you please help me to find this in the mikrotik switches because this what i was searching for .
                          thank you so much for your patience and help .

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Unfortunately I have zero experience with Mikrotik switches so I probably can't help you there. 😉 However I imagine there are numerous videos on youtube etc walking through VLAN config on Mikrotik.

                            Steve

                            L 1 Reply Last reply Reply Quote 1
                            • L
                              learn @stephenw10
                              last edited by

                              @stephenw10 thank you friend

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                For reference, which Mikrotik switch and OS are you using?

                                L 1 Reply Last reply Reply Quote 0
                                • L
                                  learn @stephenw10
                                  last edited by

                                  @stephenw10 i am using two switches of mikrotik CRS305-1G-4S+ and CRS305-1G-8S+ the OS is windows

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Sorry I meant which OS type/version on the switch(es).

                                    L 1 Reply Last reply Reply Quote 1
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Seems like it's this:
                                      https://help.mikrotik.com/docs/pages/viewpage.action?pageId=76415036#CRS3xxandCSS32624G2S+seriesManual-VLANandVLANs

                                      1 Reply Last reply Reply Quote 1
                                      • L
                                        learn @stephenw10
                                        last edited by

                                        @stephenw10 I was on RouterOS and I switched to SWOS

                                        A 1 Reply Last reply Reply Quote 0
                                        • A
                                          akuma1x @learn
                                          last edited by akuma1x

                                          @learn I don't see it mentioned here yet, but the IP address space you chose is out of spec. The 172.16.X.X address space is as follows:

                                          172.16.0.0/12 IP addresses: 172.16.0.0 – 172.31.255.255

                                          You used 172.168.100.X, and that address space looks to belong to Microsoft maybe, somewhere else in the world. First, fix that problem, bring your IP address space within the proper range.

                                          L 1 Reply Last reply Reply Quote 1
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Yup, that's true ^.

                                            I would not expect it to prevent the VLAN config working though.

                                            The VLAN setup in SwOS looks more complex that many switches but I'm sure once you're familiar with it it's easy enough.

                                            Steve

                                            L 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.