Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense setup over an existing wired network

    General pfSense Questions
    4
    17
    7.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hchady
      last edited by

      actually it's not possible to obtain a dhcp leases from the campus dhcp server. they use a kind of dhcp static leases and unknown clients (wired or wireless) could not obtain any dynamic ip adress.

      with VLANs, all used switches should be vlan compatible ? or just the switch connected to the pfsense and the end switch ?
      pfsense can do site to site VPN ? (or something like EoIP developed by mikrotik)
      there is no way to access to pfsense lan side from the wan side ?

      thanks

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        You really should consult the network administrator of this network. Anything that we are discussing here is not worth anything if he doesn't allow you to run this on his network.

        1 Reply Last reply Reply Quote 0
        • H
          hchady
          last edited by

          the administrator of the network is ok to modify some setups, but he cannot modify any material (switches or something like that)
          DHCP leases from the university server are also possible

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            Ask him if he can setup tagged vlans on the ports that you hook up your devices on. One vlan for the network that already is non vlaned present there. One additional vlan for your captive portal lan. Then setup 2 vlans at your pfSense. One for the incoming WAN and one for the captive portal LAN. Setup your accesspointdevices to be in the captive portal vlan. This way you onl need 1 nic for this setup at your pfSense and it's also pretty secure as though only using one physical wire  the both networks are seperated.

            1 Reply Last reply Reply Quote 0
            • J
              jeroen234
              last edited by

              @hchady:

              Hello,

              I need to configure pfsense to work with an existing LAN network.
              the existing LAN is a university network that have it's DHCP server

              pfsense server is now connected to this network on the WAN port (WAN adress 134.214.116.x/22)
              the LAN side have DHCP and captive portal enabled (DHCP range 192.168.10.x/24) and is connected to an access point (WRT54G) to serve only wirless clients.
              to extend the range of my wirless network, I am using many WRT54G connected by WDS.
              Everything work great, I don't have any problem with this configuration
              But over WDS my transfer rates are around 4Mbps.
              Now I would like to modify my configuration and find a way to connect my access point by LAN to have higher transfer rates (on wan side I have ~45 Mbps)

              note that every added ap with wds will cut youre transfer rates in two
              and that wireless is one way thafic and cabled is 2 way trafic
              with one 54 mb ap(11g) you get a max transfer rate of 27 mb
              example with 54 mb ap's
              1 ap 27 mb
              2 ap 13,5 mb
              3 ap 6,7 mb
              4 ap 3,4 mb
              etc

              1 Reply Last reply Reply Quote 0
              • H
                hchady
                last edited by

                yes sure, I know that wds cut transfer rates. but i didn't have another option !

                now i am trying to setup VLANs but i am not really familliar with this kind of setup

                also we have some installed switched that are not vlan compatible so i can only play with start and end switches… any chance to work ?

                1 Reply Last reply Reply Quote 0
                • H
                  hoba
                  last edited by

                  Most non vlan capable switches will pass the traffic unchanged. it might work though you won't have the security level that real vlan switches would provide you with.

                  1 Reply Last reply Reply Quote 0
                  • H
                    hchady
                    last edited by

                    and what about PCs connected to non-compatible VLAN switches ? they get their dhcp leases from pfsense or from the campus network dhcp ?

                    thanks

                    1 Reply Last reply Reply Quote 0
                    • H
                      hoba
                      last edited by

                      They should get it from the campus server and ignore the vlan traffic though they might see them. Nics that support VLANs could be configured to reside in the VLAN though, so it depends on how the client is configured or what the client supports.

                      1 Reply Last reply Reply Quote 0
                      • H
                        hchady
                        last edited by

                        it didn't work as expected,

                        wireless clients always get their dhcp leases from pfsense, but other PCs connected to the university switches get sometimes their leases from pfsense too …

                        1 Reply Last reply Reply Quote 0
                        • H
                          hoba
                          last edited by

                          Sorry, no other solution that I can think of then.

                          1 Reply Last reply Reply Quote 0
                          • H
                            hchady
                            last edited by

                            Thank you anyway

                            I will try to use EoIP between dd-wrt routers and see if it works

                            Chady

                            1 Reply Last reply Reply Quote 0
                            • H
                              hoba
                              last edited by

                              Not sure if the DD-WRT's support dhcp relay. Maybe that would work too.

                              1 Reply Last reply Reply Quote 0
                              • R
                                rsw686
                                last edited by

                                I just updated my WRT54G access point to DD-WRT v23 revision 2. It does support DHCP forwarding. So you could go this route.

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hchady
                                  last edited by

                                  DD-WRT support DHCP relay and i was playing with this option also.

                                  on pfsense i have denied unkown users to get a lease from dhcp and i have connected the pfsense LAN side to the campus network
                                  DHCP forwarder is set on dd-wrt routers to forward dhcp requests to pfsense. routers are connected to campus network from their LAN side

                                  Now when a registred wireless user connects to ddwrt router, it gets a dhcp from pfsense. but if it's not a registred user, it get an IP from the university DHCP after 1 minute : so no captive portal authetication and no security
                                  and when a PC connects to campus network, sometimes it doesn't get its IP quickly. this is not a real problem, i think there are some additionnal setup to do with university network and routers.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.