Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nework Layout & Routing Help… please :)

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    16 Posts 3 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      Nucleus
      last edited by

      @kejianshi:

      Everything connected to pfsense and riding those vlans will be double NATed, so your system isn't ideal.

      That is what I wanted to avoid if I could, but wasn't sure if it was possible? What about turning NAT off in pfsense and setting up a static route in DD-WRT? Would that work to eliminate the double NAT issue?

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        In that case, what is the role of pfsense in your configuration?  Useless dongle/additional point of failure/latency increaser?
        What is it you want pfsense to accomplish for you?

        1 Reply Last reply Reply Quote 0
        • N
          Nucleus
          last edited by

          At this point I wanted more granular control of VLANs via a GUI. Like I said though I will be migrating over to just pfSense over time.

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            If you just want granular control via VLANs via GUI, you can do that with just a VLAN switch.  Most have GUIs and will allow VLAN segregation, VLAN tagging etc. You can even set up VLANs segregated out inside of DD-WRT.

            1 Reply Last reply Reply Quote 0
            • N
              Nucleus
              last edited by

              The level of switch that I'm buying won't give me the ability to block/allow access to/from VLANs down to the node IP & port. I want to move my VLANs away from DD-WRT and phase it out.

              1 Reply Last reply Reply Quote 0
              • K
                kejianshi
                last edited by

                Then you need to move directly to pfsense.  Whats the issue with your pfsense hardware again?

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Whilst I agree with Kejianshi that moving to pfSense as your primary router would be a better solution I can understand your reasons for keeping DD-WRT. Moving from one working setup to some thing different is always best accomplished one step at a time. There have been countless threads here where people have replaced a complex configuration on some other firewall with pfSense all in one go and then struggled for hours troubleshooting.

                  It's possible to use pfSense just to route/firewall between your VLANs without NAT. You'll need to add some static routes to dd-wrt so it knows where to send traffic. As I said above though, one step at a time! Set it up as double NAT to start off with and take it from there.

                  In pfSense there are really only two types of interface, those with a gateway defined and those without. Since pfSense needs at least one gateway the first interface you assign will have one and is labelled 'WAN'. The second interface, by default, will be the internal interface and is labelled 'LAN'. Those are just labels though. Subsequent interfaces are defined as internal (Lan type) or extrenal (Wan type) only by weather or not they have a gateway and can be labelled anything you like. The only interface that has any special properties is the 'LAN' which has firewall rules allowing outbound traffic by default. All other interfaces must be given appropriate rules to allow traffic. I hope that didn't come across too confusing!  ;)

                  Steve

                  Edit: typo

                  1 Reply Last reply Reply Quote 0
                  • N
                    Nucleus
                    last edited by

                    @stephenw10:

                    It's possible to use pfSense just to route/firewall between your VLANs without NAT. You'll need to add some static routes to dd-wrt so it knows where to send traffic.

                    Thanks, Steve.
                    Would I need to setup a static route for each VLAN (subnet) routed by pfSense or just (1) for the VLAN between pfSense and the router?

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      You would need one for each subnet behind pfSense.
                      Get it working with double NAT first then experiment.  ;)

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • N
                        Nucleus
                        last edited by

                        Thanks, Steve!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.