Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Basic pfsense/vlan/network question

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    15 Posts 3 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      "What to do with the bridge."

      I get rid of it..  Bridges have very limited use cases, really limited..  Why do you have your wifi and lan bridged?  Don't you have external AP??  if you want that on your lan network, why not just connect your AP(s) to your switch?  Ports on pfsense are router ports not switch ports..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • M
        mark81
        last edited by

        Hi,

        Thanks again. I don't have an external AP. Just my Pfsense appliance with wireless.

        I configured a wifi/lan bridge cause I need both interfaces in the same subnet. I would like to configure the LAN port as trunk port so I can send multiple subnets to my first floor but also the LAN subnet.

        So the challenge I'm facing is the 192.168.100.0/24 network. It is now configured as the network address of the bridge. But I would like to have it tagged upstairs as well (so part of my trunk port).
        I cannot configure it on a vlan cause it tells me it is already in use,

        So how can I get the LAN port as a trunkport. With multiple vlans, but also the 192.168.100.x vlan and still have both the LAN interface and the wifi interface in that vlan as well?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          You can not put a vlan on a bridge AFAIK… why would anyone ever want to do that??  You put the vlan on the physical interface..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • M
            mark81
            last edited by

            I understand that i cannot put the vlan on the bridge. i would like to put the vlan on the LAN interface (physical).

            So if I create vlan 100 on LAN. I assign it and I configure network 192.168.100.1/24. How can I configure my Wifi interface in that same vlan?

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              huh??  Your wifi is already on the lan with your bridge… How you can not be in 2 networks at the same time.

              Didn't you already create a bridge?  And your wifi and lan are on the same network 192.168.100/24

              You stated
              "My goal is to have LAN and wifi both in the same 192.168.100 network,"

              What does that have to do with vlans??  why don't you draw what your trying to accomplish..  Currently you have 1 network 192.168.100.0/24 this is connected to both your wire and wifi via a bridge..    So what do you want to do with these vlans?  Create your vlans and assign them to physical interface that is connected to the switch you want to use these vlans on..  You would then trunk that switch port.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • M
                mark81
                last edited by

                Hi,

                Thanks again for helping me. I attached an ugly mspaint drawing which I hope clears up what I'm trying to acchieve.
                Hope it can be done.

                Kind regards,

                Mark

                ![network drawing.jpg](/public/imported_attachments/1/network drawing.jpg)
                ![network drawing.jpg_thumb](/public/imported_attachments/1/network drawing.jpg_thumb)

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  why would your computer need both 20 and 100 vlans?

                  And since your bridge network is 192.168.100/24 then that would just be your native vlan.. What exactly do you want vlan 20 for?  You show no devices in vlan 20 other than your computer that is also in vlan 100??

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • M
                    mark81
                    last edited by

                    The computer is a hyper-v host. I have 2 of those. Is the configuration how I drew it possible? And if it is, how should I configure it?

                    Thanks!

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Again u dont create a vlan that is the same as your native network. Seems all u need is vlan 20 and then u would trunk port to tour vm host i run an esxi vswitch contected to the trunk port in sim fashion as what your wanting to do

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • M
                        mark81
                        last edited by

                        Thanks John. That did the trick. I just assigned vlan20 to my LAN interface and it started working right away.
                        I think I was thinking a little to difficult. I'm a little new with networking devices in general.

                        Thanks again for your patience and help today. I'm happy that I got it working.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Once u get vlans they are not that difficult understanding native and tagged vs untagged and different switch makers use terms a bit different but if you understand the basics just need to know what switch your dealing with

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.