Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Move from non-VLAN to VLAN without complete reconfig?

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 635 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      skywalker
      last edited by

      Hello,
      I have a quick question.
      I have a non VLAN deployment and would like to introduce VLANs on the LAN interface.
      Can I do that without loosing everything?
      I thought about this procedure:

      1. define the VLANs on the switch
      2. configure a backdoor management interface on pfsense, so I don't loose access
      3. configure VLANs
      4. Re-Assign LAN from em0 to my defined VLAN
        -> all defined rules for LAN should now apply to the new interface assignment and all should work, correct?

      thanks if someone could just quickly confirm this before I break things.

      Till

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Yeah. The simple act of defining the VLANs is not generally an interruption.

        After you have the VLANs defined on the right interface and the switchport properly tagged just go to Interfaces > (assign) and change the interface to the tagged VLAN.

        For instance, if you have LAN assigned to igb0, then create VLAN 100 on igb0, you can change the interface assignment to VLAN 100 on igb0 and that network will now be tagged to the switch. All of your configuration (firewall rules, DHCP, etc) will move with that interface assignment.

        Changes like this are certainly best done connected on an interface you are not messing with, as you said.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S Offline
          skywalker
          last edited by

          Great. That's exactly what I wanted to hear!

          many thanks!

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN Offline
            NogBadTheBad
            last edited by

            I used the untagged vlan for the LAN magagement vlan and tagged the other vlans and gradually moved everything, I didn't see an outage.

            That way if I ever do something to hose the VLANS I can still connect to the router by directly connecting a laptop.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              As much as I rail against mixing tagged and untagged traffic I am coming around to this way of thinking as well.

              In fact I just sent a bundle of SG-2440, Ruckus 7372, and D-link DGS-1100-08 home with a family member who lives a few hours from me.

              Everything was untagged except for the OPTX interface for guest WiFi. If something goes wrong I certainly don't want to be dealing with VLAN tags on the phone with them.

              Even though the macOS makes it drop-dead easy to add a tagged virtual interface.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • jahonixJ Offline
                jahonix
                last edited by

                @Derelict:

                Even though the macOS makes it drop-dead easy to add a tagged virtual interface.

                Thanks for the hint, just found it! Is that new in macOS or has it been there longer already? Never looked before …

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  It has been there as long as I can remember.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.