Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to use SFP as a trunk from pfSense router to UniFi switch where I can tag VLANs from the switch ports.

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    5 Posts 2 Posters 825 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • caramel_juniC
      caramel_juni
      last edited by caramel_juni

      Hi all!

      So, for some context, I'm experimenting with the following setup:

      ISP Modem ---[ETHERNET]--> pfSense 7100U ---[SFP+ Trunk]---> UniFi USW-Pro 48-port Managed Switch

      I then plan to assign & manage VLAN tagging from the UniFi switch based on which ports devices are plugged into: e.g. first 8 ports are for Management Network Devices, next 8 are for Guest Network Devices, and so on.

      Now, I believe I've managed to get the SFP connection working as a trunk from the pfSense to the UniFi switch, with devices connected to the switch being assigned IPs & able to connect to the internet, but that's without adding specific VLANs per port range, so all of the connected devices are just on the single SFP0 network at present.

      However, I have encountered two major limitations/roadblocks.

      1. As soon as I set a UniFi switch port to assign specific VLAN tags to any passing traffic, the device connected to the port is stuck without an IP and internet access. I have restarted & reconfigured the DNS resolver & DHCP servers, and added firewall rules to ensure the SFP0 network can communicate with the desired VLAN, all to no avail. Does anyone have any experience using SFP as a trunk to a switch & tagging VLANs from the switch ports???

      2. (less of an issue, but may indicate the SFP isn't passing/using VLANs properly) The SFP port I'm using (Network port ix0, mapped to Interface SFP0) does not work when I try and assign a native VLAN to ix0 (see the not working SETUP 2, "VLAN 110 on ix0 - opt4 (SFP Switch Management)", compared to the working SETUP 1).

      Just a bit of a puzzling situation, and was wondering if anyone could lend a hand. To confirm, I have got this setup working when using an ETHERNET cable as a trunk, but not the SFP cable - see the guide I wrote here.

      Below are snapshots from my config if needed. Thank you!! <33

      SETUP 1: (Network port ix0, mapped to Interface SFP0) - working:

      ef886994-e690-495a-919f-8a4ca1c9d9ee-image.png

      SETUP 2: (VLAN & Network port: VLAN 110 on ix0, mapped to Interface: SFP0) - NOT WORKING:

      d55466c5-ff60-4088-b9bb-8ac31006e8ce-image.png


      Interface settings, DHCP server, DNS resolver config & firewall rules below (all UNCHANGED throughout the above scenarios):


      SFP Interface Settings

      c7b2399b-f548-45e6-9835-1bfd700b31ac-image.png

      SFP DHCP Server Settings (everything further down on the page is default)

      3d03dfb6-aa71-4dd9-bb03-447c0443cdb0-image.png

      DNS Resolver Settings

      82bd8239-a0ea-4839-9f3f-ece2c253e64f-image.png

      Firewall - Switch SFP Network

      25fde2a6-8e36-4288-bac1-ba7d6dcf6eef-image.png

      Firewall - Destination VLAN

      a3dbff83-a7e1-4a81-a243-cbf099eaf02a-image.png

      UniFi Port Tagging Settings (when set to the below settings, connected device is unable to connect/be assigned IP on the desired VLAN (ADLOFFICE, VLAN 70)

      41e1d7ea-8d76-4f70-bd31-3d08971f7fc1-image.png

      f38f95de-9ac3-4ab8-9717-46da18ee2bce-image.png

      f990866c-32bb-49e1-bab8-97349eba6e89-image.png

      1 Reply Last reply Reply Quote 0
      • L
        laser22
        last edited by

        in my setup I have my pfsense system connected via a SFP+ with 5 vlans---on my cloudkey plus 2 my xg-16 has port 1 set as the trunk port whereby the port configuration is set to ALL- my nanoHD is attached via rj45 to xg-16 port 15 port config is the parent LAN and associated vlans.
        has worked great- have you checked out your port configuration profiles? are myou using a global config that might not be selected or selected and it shouldnt be?

        caramel_juniC 1 Reply Last reply Reply Quote 1
        • caramel_juniC
          caramel_juni @laser22
          last edited by

          @laser22 Hiya, thanks so much for the response. Would you be able to send/DM me your pfsense config, and screenshots from unifi? Would be a massive help <33

          L 2 Replies Last reply Reply Quote 0
          • L
            laser22 @caramel_juni
            last edited by

            @caramel_juni
            just got back on forum was sic k---did you get this working?

            1 Reply Last reply Reply Quote 0
            • L
              laser22 @caramel_juni
              last edited by

              @caramel_juni
              also noticed that your using a LAGG network make sure your unifi supports it (sure it does) and I think aggregation is the unifi setting-

              I also assign all my unifi devices a static IP address- otherwise I have seen my cloudkey list my trunk port gateway address as on of the vlans rather than the parent interface address-

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.