Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense and Unifi basic config with vlans

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    18 Posts 2 Posters 776 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Polar_Bear88
      last edited by

      Hi all, Im hoping you can help me with the basic set up of my pfSense and Unifi network with vlans as I've gt myself a bit stuck. Sorry this is going to be a long one and Ive taken a lot of screenshots (if I can upload them) to give as much info as possible.

      I'm wanting to eventually set up a netwrk consisting of a pfSense router, 3 unifi switches and 3 unifi WAPs but to keep things simple with initial configuration Im starting with the router and one switch. I was originally going to have 3 vlans handling all my devices (Home, Guest and IOT) but after advice Ive added in a 4th vlan for management which will have all my unifi devices on.

      I believe I have pfSense configured correctly with basic firewall rules on Home, Guest and IOT that should prevent them talking to each other but allow access to the internet. I also believe that Ive got the vlans set correctly on unifi but I must have smething wrong as everytime I try to set my client with a static IP from the Home (only vlan tested so far as theyre all set up the same) I loose connection; as soon as I set it back to DHCP and it obtains an IP from the LAN pool it starts working again.

      Any help would be very much appreciated.

      1. Interface Assignments.jpg 2. Vlans.jpg 3. Home Vlan.jpg 4. Guest Vlan.jpg 5. IOT Vlan.jpg 6. Management Vlan.jpg 7. WAN Firewall Rules.jpg 8. LAN Firewall Rules.jpg 9. Home Firewall Rules.jpg 10. Guest Firewall Rules.jpg 11. IOT Firewall Rules.jpg 12. Management Firewall Rules.jpg 13. LAN DHCP Server Part 1.jpg 14. LAN DHCP Server Part 2.jpg 15. LAN DHCP Server Part 3.jpg 16. LAN DHCP Server Part 4.jpg 17. Home DHCP Server Part 1.jpg 18 Home DHCP Server Part 2.jpg 19. Home DHCP Server Part 3.jpg 20. Home DHCP Server Part 4.jpg 21. Guest DHCP Server Part 1.jpg 22. Guest DHCP Server Part 2.jpg 23. Guest DHCP Server Part 3.jpg 24. Guest DHCP Server Part 4.jpg 25. IOT DHCP Server Part 1.jpg 26. IOT DHCP Server Part 2.jpg 27. IOT DHCP Server Part 3.jpg 28. Management DHCP Server Part 1.jpg 29. Management DHCP Server Part 2.jpg 30. Management DHCP Server Part 3.jpg 31. Management DHCP Server Part 4.jpg 32. Unifi Devices.jpg 33. Unifi Networks.jpg 34. Unifi Default Network.jpg 35. Unifi Home Network.jpg 36. Unifi Guest Network.jpg 37. Unifi IOT Network.jpg 38. Unifi Management Network.jpg 39. Unifi Port Profiles.jpg

      Austin 0A 1 Reply Last reply Reply Quote 0
      • P
        Polar_Bear88
        last edited by

        1. Interface Assignments.jpg

        1 Reply Last reply Reply Quote 0
        • P
          Polar_Bear88
          last edited by

          2. Vlans.jpg 3. Home Vlan.jpg 4. Guest Vlan.jpg 5. IOT Vlan.jpg 6. Management Vlan.jpg

          1 Reply Last reply Reply Quote 0
          • P
            Polar_Bear88
            last edited by

            7. WAN Firewall Rules.jpg 8. LAN Firewall Rules.jpg 9. Home Firewall Rules.jpg 10. Guest Firewall Rules.jpg 11. IOT Firewall Rules.jpg 12. Management Firewall Rules.jpg

            1 Reply Last reply Reply Quote 0
            • P
              Polar_Bear88
              last edited by

              13. LAN DHCP Server Part 1.jpg 14. LAN DHCP Server Part 2.jpg 15. LAN DHCP Server Part 3.jpg 16. LAN DHCP Server Part 4.jpg 17. Home DHCP Server Part 1.jpg 18 Home DHCP Server Part 2.jpg 19. Home DHCP Server Part 3.jpg 20. Home DHCP Server Part 4.jpg

              1 Reply Last reply Reply Quote 0
              • P
                Polar_Bear88
                last edited by

                21. Guest DHCP Server Part 1.jpg 22. Guest DHCP Server Part 2.jpg 23. Guest DHCP Server Part 3.jpg 24. Guest DHCP Server Part 4.jpg 25. IOT DHCP Server Part 1.jpg 26. IOT DHCP Server Part 2.jpg 27. IOT DHCP Server Part 3.jpg

                1 Reply Last reply Reply Quote 0
                • P
                  Polar_Bear88
                  last edited by

                  28. Management DHCP Server Part 1.jpg 29. Management DHCP Server Part 2.jpg 30. Management DHCP Server Part 3.jpg 31. Management DHCP Server Part 4.jpg

                  1 Reply Last reply Reply Quote 0
                  • P
                    Polar_Bear88
                    last edited by

                    32. Unifi Devices.jpg 33. Unifi Networks.jpg 34. Unifi Default Network.jpg 35. Unifi Home Network.jpg 36. Unifi Guest Network.jpg 37. Unifi IOT Network.jpg

                    1 Reply Last reply Reply Quote 0
                    • P
                      Polar_Bear88
                      last edited by

                      38. Unifi Management Network.jpg 39. Unifi Port Profiles.jpg

                      1 Reply Last reply Reply Quote 0
                      • P
                        Polar_Bear88
                        last edited by

                        Thats all the screenshots which I'm hoping is every screen you should need.

                        1 Reply Last reply Reply Quote 0
                        • Austin 0A
                          Austin 0 @Polar_Bear88
                          last edited by

                          @Polar_Bear88 2 things.

                          What are you trying to set the IP settings to when you are setting it statically?
                          Can you provide a picture of the port settings on unifi, both the client device and the router.

                          I am using Unifi and Pfsense at my church and have not had issues getting the VLANs setup.

                          P 1 Reply Last reply Reply Quote 0
                          • P
                            Polar_Bear88 @Austin 0
                            last edited by

                            @Austin-0

                            For an IP I was using:
                            IP 10.100.1.4
                            Subnet 255.255.255.0
                            Gateway 10.100.1.1

                            I believe all ths screenshots should be there now. The very last one is the port settings for the unifi switch showing every port has all

                            Austin 0A 1 Reply Last reply Reply Quote 0
                            • Austin 0A
                              Austin 0 @Polar_Bear88
                              last edited by

                              @Polar_Bear88 I see that now thank you. So you are passing all VLANs to the client PC? If I am not mistaken since Windows is not VLAN aware it will only see the native VLAN (VLAN 1 by default). In this case I believe that would be your LAN network, and I believe that the IP you are setting is outside of that subnet. I am still a bit new to this networking stuff, so if I am incorrect anyone should feel free to correct me.

                              P 1 Reply Last reply Reply Quote 0
                              • P
                                Polar_Bear88 @Austin 0
                                last edited by

                                @Austin-0

                                I thought that with the unifi switch going between the pfSense router (configured with all the networks) and the client, it should be stripping off the vlan tag and allowing the client to connect

                                Austin 0A 1 Reply Last reply Reply Quote 0
                                • Austin 0A
                                  Austin 0 @Polar_Bear88
                                  last edited by

                                  @Polar_Bear88 You would need to select the "HOME" profile for that port on the switch in order to put the client device on the "HOME" vlan.

                                  P 1 Reply Last reply Reply Quote 0
                                  • P
                                    Polar_Bear88 @Austin 0
                                    last edited by

                                    @Austin-0

                                    So I can’t have multiple networks being fed through a single port on the switch and then my client selects the vlan it wants to connect to? I need to individually select the network that each port is for (multiple when going to anther device such as a switch or WAP) ?

                                    Austin 0A 1 Reply Last reply Reply Quote 0
                                    • Austin 0A
                                      Austin 0 @Polar_Bear88
                                      last edited by

                                      @Polar_Bear88 That is my understanding. As devices that are not VLAN aware only see the native VLAN when multiple VLANs are passed to it.

                                      P 1 Reply Last reply Reply Quote 1
                                      • P
                                        Polar_Bear88 @Austin 0
                                        last edited by

                                        @Austin-0

                                        Ah ok. My first time playing with vlans so I thought that as long as a vlan capable switch was in the middle I could still feed multiple vlans down one cable.

                                        I’m currently setting up another client with windows. Once done I’ll change a port to each individual vlan only, assign it an IP from the respective pool and test then feed back. Would be great if this is working and it was just my understanding of it being lacking as I can then start asking my next questions in the appropriate threads.

                                        1 Reply Last reply Reply Quote 1
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.