• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Unable to use SFP as a trunk from pfSense router to UniFi switch where I can tag VLANs from the switch ports.

Scheduled Pinned Locked Moved L2/Switching/VLANs
5 Posts 2 Posters 813 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    caramel_juni
    last edited by caramel_juni Nov 21, 2023, 3:50 AM Nov 21, 2023, 3:40 AM

    Hi all!

    So, for some context, I'm experimenting with the following setup:

    ISP Modem ---[ETHERNET]--> pfSense 7100U ---[SFP+ Trunk]---> UniFi USW-Pro 48-port Managed Switch

    I then plan to assign & manage VLAN tagging from the UniFi switch based on which ports devices are plugged into: e.g. first 8 ports are for Management Network Devices, next 8 are for Guest Network Devices, and so on.

    Now, I believe I've managed to get the SFP connection working as a trunk from the pfSense to the UniFi switch, with devices connected to the switch being assigned IPs & able to connect to the internet, but that's without adding specific VLANs per port range, so all of the connected devices are just on the single SFP0 network at present.

    However, I have encountered two major limitations/roadblocks.

    1. As soon as I set a UniFi switch port to assign specific VLAN tags to any passing traffic, the device connected to the port is stuck without an IP and internet access. I have restarted & reconfigured the DNS resolver & DHCP servers, and added firewall rules to ensure the SFP0 network can communicate with the desired VLAN, all to no avail. Does anyone have any experience using SFP as a trunk to a switch & tagging VLANs from the switch ports???

    2. (less of an issue, but may indicate the SFP isn't passing/using VLANs properly) The SFP port I'm using (Network port ix0, mapped to Interface SFP0) does not work when I try and assign a native VLAN to ix0 (see the not working SETUP 2, "VLAN 110 on ix0 - opt4 (SFP Switch Management)", compared to the working SETUP 1).

    Just a bit of a puzzling situation, and was wondering if anyone could lend a hand. To confirm, I have got this setup working when using an ETHERNET cable as a trunk, but not the SFP cable - see the guide I wrote here.

    Below are snapshots from my config if needed. Thank you!! <33

    SETUP 1: (Network port ix0, mapped to Interface SFP0) - working:

    ef886994-e690-495a-919f-8a4ca1c9d9ee-image.png

    SETUP 2: (VLAN & Network port: VLAN 110 on ix0, mapped to Interface: SFP0) - NOT WORKING:

    d55466c5-ff60-4088-b9bb-8ac31006e8ce-image.png


    Interface settings, DHCP server, DNS resolver config & firewall rules below (all UNCHANGED throughout the above scenarios):


    SFP Interface Settings

    c7b2399b-f548-45e6-9835-1bfd700b31ac-image.png

    SFP DHCP Server Settings (everything further down on the page is default)

    3d03dfb6-aa71-4dd9-bb03-447c0443cdb0-image.png

    DNS Resolver Settings

    82bd8239-a0ea-4839-9f3f-ece2c253e64f-image.png

    Firewall - Switch SFP Network

    25fde2a6-8e36-4288-bac1-ba7d6dcf6eef-image.png

    Firewall - Destination VLAN

    a3dbff83-a7e1-4a81-a243-cbf099eaf02a-image.png

    UniFi Port Tagging Settings (when set to the below settings, connected device is unable to connect/be assigned IP on the desired VLAN (ADLOFFICE, VLAN 70)

    41e1d7ea-8d76-4f70-bd31-3d08971f7fc1-image.png

    f38f95de-9ac3-4ab8-9717-46da18ee2bce-image.png

    f990866c-32bb-49e1-bab8-97349eba6e89-image.png

    1 Reply Last reply Reply Quote 0
    • L
      laser22
      last edited by Dec 8, 2023, 5:34 AM

      in my setup I have my pfsense system connected via a SFP+ with 5 vlans---on my cloudkey plus 2 my xg-16 has port 1 set as the trunk port whereby the port configuration is set to ALL- my nanoHD is attached via rj45 to xg-16 port 15 port config is the parent LAN and associated vlans.
      has worked great- have you checked out your port configuration profiles? are myou using a global config that might not be selected or selected and it shouldnt be?

      C 1 Reply Last reply Dec 14, 2023, 1:25 AM Reply Quote 1
      • C
        caramel_juni @laser22
        last edited by Dec 14, 2023, 1:25 AM

        @laser22 Hiya, thanks so much for the response. Would you be able to send/DM me your pfsense config, and screenshots from unifi? Would be a massive help <33

        L 2 Replies Last reply Dec 28, 2023, 4:27 PM Reply Quote 0
        • L
          laser22 @caramel_juni
          last edited by Dec 28, 2023, 4:27 PM

          @caramel_juni
          just got back on forum was sic k---did you get this working?

          1 Reply Last reply Reply Quote 0
          • L
            laser22 @caramel_juni
            last edited by Dec 28, 2023, 4:35 PM

            @caramel_juni
            also noticed that your using a LAGG network make sure your unifi supports it (sure it does) and I think aggregation is the unifi setting-

            I also assign all my unifi devices a static IP address- otherwise I have seen my cloudkey list my trunk port gateway address as on of the vlans rather than the parent interface address-

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              [[user:consent.lead]]
              [[user:consent.not_received]]