Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Will pfSense pass through VLAN tagged traffic in transparent firewall mode?

    Firewalling
    3
    7
    3.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      radicd
      last edited by

      I'm looking to add a pfSense firewall in between a router and switch with vlan tagging setup on the router and just placing a transparent firewall in between without any additional configuration. Would there be any problems passing through the vlan tagged traffic?

      Current setup:

      Router (vlan tagged traffic) > brocade switch

      Looking to get the following in production:

      Router (vlan tagged traffic) > pfSense (transparent firewall) > brocade switch

      1 Reply Last reply Reply Quote 0
      • K
        k6usy
        last edited by

        You just need to setup the vLANs on both NICs of the pfsense box.  Then assign the vLANs to interfaces and setup the rules.

        1 Reply Last reply Reply Quote 0
        • R
          radicd
          last edited by

          Thanks for the reply, but I'm trying to avoid maintaining VLANs in the firewall. I would like pfSense to act as nothing more than a firewall and have the VLANs configured in the router.

          Is the setup I mentioned in the original post possible?

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            I believe the behavior of if_bridge is it will pass through the 802.1Q tags. Some searching indicates that's been broken at some past points but that predates the base version we're on.

            1 Reply Last reply Reply Quote 0
            • K
              k6usy
              last edited by

              @radicd:

              Thanks for the reply, but I'm trying to avoid maintaining VLANs in the firewall. I would like pfSense to act as nothing more than a firewall and have the VLANs configured in the router.

              Is the setup I mentioned in the original post possible?

              How many vLANs do you have?

              1 Reply Last reply Reply Quote 0
              • R
                radicd
                last edited by

                @cmb:

                I believe the behavior of if_bridge is it will pass through the 802.1Q tags. Some searching indicates that's been broken at some past points but that predates the base version we're on.

                Thanks, going to do some internal testing and I will confirm back.

                1 Reply Last reply Reply Quote 0
                • R
                  radicd
                  last edited by

                  @k6usy:

                  @radicd:

                  Thanks for the reply, but I'm trying to avoid maintaining VLANs in the firewall. I would like pfSense to act as nothing more than a firewall and have the VLANs configured in the router.

                  Is the setup I mentioned in the original post possible?

                  How many vLANs do you have?

                  Too many, 50+ on each switch and constantly being modified.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.