Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't access VLAN20 from VLAN60 - Interface bound state help

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @runevn
      last edited by

      @runevn I don't see how that state change would effect you unless you were having some sort of asymmetrical flow.

      When 60.x goes to talk to 20.x a state would be create on the 60.x interface and would allow traffic to flow back from the 20.x to pfsense. That return traffic shouldn't be coming in any other interface.

      Does what your talking to on this 20.x have multiple gateways?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      R 1 Reply Last reply Reply Quote 0
      • R
        runevn @johnpoz
        last edited by runevn

        @johnpoz said in Can't access VLAN20 from VLAN60 - Interface bound state help:

        Does what your talking to on this 20.x have multiple gateways?

        No, only one WAN gateway (WAN_DHCP (default)). If that is what you are asking about?

        Edit: On another thought, each interface has a DHCP server attached and under "Other DHCP Options" Gateway is set to 192.168.60.1 for vlan 60 and 192.168.20.1 for vlan 20. Is that wrong?

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @runevn
          last edited by

          @runevn no that would be correct.. 20 gateway should be pfsense IP in that 20 vlan, and 60s devices gateway should be pfsense IP in the 60 network.. I assume those are both .1 ?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          R 1 Reply Last reply Reply Quote 0
          • R
            runevn @johnpoz
            last edited by

            @johnpoz said in Can't access VLAN20 from VLAN60 - Interface bound state help:

            @runevn no that would be correct.. I assume those are both .1 ?

            Yes, thet are both .1

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @runevn
              last edited by johnpoz

              @runevn I haven't moved to 24.03 yet.. But the change in state behavior should not have any thing to do with typical network talking to another network using pfsense as its gateway with only 1 path to talk back and forth.

              Your not doing any policy routing are you - on the 60 and 20 interfaces do you have gateway called out in the rules, or just * where pfsense uses it normal routing table.

              In your rules for these interfaces you didn't call out wan_dhcp as the gateway?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • P
                pst @runevn
                last edited by pst

                @runevn You didn't specify what NAS equipment you are using, but I experienced exactly the same issue in my setup when I switched to 24.03. I run a Synology NAS, so it might be applicable to you, and for this setup to work you need to set "Enable Multiple Gateways" in Control Panel / Network / General / Advanced Settings. If that is not set you end up with assymetric routing just like @johnpoz said, as everything goes through your default gateway on the NAS.

                R 1 Reply Last reply Reply Quote 0
                • P
                  pst @runevn
                  last edited by

                  @runevn said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                  I did some searching on the topic and found this topic on state policy but I don't know if that even relates to my issue and if so I can't find the setting for enable multi gateways

                  Ah, I see you found my thread from earlier. Yes it might apply, and if you run Synology then the specific setting is as I specified in my previous post.

                  1 Reply Last reply Reply Quote 0
                  • R
                    runevn @pst
                    last edited by runevn

                    @pst said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                    @runevn I run a Synology NAS, so it might be applicable to you, and for this setup to work you need to set "Enable Multiple Gateways" in Control Panel / Network / General / Advanced Settings.

                    I don't know why but can't find the setting where I can enable multiple gateways. Could you be more specific where I can find it? Am I on the wrong setting section?

                    Screenshot 2024-04-27 at 10.57.02.png

                    Screenshot 2024-04-27 at 10.59.06.png

                    BTW - I'm using Trueness Scale Dragonfish-24.04.0

                    P johnpozJ 4 Replies Last reply Reply Quote 0
                    • P
                      pst @runevn
                      last edited by

                      @runevn said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                      Could you be more specific where I can find it? Am I on the wrong setting section?

                      The change you need to do is not in pfSense, it is on the NAS.

                      1 Reply Last reply Reply Quote 0
                      • P
                        pst @runevn
                        last edited by

                        @runevn said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                        I'm using Trueness Scale Dragonfish-24.04.0

                        I'm not familiar with that NAS, but I'll take a quick look if there a similar gateway option there.

                        1 Reply Last reply Reply Quote 0
                        • P
                          pst @runevn
                          last edited by

                          @runevn I can't see any setting for multiple gateways in the TrueNAS Scale documentation. From what I gather it should work if everything is set up "normally", confirm:

                          • your NAS interfaces are configured using DHCP
                          • pfSense provides the correct gateway address (check DHCP server setup)
                          • you don't have default gateway specified in NAS Global Configuration / Default Gateway Settings, as that overrides the one given in DHCP (according to https://www.truenas.com/docs/scale/24.04/scaleuireference/network/globalconfigurationscreens/)
                          R 1 Reply Last reply Reply Quote 1
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @runevn
                            last edited by

                            @runevn does your nas have more than 1 interface?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              runevn @johnpoz
                              last edited by

                              @johnpoz Yes, three different:

                              • One management interface (GUI)
                              • NFS share
                              • SMB share
                              1 Reply Last reply Reply Quote 0
                              • R
                                runevn @pst
                                last edited by

                                @pst said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                                @runevn I can't see any setting for multiple gateways in the TrueNAS Scale documentation. From what I gather it should work if everything is set up "normally", confirm:

                                • your NAS interfaces are configured using DHCP
                                • pfSense provides the correct gateway address (check DHCP server setup)
                                • you don't have default gateway specified in NAS Global Configuration / Default Gateway Settings, as that overrides the one given in DHCP (according to https://www.truenas.com/docs/scale/24.04/scaleuireference/network/globalconfigurationscreens/)

                                Thanks a million! You were right.

                                I had defined a default gateway and had a static IP address for the vlan 20 interface. I removed the default gateway and then set the storage vlan20 to get the IP from the DHCP server (I couldn't find a way to manually add a gateway per interface when using static IP.

                                But now it works.

                                Thanks for all the help @johnpoz and @pst.

                                P johnpozJ 2 Replies Last reply Reply Quote 0
                                • P
                                  pst @runevn
                                  last edited by

                                  @runevn glad we could help :)

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @runevn
                                    last edited by johnpoz

                                    @runevn said in Can't access VLAN20 from VLAN60 - Interface bound state help:

                                    You were right.

                                    This brought to mind a line from Grateful Dead song ;)

                                    "Well, I ain't always right, but I've never been wrong"

                                    You get a cookie if you know what song, without having to look it up ;)

                                    Dead on the Brain - My Dave's Pick 50 came in the mail today.. Always a good day when they come..

                                    https://store.dead.net/en/grateful-dead/special-collections/daves-picks/daves-picks-vol.-50-palladium-new-york-city-ny-5377/081227817466.html

                                    I always have subscription, so 4 times a year is like xmas ;)

                                    Glad you got it sorted.

                                    edit: soon to be 52, as soon as get it ripped and on plex ;)

                                    soon.jpg

                                    edit2: make that 53, this shipment had the bonus disc.. Sweet! And hint that above line is from a song on the bonus disc ;)

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.