PFSense DHCP gives IP to wrong VLANs
-
Hi,
I have a PfSense/LinkSys/Engenius(FIT controller and AP) setup for guest wifi network.
There are 3 vlans(300/310/320) configured in PFSense, 300 for staff SSID, 310 for Guest SSID and 320 for wifi devices network. Everything works as expected, Engenius devices gets IP in the 10.3.220.0/24 series, staff devices get 10.3.200.0/24 and Guest devices get 10.3.210.0/24 series. However, surprisingly in the PFsense dhcp leases, i can find another IP from guest vlan series given to the access point.
ie; AP has two IPs, 10.3.200.15 and 10.3.220.11 for the same MAC address, and both IPs ping.Linksys switch port 24 is connected to pfsense and all 3 vlans are tagged. On port 23, FitCon controller is connected as untagged. On port 22, AP is connected as untagged and tagged for LAN and Guest VLANs(pictures attached.)
Please help me to identify where the configuration is wrong!
-
@thomaspsimon I don’t think you did anything wrong. There are AP’s our there that claims DHCP leases in tagged VLANs to enable their IP stack in this VLAN (usually because a IP stack is required in the vendors quickfix code to enable Fx. Inspection, IGMP or mDNS control)
-
@keyser thank you for the quick response.
Even in static IP(10.4.320.11) mode also it claims back the Guest VLAN series IP.
-
@keyser said in PFSense DHCP gives IP to wrong VLANs:
@thomaspsimon I don’t think you did anything wrong. There are AP’s our there that claims DHCP leases in tagged VLANs to enable their IP stack in this VLAN (usually because a IP stack is required in the vendors quickfix code to enable Fx. Inspection, IGMP or mDNS control)
Hi @keyser Surprised, why it is taking IP only from Guest VLAN. If it is IP stacking as you mentioned, it should have claimed one IP from staff VLAN as well. Please correct if I am wrong.
-
@thomaspsimon Yeah I would have expected that to if you have configured the same settings for all the VLANs.
But I’m guessing you are using some kind of Guest WLAN feature on the AP as opposed to just a straight VLAN/SSID setup, and it’s that Guest feature that needs a IP stack (Probably because it can also offer a captive portal if you configure it). -
@keyser yes. Captive portal with voucher service is enabled on guest SSID.