Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Solved! Has anyone recently (2024) set up a VLAN using pfSense and Unifi Network application and switches? (DHCP back-end has to be ISC)

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    20 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NGUSER6947 @Gblenn
      last edited by NGUSER6947

      @Gblenn So, the way I have Port 1 configured is like this:
      9c59cd03-b804-4917-9c94-c8f005c8379d-image.png

      and yeah just looking at this page it appears Port 1 isn't tagged. But! drilling into it shows this for Port 1 and Port 3:
      9681e000-0ecf-486f-9361-1c8de4a8bc6c-image.png

      Unless the Unifi UI is once again messing with my brain (quite possible), the way I understand this is that Port 1 and Port 3 are set for Default but also is tagged for the Automation VLAN.

      If I just tag Port 1 by setting the Native VLAN/Network to Automation, this is when all network comm halts. I assume that's because nothing else on the switch can get to the router (but who knows, that's just my assumption). Nonetheless, that's what I have observed via testing.

      I did the test you suggested. With a PC plugged into Port 2, set up like this:
      f4abf3fe-457a-4f1f-8133-78ae947a23b3-image.png

      it does not get an IP, just spins a bit then gives up.

      N 1 Reply Last reply Reply Quote 0
      • N
        NGUSER6947 @NGUSER6947
        last edited by

        Here are the screenshots from pfSense.
        d9cb79a6-f06c-49d0-9098-d9b32bec4aa1-image.png

        077f0ac5-1ce1-4f09-a3d7-4906cedbc8ed-image.png

        33b376f3-57f1-4c1b-ae7b-c6b0bd2a868c-image.png

        cb033925-4660-4f2b-870e-48491fb95ac1-image.png
        5b8e023b-8b3e-4bbe-9484-c689906b8981-image.png

        ed2170b0-9236-4780-a3b4-6da6c0506404-image.png

        7729ddea-b314-4675-be9b-2cca17f95475-image.png

        G 1 Reply Last reply Reply Quote 0
        • G
          Gblenn @NGUSER6947
          last edited by Gblenn

          @NGUSER6947 Well I can't see anything out of the ordinary there. It looks like it's correctly set up in pfsense. Perhaps one more thing... there is a menu item under Interfaces called Switch / VLANs, correct? What does that look like?
          Aaand, I assume you are connecting the switch to the port with the label LAN on the Netgate device?

          N 1 Reply Last reply Reply Quote 0
          • U
            Uglybrian
            last edited by

            In addition to everything that has Been said here. I noticed that you are Using the KEA back end. As a last resort, you may want to try switching the back to ISC and see if that makes any difference. I know the first time you tried to do this you were probably using ISC. Even though that didn’t work out. KEA is still in the detail shop and not ready for the showroom floor.

            N 1 Reply Last reply Reply Quote 0
            • N
              NGUSER6947 @Gblenn
              last edited by NGUSER6947

              @Gblenn This is the setup page you asked about:
              0a59db6c-3cbb-4335-83b6-afe149afbf76-image.png

              And yes, the switch is plugged into the LAN port on pfSense.

              N 1 Reply Last reply Reply Quote 0
              • N
                NGUSER6947 @Uglybrian
                last edited by

                @Uglybrian To change it to ISC where is that, also do I need to restart the router or just save and apply changes?

                1 Reply Last reply Reply Quote 0
                • N
                  NGUSER6947 @NGUSER6947
                  last edited by

                  @Gblenn I did some research and apparently with the SG-1100 you have to set up tagging inside Interfaces/Switch/VLANs.

                  This is how I have it configured now, which exactly matches several of the tutorials I found:
                  9e73f904-16d7-4180-9906-d20bd078f18d-image.png

                  Still, no happiness. Neither a wifi device or the PC I have plugged into Port 2 (which is tagged) will obtain an IP.

                  1 Reply Last reply Reply Quote 0
                  • U
                    Uglybrian
                    last edited by

                    If you want to give it a try. Go to System> Advanced> Networking. Click on ISC DHCP then save at the bottom. There is no need to restart the router.

                    N 1 Reply Last reply Reply Quote 0
                    • N
                      NGUSER6947 @Uglybrian
                      last edited by

                      @Uglybrian Well sure enough, that did it! Man, this has been driving me nuts.

                      Phone connected right away.

                      Thanks to you and @Gblenn for your help and assistance.

                      G 1 Reply Last reply Reply Quote 0
                      • G
                        Gblenn @NGUSER6947
                        last edited by

                        @NGUSER6947 Great that it works now, but really strange that KEA would be the culprit. I think you had some issues with KEA all along, which you didn't notice until you were testing with something requiring a new IP. I would try changing back to KEA to see if it still works, which I'm guessing it will...

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          NGUSER6947 @Gblenn
                          last edited by

                          @Gblenn yeah I may try that at some point. Since ISC is marked "Deprecated" I would think that KEA would be pretty well sorted out by now.

                          G 1 Reply Last reply Reply Quote 0
                          • G
                            Gblenn @NGUSER6947
                            last edited by

                            @NGUSER6947 Yes but things seem to pop up, at least in discussions. I had it crash a few months back and it didn't want to restart due to a lock file lingering, so changed back. But I also have it running on another instance on CE where it's been working fine...

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.