Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense fresh install / No internet on VLAN's

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    23 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marcel1988
      last edited by marcel1988

      Hardware:

      Proxmox 8.2.2
      VM - PfSense 2.7.2-Release
      1x TP-Link TL-SG1016DE
      1x TP-Link TL-SG108E-Gigabit (8-poorts)
      1x TP-Link TL-SG105E-Gigabit (5-poorts)

      Settings VM in Poxmox:
      alt text

      I have made some VLANS inside PfSense:
      alt text

      These are the settings of the VLANS (All are the same exept for the ip address)
      alt text
      alt text

      Then i have added them to the interfaces:
      alt text

      I have edited them so they have a DHCP server:
      (All of the settings are the same on each VLAN)
      alt text

      This is the IP Range of alle the VLANS:
      VLAN 10 = Main network. 192.168.10.1
      VLAN 20 = Kids network. 192.168.20.1
      VLAN 30 = Security network. 192.168.30.1
      VLAN 40 = Guest network. 192.168.40.1

      There is no intereconnection between the VLANS, So that is working like i want to have it. But there is also no internet access on the VLANS either.
      I can ping 8.8.8.8 or 1.1.1.1 but when i try to ping google.nl there is no answer. These are the firewall setings/Rules (They are all the same on each VLAN)
      alt text

      I dont know why, but at this point only the devices that are outside the VLAN (So on the native VLAN1) have internet without any problems.

      The settings in the TP-LINK swichtes are right, since the devices inside the vlan are getting the right Ip Addresses.

      The only thing i have changed in the basic setup is that i have installed AdGuard Home by this tutorial: Installing AdGuard Home on PFSense

      Where is my mistake ๐Ÿ˜ง

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @marcel1988
        last edited by Bob.Dig

        @marcel1988 said in Pfsense fresh install / No internet on VLAN's:

        Where is my mistake ๐Ÿ˜ง

        You block private Addresses on your LAN?
        What do your Clients use for DNS?

        If it doesn't work, it is probably your proxmox. ๐Ÿ˜‰

        M 1 Reply Last reply Reply Quote 0
        • M
          marcel1988 @Bob.Dig
          last edited by marcel1988

          @Bob-Dig said in Pfsense fresh install / No internet on VLAN's:

          You block private Addresses on your LAN?
          What do your Clients use for DNS?

          If it doesn't work, it is probably your proxmox. ๐Ÿ˜‰

          Can you elaborate on that?

          if you want screenshots just let me know of which page and i will provide them.

          For the DNS on the clients, they get a Gateway and DNS address of the VLAN. 192.168.10.1 192.168.20.1 and so on.

          My DNS is working on the PfSense itself (Like i linked the tutorial for it)
          So that is working on 192.168.1.1

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @marcel1988
            last edited by

            @marcel1988 said in Pfsense fresh install / No internet on VLAN's:

            Can you elaborate on that?

            @Bob-Dig said : your first firewall rule on MAIN blocks RFC1918.

            The 'definition' of RFC1918 is :

            Blocks traffic from IP addresses that are reserved for private networks per RFC 1918 (10/8, 172.16/12, 192.168/16) and unique local addresses per RFC 4193 (fc00::/7) as well as loopback addresses (127/8). This option should generally be turned on, unless this network interface resides in such a private address space, too.

            and your MAIN network falls right into RFC1918.
            Your first firewall rule blocks all your 'LAN' (MAIN) traffic.
            No traffic will match/ reach the second, pass all rule : the counters stay at zero.
            The first rule does have matches : its blocking all your traffic coming into that interface.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            M 1 Reply Last reply Reply Quote 0
            • M
              marcel1988 @Gertjan
              last edited by

              @Gertjan

              That rule is made since i did a checkbox on the "Block private networks and loopback addresses"

              So when i disabled that checkbox, it should work?

              M 1 Reply Last reply Reply Quote 0
              • M
                marcel1988 @marcel1988
                last edited by

                @marcel1988 said in Pfsense fresh install / No internet on VLAN's:

                @Gertjan

                That rule is made since i did a checkbox on the "Block private networks and loopback addresses"

                So when i disabled that checkbox, it should work?

                I tried that, but no change. The firewall rule is gone but there is stil no internet on VLAN10, 20, 30, or 40.

                A 1 Reply Last reply Reply Quote 0
                • A
                  Antibiotic @marcel1988
                  last edited by

                  @marcel1988 I think you have to create firewall rules to allow traffic on your VLAN's))))

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    marcel1988 @Antibiotic
                    last edited by marcel1988

                    @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

                    @marcel1988 I think you have to create firewall rules to allow traffic on your VLAN's))))

                    There is on the main. This is copied from the LAN firewall rule. (Same on all the VLAN firewall rules)
                    alt text

                    A 2 Replies Last reply Reply Quote 0
                    • A
                      Antibiotic @marcel1988
                      last edited by

                      @marcel1988 Oh , did you setup Adguard as well. Could be wrong set up with DNS resolution. I think better to uninstall Adguard, than try with default unbound resolver.

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @marcel1988
                        last edited by Antibiotic

                        @marcel1988 If you want to block something from kids you can use pfblockerNG more power ad blocker, than Adguard

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          marcel1988 @Antibiotic
                          last edited by

                          @Antibiotic

                          first, this should be working WITH AdGuard home. SO no need to uninstall it.

                          second: pfblockerNG does not have specific blocking for app/websites with just one click.

                          A 2 Replies Last reply Reply Quote 0
                          • A
                            Antibiotic @marcel1988
                            last edited by

                            @marcel1988 Ok , up to you. But it potential additional problem. If you aware that Adguard dns resolution working

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            1 Reply Last reply Reply Quote 0
                            • A
                              Antibiotic @marcel1988
                              last edited by

                              @marcel1988 Did you set dns forwarding in Unbound settings?

                              pfSense plus 24.11 on Topton mini PC
                              CPU: Intel N100
                              NIC: Intel i-226v 4 pcs
                              RAM : 16 GB DDR5
                              Disk: 128 GB NVMe
                              Brgds, Archi

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                marcel1988 @Antibiotic
                                last edited by

                                @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

                                @marcel1988 Did you set dns forwarding in Unbound settings?

                                This is what you mean? This is untouched and empty
                                alt text

                                A 3 Replies Last reply Reply Quote 0
                                • A
                                  Antibiotic @marcel1988
                                  last edited by

                                  @marcel1988
                                  ea63278e-df70-49ae-b890-a6eae24cfb6d-image.png
                                  9f15b078-2a7d-4069-93c9-b8ff9fec1278-image.png
                                  9fc90a0e-33ef-4a87-a741-80c08ff25bea-image.png

                                  Dnssec in case of forwarding should be disable!

                                  pfSense plus 24.11 on Topton mini PC
                                  CPU: Intel N100
                                  NIC: Intel i-226v 4 pcs
                                  RAM : 16 GB DDR5
                                  Disk: 128 GB NVMe
                                  Brgds, Archi

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Antibiotic @marcel1988
                                    last edited by Antibiotic

                                    @marcel1988 Not DNS forwarder, but Unbound dns resolver forward mode. I show my settings just as example for forwarding mode

                                    pfSense plus 24.11 on Topton mini PC
                                    CPU: Intel N100
                                    NIC: Intel i-226v 4 pcs
                                    RAM : 16 GB DDR5
                                    Disk: 128 GB NVMe
                                    Brgds, Archi

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      Antibiotic @marcel1988
                                      last edited by

                                      @marcel1988
                                      b961bdf1-0cb2-40db-8ec1-7ea5343bb176-image.png

                                      pfSense plus 24.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      M 1 Reply Last reply Reply Quote 0
                                      • M
                                        marcel1988 @Antibiotic
                                        last edited by

                                        @Antibiotic

                                        That did nothing.
                                        BUT, when i change the listen port back to 53, and changed the Network interfaces from Localhost to Any everything is working and the pc's are getting internet.
                                        But, the can also communicate between eachother.

                                        A 1 Reply Last reply Reply Quote 0
                                        • A
                                          Antibiotic @marcel1988
                                          last edited by

                                          @marcel1988
                                          Idk how configured your Adguard server, looks like problem with a port listening. Localhost WAS IN MY EXAMPLE FOR MY SETTINGS, FOR AVOID PROBLEM FIRST SET TO DEFAULT IN NETWORK INTERFACE AND OUTGOING INTERFACE.

                                          pfSense plus 24.11 on Topton mini PC
                                          CPU: Intel N100
                                          NIC: Intel i-226v 4 pcs
                                          RAM : 16 GB DDR5
                                          Disk: 128 GB NVMe
                                          Brgds, Archi

                                          M 1 Reply Last reply Reply Quote 0
                                          • M
                                            marcel1988 @Antibiotic
                                            last edited by

                                            @Antibiotic said in Pfsense fresh install / No internet on VLAN's:

                                            @marcel1988
                                            Idk how configured your Adguard server, looks like problem with a port listening. Localhost WAS IN MY EXAMPLE FOR MY SETTINGS, FOR AVOID PROBLEM FIRST SET TO DEFAULT IN NETWORK INTERFACE AND OUTGOING INTERFACE.

                                            Exactly like this toturial: Tutorial Adguard Home

                                            A 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.