Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setting up vlans/trunk

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    12 Posts 4 Posters 7.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      So what version are you trying to use?

      What are you setting to general? I see no general LAGG setting in pfSense (but I'm looking at 2.3.)

      In my experience, you have to create a lagg using interfaces with a similar configuration (all the same vlan tags, etc) After you create the lagg you tag the lagg and it is added to all member interfaces. Are your pfSense VLAN tags on the lagg interface or member interfaces?

      Whatever you're seeing it's probably not because pfSense can't do it but that mistakes or erroneous assumptions are being made.

      But before making a complete fool of myself I'm going to lacp two interfaces on an SG-2440 on 2.2.6 to my SG300.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Don't know, friend. It all seemed to work as expected…

        Switch:

        interface gigabitethernet9
        channel-group 2 mode auto
        !
        interface gigabitethernet10
        channel-group 2 mode auto
        !
        interface Port-channel2
        description TEST_LAGG
        switchport general acceptable-frame-type tagged-only
        switchport mode general
        switchport general allowed vlan add 1200 tagged
        !

        Interfaces > (assign), LAGG Tab - Create LACP lagg with igb2,igb3

        Patch gi9 to igb2 and gi10 to igb3

        sg300-223#sh int port-channel 2

        Load balancing: src-dst-mac-ip.

        Gathering information…
        Channel  Ports
        -------  -----
        Po2      Active: gi9-10

        Interfaces > (assign), VLAN tab - Create VLAN 1200 on lagg0
        Interfaces > (assign) - Add OPT1 with Network port VLAN 1200 on lagg 0
        Interfaces > OPT1 - Enable interface and assign address 10.34.56.1/24
        Firewall > Rules, OPT1 tab - Create generic pass any any from OPT1 net rule.

        Create a workstation interface on VLAN 1200 with an address of 10.34.56.99/24.

        $ ping 10.34.56.1
        PING 10.34.56.1 (10.34.56.1): 56 data bytes
        64 bytes from 10.34.56.1: icmp_seq=0 ttl=64 time=0.442 ms
        64 bytes from 10.34.56.1: icmp_seq=1 ttl=64 time=0.352 ms
        64 bytes from 10.34.56.1: icmp_seq=2 ttl=64 time=0.305 ms
        64 bytes from 10.34.56.1: icmp_seq=3 ttl=64 time=0.384 ms
        ^C
        –- 10.34.56.1 ping statistics ---
        4 packets transmitted, 4 packets received, 0.0% packet loss
        round-trip min/avg/max/stddev = 0.305/0.371/0.442/0.050 ms

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • G
          glennonline
          last edited by

          Thanks for the info, i've attached some screenshots of how I got everything set-up, the snap of the switch is of how it always used to work, in trunk mode.

          All the vlans were made member of the LAG on the switch.

          Thanks for the quick feedback!

          I'm on  pFsense 2.2.6-RELEASE (amd64)

          interfaces.PNG
          interfaces.PNG_thumb
          LAGG.PNG
          LAGG.PNG_thumb
          ![switch trunk.PNG](/public/imported_attachments/1/switch trunk.PNG)
          ![switch trunk.PNG_thumb](/public/imported_attachments/1/switch trunk.PNG_thumb)
          vlan.PNG
          vlan.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Mixing tagged and untagged traffic on one interface can be problematic. Vendors do it differently. Just tag it all and it'll work.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • jahonixJ
              jahonix
              last edited by

              We don't see the VLAN config of your TP-Link switch.
              Can we assume you have VLAN 2 tagged configured on the trunk as well?

              1 Reply Last reply Reply Quote 0
              • G
                glennonline
                last edited by

                Yes, VLAN2 was configured and tagged, but it didnt do a thing.

                Just yet I tried to create VLAN 1 on my pfsense router, assign LAN to it and change the config on my switch to trunk, it's all dead.

                I'd be inclined to just buy the TL-SG3216 V2 to see if that would fix the problem, but I'm guessing that wouldn't help all to much, or is it worth a shot?

                1 Reply Last reply Reply Quote 0
                • R
                  robi
                  last edited by

                  Note that meaning of "trunk" in TP-Link hardware is not the same as in Cisco hardware. Read the docs carefully.

                  1 Reply Last reply Reply Quote 0
                  • G
                    glennonline
                    last edited by

                    I'm aware that Cisco has VTP for trunking, but in essence, both TP-link and Cisco use the term trunking for combining multiple vlans over a single link right?

                    I'm still having this issue, so if anyone could point me in a direction for troubleshooting that would be great!

                    1 Reply Last reply Reply Quote 0
                    • R
                      robi
                      last edited by

                      @glennonline:

                      I'm aware that Cisco has VTP for trunking, but in essence, both TP-link and Cisco use the term trunking for combining multiple vlans over a single link right?

                      I'm still having this issue, so if anyone could point me in a direction for troubleshooting that would be great!

                      Nope. Check out the docs of Tp-Link (user manual of your switch, download it from their site). They use the "trunk" term for port aggregation:
                      Defines a network link aggregation and trunking method which specifies how to create a single high-speed logical link that combines several lower-speed physical links.
                      This has nothing to do with vlans.

                      1 Reply Last reply Reply Quote 0
                      • R
                        robi
                        last edited by

                        @Derelict:

                        Mixing tagged and untagged traffic on one interface can be problematic. Vendors do it differently. Just tag it all and it'll work.

                        On TP-Link switches, it is possible to have tagged and untagged traffic on the same interface, and it works flawlessly also with pfSense like that.
                        I'm using dozens of UniFi wireless hotspots on each site with TP-Link switches, which require to have their management network untagged, and wireless networks tagged on the same interface.

                        1 Reply Last reply Reply Quote 0
                        • G
                          glennonline
                          last edited by

                          @robi:

                          @Derelict:

                          Mixing tagged and untagged traffic on one interface can be problematic. Vendors do it differently. Just tag it all and it'll work.

                          On TP-Link switches, it is possible to have tagged and untagged traffic on the same interface, and it works flawlessly also with pfSense like that.
                          I'm using dozens of UniFi wireless hotspots on each site with TP-Link switches, which require to have their management network untagged, and wireless networks tagged on the same interface.

                          Hi Derelic,

                          I've always used it as you described, untagged LAN network, additional tagged networks and the switch in LAGG with trunked ports.

                          However, since i've upgraded it stopped working for my LAG, i've now decided to buy a new switch to see what it does, i'll keep you guys posted.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.