Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic Shaper

    Scheduled Pinned Locked Moved Traffic Shaping
    20 Posts 3 Posters 9.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      johnnguyen
      last edited by

      Hi hoba, thanks for you answer me, I want said to you about system I made.

      I make VLANs at Layer 2 Core Switch, at Layer 3 I used RIP routing for all network in system and used static route to route outside.

      The system before pfsense:

      From Layer 3 Core Swicth connected to Inside in Fix Firewall.
      For traffic from VLANs to Internet I used static route "any" at Layer 3 Core Switch route to "PiX Inside" and system running is OK

      The system after connected pfsense

      From Layer 3 Core Switch connect to "pfsense LAN", from "pfsense WAN" connect to "Pix Inside", and changed "static route" at Layer3 Core Switch to pfsense LAN IP address, but system can not run.

      After change I see LAN system run is OK but others VLANs can not run.
      In pfsense I open all Firewall rule at LAN an WAN to any.

      Pls help me fix this problem.

      regards, Johnnguyen!

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        I think you are just missing the static routes for the vlans back to the coreswitch. This way traffic doesn'T know how to return and no outbound NAT rules will be generated automatically by the pfsense for the vlan subnets.
        You already placed the pass any source rule at lan it seems so this should not be a firewall problem.

        1 Reply Last reply Reply Quote 0
        • J
          johnnguyen
          last edited by

          So, I should make static routes "any" at pfsense LAN interface?

          1 Reply Last reply Reply Quote 0
          • J
            johnnguyen
            last edited by

            I want ask you one question, when I make static route at LAN interface the traffic shapper can active on traffic?

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              You need a bunch of static routes:
              Interface LAN, subnet vlan1, gateway layer 3 coreswitch
              Interface LAN, subnet vlan2, gateway layer 3 coreswitch
              Interface LAN, subnet vlan3, gateway layer 3 coreswitch
              …

              1 Reply Last reply Reply Quote 0
              • J
                johnnguyen
                last edited by

                oh, I need make VLAN ID on pfsense LAN Interface the same VLAN ID at Core Switch? and at pfsense LAN interface I make Bridge with LAN interface, after that I make static route for each VLAN subnet?

                1 Reply Last reply Reply Quote 0
                • J
                  johnnguyen
                  last edited by

                  Hi Hoba,

                  When I input static route Interface LAN, subnet vlan1, gateway layer 3 coreswitch … --> Network down, from in pfsense I cannot access to Outsite? What's problem?

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnnguyen
                    last edited by

                    Hi Hoba, I performed static route at LAN Interface with VLAN subnet but it's not run, I monitor just LAN address run other VLAN not run, plshelp me fix this problem

                    1 Reply Last reply Reply Quote 0
                    • H
                      hoba
                      last edited by

                      Make sure your coreswitch is configured properly and you have all routes in place that are needed at all involved routers/switches.

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnnguyen
                        last edited by

                        yeah, That is correct because my system run is OK before connect to Pfsense and in Pfsense I in put all Subnet VLAN route.

                        I don't know what is problem?

                        Johnnguyen

                        1 Reply Last reply Reply Quote 0
                        • H
                          hoba
                          last edited by

                          You added static routes at the pfsense for the vlans? You don't need routes for subnets that are directly connected to the pfsense.

                          1 Reply Last reply Reply Quote 0
                          • J
                            johnnguyen
                            last edited by

                            Hi Hoba,

                            Examples: I have VLAN 5: Network: 10.100.5.0/24, Gateway: 10.100.5.1, VLAN 6: network 10.100.6.0/24, gateway: 10.100.6.1…

                            LAN address at pfsense: 10.100.100.5/24

                            In Layer 3 Core switch I used static route: ip route 0.0.0.0 0.0.0.0 10.100.100.5

                            Last time (not connect to pfsense) the system running is OK

                            As you help me, at pfsense LAN address I used static route as follow:

                            Interface LAN, Network:10.100.5.0/24, gateway layer 3 coreswitch: 10.100.5.1
                            Interface LAN, Network:10.100.6.0/24, gateway layer 3 coreswitch: 10.100.5.1
                            ...

                            Of course, I don't make routes for subnets that are directly connected to the pfsense.

                            Pls give me what is wrong?

                            Regards,
                            Johnnguyen

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnnguyen
                              last edited by

                              Sorry Interface LAN, Network:10.100.6.0/24, gateway layer 3 coreswitch: 10.100.6.1 (not 10.100.5.1)

                              1 Reply Last reply Reply Quote 0
                              • A
                                aldo
                                last edited by

                                i think this should be
                                lan 192.168.5.0/24 gateway "other ip of the switch"

                                the gateway of the static route needs to be in the directly connected subnet

                                1 Reply Last reply Reply Quote 0
                                • J
                                  johnnguyen
                                  last edited by

                                  Can you speak clearly?

                                  Because I connect direct from Layer3 core Switch to Pix then system run is OK, but I connect from Layer 3 core switch to pfsense to pix then system is down. I make route already but it is not run, I don't know why?

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    hoba
                                    last edited by

                                    Just one very weird thought…are all links at the pfSense up at all (see status>interfaces)? Or do you maybe need a crossovercable between some of the devices?  ::)

                                    1 Reply Last reply Reply Quote 0
                                    • J
                                      johnnguyen
                                      last edited by

                                      oh, crossovercable between some of the devices? I don't think so because I test "ping" to outside at LAN or WAN pfsense interfase are very good, just other subnets from other VLANs cannot access to outside, although I used static route the same you consult but from LAN pfsense interface I can not ping to gateways of other VLAN

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        johnnguyen
                                        last edited by

                                        Hi all, may I help me to solve this problem?

                                        Regards, Johnnguyen

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.