Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can i set up my WLAN Network with this picture ?

    Scheduled Pinned Locked Moved Captive Portal
    11 Posts 6 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      The picture does not work.

      1 Reply Last reply Reply Quote 0
      • X
        xTobiasx
        last edited by

        sry. I have it now appended.

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan
          last edited by

          Strange.
          Having a 3 NIC pfSense that could ans should do everything (isolated guest captive portal, DHCP server, DNS server, firewall, etc) we see lately the most incredible VLAN structures ….
          One of the least known secrets about networking is : KEEP IT SIMPLE - NO MATTER WHAT.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • C
            chris4916
            last edited by

            I've to admit that I even don't clearly understand the purpose, although I've some idea  ;)
            Better than implementation drawing, some written explanation about goal and features would help.

            I guess goal is to implement:

            • captive portal for WLAN guest providing isolated access to internet (I mean isolated from LAN and other networks)
            • access to internet for LAN user
            • regarding intern WLAN users, this is not clear to me yet. Dedicated VLAN, then… ?

            Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              I don't understand why you are putting Intern WLAN through pfSense at all.  Why not just drop the WLAN onto VLAN 1 to begin with? (all the reasons not to use VLAN 1 in a managed switch environment suppressed)

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • X
                xTobiasx
                last edited by

                @Derelict:

                I don't understand why you are putting Intern WLAN through pfSense at all.  Why not just drop the WLAN onto VLAN 1 to begin with? (all the reasons not to use VLAN 1 in a managed switch environment suppressed)

                i put it not direct in VLAN 1 because i will only give access to listen MAC Adresses in our Company Network. At the Moment the Intern WLAN is in VLAN 1 but is only scret with a "WPA2 Passwort" and we would scret with Password an MAC. Guest is only secret with Capative Portal.

                @chris4916:

                I've to admit that I even don't clearly understand the purpose, although I've some idea  ;)
                Better than implementation drawing, some written explanation about goal and features would help.

                I guess goal is to implement:

                • captive portal for WLAN guest providing isolated access to internet (I mean isolated from LAN and other networks)
                • access to internet for LAN user
                • regarding intern WLAN users, this is not clear to me yet. Dedicated VLAN, then… ?

                yes you are right. My english is not so good because this i have make a picture.

                • captive portal for WLAN guest providing isolated access to internet (I mean isolated from LAN and other networks)
                • access to internet for LAN user
                  yes correct and the WLAN User from the "Intern Wlan" get the IP from the "DHCP Server" in VLAN 1 because the Notebooks are in our Domäne.
                1 Reply Last reply Reply Quote 0
                • S
                  Supermule Banned
                  last edited by

                  Way to complicated.

                  Ditch the FW infront of pfSense.

                  WWW -> pfSense -> VLAN's -> WLAN

                  EOS.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    @xTobiasx:

                    i put it not direct in VLAN 1 because i will only give access to listen MAC Adresses in our Company Network. At the Moment the Intern WLAN is in VLAN 1 but is only scret with a "WPA2 Passwort" and we would scret with Password an MAC. Guest is only secret with Capative Portal.

                    But that is a function of your AP (or, maybe, your switch), not pfSense.  pfSense is needlessly in the way just to take the traffic from VLAN 5 and put it on VLAN 1 on the same switch.  You could just put the traffic out of the AP onto VLAN 1 and be done.

                    MAC addresses are so easily-spoofed and they're transmitted in-the-clear regardless of wireless security protocol in use so any security that filtering on them appears to provide is just an illusion and not worth the hassle.  It will do nothing to keep someone who knows the passphrase off your network.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • X
                      xTobiasx
                      last edited by

                      Okay, i make it so. I control the Intern Wlan with a Radius Server.

                      WLAN_Netzwerk2.JPG
                      WLAN_Netzwerk2.JPG_thumb

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        I would not use VLAN 1 (I'd use all untagged ports on, say VLAN 2 through 4094) but that looks much better if replacing the existing firewall with pfSense is not an option and you just want to use captive portal.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.