• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WiFi host can’t pull an IP from DHCP

Scheduled Pinned Locked Moved DHCP and DNS
24 Posts 5 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    DominikHoffmann @viragomann
    last edited by Nov 6, 2022, 2:10 PM

    @viragomann

    Based on the firewall rules there is no traffic on the home automation network:

    Screenshot 2022-11-06 at 9.09.24 AM.png

    versus this on the guest WiFi network:

    Screenshot 2022-11-06 at 9.09.16 AM.png

    V B 2 Replies Last reply Nov 6, 2022, 2:14 PM Reply Quote 0
    • V
      viragomann @DominikHoffmann
      last edited by Nov 6, 2022, 2:14 PM

      @dominikhoffmann
      I was requesting a Diagnostics > Packet Capture.

      There is no rule to allow DHCP traffic, even it is implicitly allowed. So you won't see any packet matching a rule there.

      D 1 Reply Last reply Nov 6, 2022, 10:36 PM Reply Quote 1
      • B
        Bob.Dig LAYER 8 @DominikHoffmann
        last edited by Bob.Dig Nov 6, 2022, 2:37 PM Nov 6, 2022, 2:37 PM

        @dominikhoffmann So you have switchports inside of pfSense which I don't have, could make thinks different.

        And your switch has only one place to configure VLANs?

        Same goes for the AP, maybe it can be differentiated if you want the VLANs only in the AP or also outside of the AP?

        D 1 Reply Last reply Nov 6, 2022, 10:26 PM Reply Quote 1
        • J
          Jarhead @DominikHoffmann
          last edited by Nov 6, 2022, 4:11 PM

          @dominikhoffmann
          WAN net is just the network assigned by your ISP, it's not the internet.

          You don't show if you're vlans are tagged or untagged on your switch.
          Assuming you have 3 AP's? Ports 2, 3 and 4? With 8 going to the router?

          if so, ports 2, 3, 4 and 8 should all be set with your LAN as pvid as untagged, and vlans 11 and 13 as tagged.
          Is that what you have?

          D 1 Reply Last reply Nov 6, 2022, 10:23 PM Reply Quote 1
          • D
            DominikHoffmann @Jarhead
            last edited by Nov 6, 2022, 10:23 PM

            @jarhead said in WiFi host can’t pull an IP from DHCP:

            You don't show if you're vlans are tagged or untagged on your switch.

            Here is how the port tagging on the switch is presented:

            Screenshot 2022-11-06 at 5.15.29 PM.png
            Screenshot 2022-11-06 at 5.15.37 PM.png
            Screenshot 2022-11-06 at 5.15.44 PM.png

            Assuming you have 3 AP's? Ports 2, 3 and 4? With 8 going to the router?

            That’s the way I have it set up.

            1 Reply Last reply Reply Quote 0
            • D
              DominikHoffmann @Bob.Dig
              last edited by Nov 6, 2022, 10:26 PM

              @bob-dig said in WiFi host can’t pull an IP from DHCP:

              And your switch has only one place to configure VLANs?

              Both VLANs are on the switch port associated with the physical OPT port, because that’s where the Ethernet going to my switch is plugged in.

              Same goes for the AP, maybe it can be differentiated if you want the VLANs only in the AP or also outside of the AP?

              If I had the VLANs only inside the AP, I couldn’t use the pfSense firewall to block access to my LAN from those two VLANs. They are supposed to provide internet access, only, and no access to other hosts or devices on my home LAN.

              1 Reply Last reply Reply Quote 0
              • D
                DominikHoffmann @viragomann
                last edited by Nov 6, 2022, 10:36 PM

                @viragomann

                Here is the result of the packet capture running for about 90 s, while my iPhone was trying to get onto the newly set-up VLAN ID 13 WiFi network:

                Screenshot 2022-11-06 at 5.30.26 PM.png

                Nothing! Let me think about what that implies.

                Here is a packet capture with my phone getting onto the VLAN ID 11 WiFi network (successfully):

                Screenshot 2022-11-06 at 5.34.16 PM.png

                So, evidently, devices trying to get onto VLAN ID 13 don’t get an IP address, because their DHCP request never gets to the pfSense appliance.

                R V 2 Replies Last reply Nov 6, 2022, 11:03 PM Reply Quote 0
                • R
                  rcoleman-netgate Netgate @DominikHoffmann
                  last edited by Nov 6, 2022, 11:03 PM

                  @dominikhoffmann What's running at 11.1? 2d22bd9a-bd2f-497e-baea-046f54db5fcd-image.png

                  this implies the request comes in (UDP port 68) and a response goes out.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  R 1 Reply Last reply Nov 6, 2022, 11:04 PM Reply Quote 1
                  • R
                    rcoleman-netgate Netgate @rcoleman-netgate
                    last edited by Nov 6, 2022, 11:04 PM

                    I would run the capture on the VLAN on port UDP 68 and nothing else... just sniff the traffic. The extra stuff showing up is unhelpful.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    D 1 Reply Last reply Nov 6, 2022, 11:09 PM Reply Quote 0
                    • D
                      DominikHoffmann @rcoleman-netgate
                      last edited by Nov 6, 2022, 11:09 PM

                      @rcoleman-netgate said in WiFi host can’t pull an IP from DHCP:

                      I would run the capture on the VLAN on port UDP 68 and nothing else... just sniff the traffic. The extra stuff showing up is unhelpful.

                      Well, that's from the VLAN that’s working. The same packet capture running on the VLAN that is not is just crickets.

                      1 Reply Last reply Reply Quote 0
                      • D
                        DominikHoffmann
                        last edited by Nov 6, 2022, 11:10 PM

                        I thought of another troubleshooting step: I will temporarily re-tag my guest network with VLAN ID 13 (from VLAN 11) and will see, what happens.

                        R D 2 Replies Last reply Nov 6, 2022, 11:27 PM Reply Quote 0
                        • R
                          rcoleman-netgate Netgate @DominikHoffmann
                          last edited by rcoleman-netgate Nov 6, 2022, 11:28 PM Nov 6, 2022, 11:27 PM

                          @dominikhoffmann c9129c6e-62c6-4418-b2ed-250ca978b385-image.png

                          What is the Interfaces->Switches Ports and VLAN tabs like?

                          You have a device with a built-in switch, you have VLANs not communicating, I don't see any screenshots of the actually Netgate's 1) Model number and 2) built-in switch programming.

                          ec2ef984-c617-419b-aa99-265b05b37508-image.png

                          Here are the pages on my 7100:
                          776f5e94-a650-4e8b-83b4-03d7eb9654b2-image.png
                          95cf0bba-b545-42bc-a2d1-d5cef32ab7e8-image.png

                          Ryan
                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                          Requesting firmware for your Netgate device? https://go.netgate.com
                          Switching: Mikrotik, Netgear, Extreme
                          Wireless: Aruba, Ubiquiti

                          D 1 Reply Last reply Nov 6, 2022, 11:55 PM Reply Quote 1
                          • V
                            viragomann @DominikHoffmann
                            last edited by Nov 6, 2022, 11:30 PM

                            @dominikhoffmann
                            So something with the VLAN configuration on one of the involved devices might be wrong. You should recheck all settings. I'd suspect the switch.

                            1 Reply Last reply Reply Quote 1
                            • D
                              DominikHoffmann @DominikHoffmann
                              last edited by Nov 6, 2022, 11:34 PM

                              The APs routing the IoT WiFi SSID through the VLAN ID 11 interface works, while the APs routing the guest WiFi SSID through the VLAN ID 13 interface does not work.

                              R 1 Reply Last reply Nov 6, 2022, 11:38 PM Reply Quote 0
                              • R
                                rcoleman-netgate Netgate @DominikHoffmann
                                last edited by Nov 6, 2022, 11:38 PM

                                @dominikhoffmann Please check out my request above for your Netgate firewall switch screen shots like what I provided...

                                Ryan
                                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                Requesting firmware for your Netgate device? https://go.netgate.com
                                Switching: Mikrotik, Netgear, Extreme
                                Wireless: Aruba, Ubiquiti

                                1 Reply Last reply Reply Quote 1
                                • D
                                  DominikHoffmann @rcoleman-netgate
                                  last edited by Nov 6, 2022, 11:55 PM

                                  @rcoleman-netgate

                                  That’s the answer:

                                  Screenshot 2022-11-06 at 6.37.39 PM.png

                                  I just added that last VLAN group. I knew, that I had forgotten something!

                                  Hurray! Success!

                                  Thanks so much, Ryan!

                                  R 1 Reply Last reply Nov 7, 2022, 12:05 AM Reply Quote 0
                                  • R
                                    rcoleman-netgate Netgate @DominikHoffmann
                                    last edited by Nov 7, 2022, 12:05 AM

                                    @dominikhoffmann You're welcome.

                                    Ryan
                                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                    Requesting firmware for your Netgate device? https://go.netgate.com
                                    Switching: Mikrotik, Netgear, Extreme
                                    Wireless: Aruba, Ubiquiti

                                    1 Reply Last reply Reply Quote 0
                                    24 out of 24
                                    • First post
                                      24/24
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      This community forum collects and processes your personal information.
                                      consent.not_received