Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Newbie Restrict device to specific DHCP

    Scheduled Pinned Locked Moved DHCP and DNS
    9 Posts 3 Posters 555 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Scarecrow4798
      last edited by

      Newbie question

      I've just started using pfSense and I'm trying so split up my network.

      I have pfSense installed on an old desktop machine with a single network card so I'm using vlans to create a couple of interfaces.

      VLANs
      1 Main Lan network
      99 Incoming internet connection
      100 IOT

      The problem.
      Everything in the main VLAN gets an ip from the main DHCP server and can access the internet fine but I'm wanting to separate my IOT devices from the main network and not to be able to access the internet. I've set up a DHCP server on the IOT vlan but I'm unable to get them to get ip addresses from the IOT DHCP server. All my IOT devices are wireless and connect to an old Linksys router that I'm using as an AP.

      Everything that connects through the AP gets an address from the main DHCP server but I'm wanting my IOT devices to use a different DHCP

      Is there any way to do this or do I need another AP that sits on the IOT vlan?

      newtork layout.png

      V J 2 Replies Last reply Reply Quote 0
      • V Offline
        viragomann @Scarecrow4798
        last edited by

        @Scarecrow4798 said in Newbie Restrict device to specific DHCP:

        Everything that connects through the AP gets an address from the main DHCP server but I'm wanting my IOT devices to use a different DHCP

        So did you configure the VLANs on the switch properly?
        This let me suspect, that port, which the AP is connected to, is not cleanly segmented from the LAN.

        Also you should not use VLAN ID 1. Some switches give this out on all ports. Maybe this is also applied to yours.

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          Scarecrow4798 @viragomann
          last edited by

          @viragomann
          Yes everything on the switch is configured correctly. If i plug a lan cable into the normal vlan port my pc shows up in the correct dhcp server and gets its address, if i then plug it into my IOT vlan it again gets a new ip on the IOT DHCP range.

          My AP is just connected to a basic port with only vlan 1 and nothing tagged as my AP does not have any vlan capability.

          V 1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann @Scarecrow4798
            last edited by

            @Scarecrow4798
            Is the DHCP server on the AP still enabled by any chance? And are the connected devices getting their IPs from it?

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              Scarecrow4798 @viragomann
              last edited by

              @viragomann
              No the only dhcp servers active are on pfsense.

              1 Reply Last reply Reply Quote 0
              • J Offline
                Jarhead @Scarecrow4798
                last edited by Jarhead

                @Scarecrow4798 said in Newbie Restrict device to specific DHCP:

                Is there any way to do this or do I need another AP that sits on the IOT vlan?

                No, you can't do that. The AP will need to support vlans since you're trying to push both vlans through it.
                So you will need another AP, or did you try to install OpenWRT on it? That would support vlans.

                S 1 Reply Last reply Reply Quote 0
                • S Offline
                  Scarecrow4798 @Jarhead
                  last edited by

                  @Jarhead

                  Might have to look into dd-wrt as apparently it supports vlan stuff and I know I've an old router that I can flash with different firmware ๐Ÿคž

                  V 1 Reply Last reply Reply Quote 0
                  • V Offline
                    viragomann @Scarecrow4798
                    last edited by

                    @Scarecrow4798
                    I was assuming, that all your AP-connected devices should be within IoT VLAN and there is no other VLAN available on the switch port. In this case, the AP would not need to support VLAN, you only have configure the switch properly.
                    But if you want to have multiple wifi VLANs, then of course you need a VLAN-capable AP.

                    S 1 Reply Last reply Reply Quote 0
                    • S Offline
                      Scarecrow4798 @viragomann
                      last edited by

                      @viragomann
                      Flashed my spare d-link dir-615 with openwrt and after watching a couple of videos I've managed to get it working. It's now running 4 vlans each with there own said and thus means each AP has its own rules making it much easier to split up my network.

                      Thanks for the help.everyone

                      ๐Ÿ˜€

                      1 Reply Last reply Reply Quote 1
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.