Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to setup an Access Point (AP) in PfSense?

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 5 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • r0utevv3R
      r0utevv3
      last edited by

      I'm trying to add a TP-Link TL-WA801ND Access Point (AP) to my PfSense Router, but I'm unable to connect to internet

      These are my PfSense configurations:
      Interfaces:
      alt text
      DHCP Server:
      alt text
      Rules:
      alt text

      and these are my Access Point TP-Link configurations:
      LAN:
      alt text
      DHCP Settings:
      alt text

      But still I don't have Internet access, Could you help me? Do I have a configuration wrong?
      Thanks

      It's not a bug, it's an undocumented feature

      JKnottJ 1 Reply Last reply Reply Quote 0
      • N
        nimrod
        last edited by

        Post a screenshot of your NAT rules. They are located in Firewall / NAT / Outbound

        r0utevv3R 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @r0utevv3
          last edited by

          @r0utevv3

          Is that on the same interface as your main LAN? If not, you'll have to provide a route to the Internet.

          Also, I have one of those APs and stopped using it because it doesn't handle VLANs & 2nd SSID properly. It allowed leaking of multicasts from the main LAN to the VLAN.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • r0utevv3R
            r0utevv3 @nimrod
            last edited by

            @nimrod
            NAT Rules:
            alt text

            @JKnott
            I have two interfaces, LAN and OPT1, how do I provide a route for the Internet?

            It's not a bug, it's an undocumented feature

            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @r0utevv3
              last edited by

              @r0utevv3 said in How to setup an Access Point (AP) in PfSense?:

              @nimrod
              NAT Rules:
              alt text

              @JKnott
              I have two interfaces, LAN and OPT1, how do I provide a route for the Internet?

              Here are the rules for my guest WiFi. The last one is the one you're interested in. I guess I should have used a different word, as these are firewall rules, not specific IP routes.

              97eff684-2dd8-4d8e-b79c-5336ace5c2be-image.png

              These rules only allow access to the Internet and pinging the interface.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              r0utevv3R 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee
                last edited by

                Did you bridge the LAN and OPT interfaces?

                Make sure to upvote

                r0utevv3R 1 Reply Last reply Reply Quote 0
                • r0utevv3R
                  r0utevv3 @JonathanLee
                  last edited by

                  @JonathanLee I didn't bridge it, why do I have to bridge them and how can I do it? I thought LAN and OPT1 were independent since they're connected in different physical ports

                  It's not a bug, it's an undocumented feature

                  JonathanLeeJ 1 Reply Last reply Reply Quote 0
                  • JonathanLeeJ
                    JonathanLee @r0utevv3
                    last edited by JonathanLee

                    @r0utevv3

                    I have not attempted a bridge inside PfSense software just yet, I set up my wifi by just changing my LAN interface to use the wireless mini pcie adapter.

                    Here is something interesting as I am still researching the internal bridges currently:

                    https://www.servethehome.com/how-to-setup-wi-fi-with-pfsense/

                    Theory is that if you bridge LAN and wireless adapters it will work with the current ruleset in LAN. It would act as an extension of LAN interface.

                    Make sure to upvote

                    1 Reply Last reply Reply Quote 0
                    • r0utevv3R
                      r0utevv3 @JKnott
                      last edited by r0utevv3

                      @JKnott so, why do I need a VLAN? What's a VLAN? I'm using a protectli vault with 4 ports, the first port is connected to WAN and thus to my modem, the second one to LAN and thus to a desktop computer, and the third is connected to OPT and thus to my Access Point, I'm not using the fourth one, why do I have to create something virtual when I have physical ports?

                      It's not a bug, it's an undocumented feature

                      JKnottJ 1 Reply Last reply Reply Quote 0
                      • the otherT
                        the other
                        last edited by the other

                        Hey,
                        Might be wrong, but...
                        In your rules Screenshot (first posting) you have that rule for Interface opt1 but source LAN...why?

                        the other

                        pure amateur home user, no business or professional background
                        please excuse poor english skills and typpoz :)

                        1 Reply Last reply Reply Quote 0
                        • JKnottJ
                          JKnott @r0utevv3
                          last edited by

                          @r0utevv3

                          A VLAN is a means of separating logical networks over a physical network. As I mentioned, I have a guest WiFi, which is allowed to only access the Internet. The way I did this was to configure a 2nd SSID on my access point, which connects to the VLAN. My main SSID connects to the native LAN. This means both the main and guest WiFi travel over the same cable, but are logically separate. I do not separate my main WiFi from my main LAN. Both wired and wireless devices are on the same subnet.

                          PfSense running on Qotom mini PC
                          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                          UniFi AC-Lite access point

                          I haven't lost my mind. It's around here...somewhere...

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.