Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to send LAN w/DHCP over both a NIC and a vLAN on another nic?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    13 Posts 4 Posters 1.2k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ Offline
      jimp Rebel Alliance Developer Netgate
      last edited by

      Why involve pfSense? That would be an ugly mess of bridging. You can solve this at L2 between the vswitches, real switches, and your AP. Whatever VLAN your LAN is using untagged, just tag that on the port connected to the AP.

      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • L Offline
        lburns
        last edited by

        So you're right.

        However that would prevent me from managing the networking from the one pane of glass that PFsense provides.

        It's worth noting that no vLANS are in use at this time, and i'm trying to use a vLAN to deliver the LAN alongside the Wireless network.

        All the networks are all on default vLAN for their interface.

        Also note that the WAP is connected DIRECTLY to the ESXi server NIC port and does not go through a switch.

        I suppose I should start thinking about a redeployment using a vLAN based setup, but I was trying to adhere to the design principle of keeping firewall and network management tasks as close to the experience of using a physical firewall server as possible.

        Any more thought on this?

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          To get both networks on the AP even directly connected you'll still have to tag VLANs.

          And the only thing you lose by handling it at L2 is being able to filter wireless users on LAN separately from users on the regular LAN, and if you're doing that, why bother putting them in the same subnet at all? Just keep them isolated.

          Bridging on the firewall is ugly. Avoid it at all costs.

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          L 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            esxi vswitches/portgroups will not strip tags if you set the vlan id to 4095.. Then you can bring in a untagged network and tagged network into a vnic on pfsense..

            This would allow you to handle your network native and vlans at pfsense.. How you connect them into pfsense is the big question.. If your to the point you want to play with vlans - then your at the point to get yourself a vlan capable switch to use..

            You can get a vlan capable switch for like $30..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

            L 1 Reply Last reply Reply Quote 0
            • L Offline
              lburns @jimp
              last edited by

              @jimp the ultimate issue is that the home theater gear at this site is driven by Logitech Harmony remote hub units. these ONLY have WiFi access - not wired.

              Whereas the media servers and rokus are all on the WIRED network to ensure 4K strems properly to all devices.

              (This is a 10Gb switched infrastructure)

              The Rokus cannot take controls from the Harmony units due to routing incompatibilities on the logitech side.

              This is why I need to have the LAN present as a separate SSID beside the WiFi network.

              :(

              1 Reply Last reply Reply Quote 0
              • L Offline
                lburns @johnpoz
                last edited by

                @johnpoz you called out the wall i ran smack into...

                I can get the vLAN out to the WAP from the firewall but how I connect it to the existing LAN is maddening.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  My roku is wired and not on the same wifi network s the harmony hub..

                  Not sure what any of that has to do with the price of tea??

                  GET A SWITCH!!!!

                  Trunk run whatever vlans you want into the esxi nic, set the portgroup to 4095 and let pfsense handle the vlans.

                  This is all basic networking 101 with the addition of simple 30$ switch that support vlans. Allow you to run uplinks on native untagged into different esxi nics or tagged, have devices on any vlan you want. Or uplinks that are tagged can carry multiple networks to the devices that will isolate them like other switches or AP.. Where you could have as many ssid on different vlans you want and them put any wired device on any network you want as well.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                  L 1 Reply Last reply Reply Quote 0
                  • L Offline
                    lburns @johnpoz
                    last edited by

                    @johnpoz It is related because as I mentioned before, the wired Roku on LAN (.1 network) does not receive commands from the Harmony Hub which lives on the WAP (.2) network without a 5-10 second delay.

                    This is a known issue at Logitech and many have issues with this.

                    The only solution at this time is to ensure the two devices are on the same network.

                    I understand what you say about the switch, however I would like to have been able to simply ride the LAN on an extra vLAN using the current setup without having to go on site and install more gear when it shouldn't be necessary.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Its not EXTRA anything... Its how you do networking... You have an AP that does vlans - you need a switch that does vlans. You don't use freaking interfaces as switch ports.

                      You clearly can afford a freaking 30$ switch to do it CORRECTLY!!!

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                      L 1 Reply Last reply Reply Quote 0
                      • L Offline
                        lburns @johnpoz
                        last edited by

                        @johnpoz

                        wow.

                        I'm surprised your a moderator.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          So am I to be honest!! ;)

                          Some times I wonder why I am even still here after 10+ years of the same shit over and over and over again..

                          You clearly can afford 30$ switch with the gear you have... To do something CORRECTLY being told you by 2 people that do networking for a living.. Myself have been in the business before there were even switches..

                          You want to do vlans.. This is your statement... You need to connect multiple devices = Vlan capable switch! Period!!

                          How is that difficult to understand. Sure you go ahead and bridge 2 of your 6 interfaces.. You could also fix your car with duct tape and bubblegum next time it breaks.. Don't yell at the mechanic when they told you to do it correctly..

                          Have Fun!

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S Online
                            stephenw10 Netgate Administrator
                            last edited by

                            Well this is getting out of hand! ๐Ÿ˜•

                            But I agree, the only reason you would want to be bridging the interfaces in pfSense is if you need to filter between the wired and wireless segments of the .1.X subnet.

                            You should be able to do this just using the vswitches in ESXi anyway. Just bring the connection to the AP in as a tagged port on whatever VLAN you configured for the additional SSID and and make that tagged on the LAN vswitch. All done no problem.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.