• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

VLAN accessed wirelessly can not access internet

L2/Switching/VLANs
5
47
2.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    hasekd
    last edited by Jul 10, 2024, 6:09 AM

    Hey. I am trying to make my VLAN access wirelessly but I can not access the internet. I can ping google, my pfsense router. For exmaple when I connect to the wifi on pc and plug also ethernet cable then the wifi is okay (based on the wifi icon on pc otherwise I have a question mark on it on linux). When I connect the VLAN through ethernet cable on port 5 on my managed switch it works fine. I have the WAP connected on port 3 and on the WAP I have created two SSIDs. One with default VLAN id which works fine and the other with VLAN id 36 which does not work. On port 1 I have the pfsense

    Can someone help me with that please?

    Here are screenshots of my managed switch setup
    login-to-view login-to-view

    G H 2 Replies Last reply Jul 10, 2024, 10:04 AM Reply Quote 0
    • G
      Gblenn @hasekd
      last edited by Gblenn Jul 10, 2024, 10:04 AM Jul 10, 2024, 10:04 AM

      @hasekd Your switch config looks fine based on your description. And it sounds like you have things set up correctly on pfsense given that you have access when connecting directly to port 5. But perhaps a bit more information is required...

      Your pfsense settings wrt VLAN, and your AP setup as well, perhaps that's where it's something you need adjusting.

      H 1 Reply Last reply Jul 10, 2024, 6:51 PM Reply Quote 0
      • H
        hasekd @Gblenn
        last edited by Jul 10, 2024, 6:51 PM

        @Gblenn You mean this? login-to-view login-to-view

        1 Reply Last reply Reply Quote 0
        • J
          JonathanLee
          last edited by Jul 11, 2024, 7:51 AM

          Have you created access control lists on the interface you assigned your vlans?

          Make sure to upvote

          H 1 Reply Last reply Jul 11, 2024, 4:32 PM Reply Quote 0
          • H
            hasekd @JonathanLee
            last edited by hasekd Jul 11, 2024, 4:33 PM Jul 11, 2024, 4:32 PM

            @JonathanLee Well I do not know what you mean, so no. How to do it please? Maybe If I install OpenWrt on my wap it will be easier to config?

            J V 2 Replies Last reply Jul 11, 2024, 4:33 PM Reply Quote 0
            • J
              JonathanLee @hasekd
              last edited by JonathanLee Jul 11, 2024, 4:35 PM Jul 11, 2024, 4:33 PM

              @hasekd What is listed on your interfaces tab?

              login-to-view

              Make sure to upvote

              H 1 Reply Last reply Jul 11, 2024, 4:35 PM Reply Quote 0
              • H
                hasekd @JonathanLee
                last edited by Jul 11, 2024, 4:35 PM

                @JonathanLee I have there the VLAN, LAN and WAN

                J 1 Reply Last reply Jul 11, 2024, 4:36 PM Reply Quote 0
                • J
                  JonathanLee @hasekd
                  last edited by Jul 11, 2024, 4:36 PM

                  @hasekd Do you have any rules listed for your VPN like this..?
                  I am sure you do just checking

                  login-to-view

                  Make sure to upvote

                  H 1 Reply Last reply Jul 11, 2024, 4:37 PM Reply Quote 0
                  • H
                    hasekd @JonathanLee
                    last edited by Jul 11, 2024, 4:37 PM

                    @JonathanLee Only this login-to-view

                    J 2 Replies Last reply Jul 11, 2024, 4:40 PM Reply Quote 1
                    • J
                      JonathanLee @hasekd
                      last edited by Jul 11, 2024, 4:40 PM

                      @hasekd run a trace route and see where the packets fail.. Did you set your DNS to allow resolution form your IOT side also?

                      login-to-view

                      Does Network interfaces have IOT selected?

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • J
                        JonathanLee
                        last edited by Jul 11, 2024, 4:41 PM

                        login-to-view

                        Also have you enabled DHCP on that interface?

                        Make sure to upvote

                        H 1 Reply Last reply Jul 11, 2024, 4:46 PM Reply Quote 0
                        • H
                          hasekd @JonathanLee
                          last edited by hasekd Jul 11, 2024, 4:47 PM Jul 11, 2024, 4:46 PM

                          @JonathanLee I have everything allowed and enabled. Maybe the WAP is the problem I will try to change for a different one and maybe install OpenWrt on it and I will see. On this I can not install it. I did not find any tutorial to set up this on tp-link, but for OpenWrt tutorials are available

                          J 1 Reply Last reply Jul 11, 2024, 5:42 PM Reply Quote 0
                          • V
                            viragomann @hasekd
                            last edited by Jul 11, 2024, 4:59 PM

                            @hasekd said in VLAN accessed wirelessly can not access internet:

                            Maybe If I install OpenWrt on my wap it will be easier to config?

                            At least I can tell you, that I'm successfully running an OpenWRT WAP with 5 VLANs behind pfSense.

                            Maybe you should try to change your VLAN ID 1 into something else. Some devices don't work properly, when you have tagged and untagged packets on the same interface.

                            H 1 Reply Last reply Jul 11, 2024, 5:02 PM Reply Quote 1
                            • H
                              hasekd @viragomann
                              last edited by Jul 11, 2024, 5:02 PM

                              @viragomann Okay, I will try it with the OpenWrt and also try to change the VLAN id 1 to something else

                              1 Reply Last reply Reply Quote 0
                              • J
                                JonathanLee
                                last edited by Jul 11, 2024, 5:41 PM

                                OpenWRT works fine I tested it out with AP dummy mode on mine.

                                Make sure to upvote

                                1 Reply Last reply Reply Quote 0
                                • J
                                  JonathanLee @hasekd
                                  last edited by Jul 11, 2024, 5:42 PM

                                  @hasekd does your AP have the DNS set as the firewall and or is it in bridge mode or is it handing out dhcp also?

                                  Make sure to upvote

                                  H 1 Reply Last reply Jul 11, 2024, 5:59 PM Reply Quote 0
                                  • H
                                    hasekd @JonathanLee
                                    last edited by Jul 11, 2024, 5:59 PM

                                    I could not find any of these settings on the AP. I have now disconnected it and will change for some else. I will let then know if I figure it out with the other one.

                                    H 4 Replies Last reply Jul 12, 2024, 2:13 AM Reply Quote 0
                                    • J
                                      JonathanLee @hasekd
                                      last edited by Jul 11, 2024, 8:13 PM

                                      @hasekd that ACL allows access to everything any VLAN or interface fyi

                                      Make sure to upvote

                                      1 Reply Last reply Reply Quote 0
                                      • H
                                        HLPPC Galactic Empire @hasekd
                                        last edited by Jul 12, 2024, 2:13 AM

                                        @hasekd Some TP-Link switches have an MDIX port and some require a crossover cable. And some have a line above two or three ports which mean you can use only one of these two or three ports for WAN/LAN.

                                        H 1 Reply Last reply Jul 12, 2024, 2:20 AM Reply Quote 0
                                        • H
                                          HLPPC Galactic Empire @HLPPC
                                          last edited by HLPPC Jul 12, 2024, 2:57 AM Jul 12, 2024, 2:20 AM

                                          @HLPPC Also, I don't think any port should be tagged except the one from the pfSense, which is doing the tagging and untagging on that port. This guide also recommends disabling vlan 1: https://youtu.be/5ohLAFHnOHg

                                          He has a TL-SG108E which can use a straight through cable with the pfsense but on my ISP router 100% needs a crossover. The TL-SG105E has an MDIX port though, and connecting two of those switches likely needs a crossover cable, or at least it matters between the two different types of TP-Link switches. MDI to MDI.

                                          Those are like, my favorite switches for now but easy af to softlock yourself out if you disable vlan 1, and doing so messes with pfBlocker and maybe VPN

                                          alt text

                                          1 Reply Last reply Reply Quote 0
                                          9 out of 47
                                          • First post
                                            9/47
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.