Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to send LAN w/DHCP over both a NIC and a vLAN on another nic?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    13 Posts 4 Posters 1.2k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      lburns
      last edited by

      So you're right.

      However that would prevent me from managing the networking from the one pane of glass that PFsense provides.

      It's worth noting that no vLANS are in use at this time, and i'm trying to use a vLAN to deliver the LAN alongside the Wireless network.

      All the networks are all on default vLAN for their interface.

      Also note that the WAP is connected DIRECTLY to the ESXi server NIC port and does not go through a switch.

      I suppose I should start thinking about a redeployment using a vLAN based setup, but I was trying to adhere to the design principle of keeping firewall and network management tasks as close to the experience of using a physical firewall server as possible.

      Any more thought on this?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        To get both networks on the AP even directly connected you'll still have to tag VLANs.

        And the only thing you lose by handling it at L2 is being able to filter wireless users on LAN separately from users on the regular LAN, and if you're doing that, why bother putting them in the same subnet at all? Just keep them isolated.

        Bridging on the firewall is ugly. Avoid it at all costs.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        L 1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          esxi vswitches/portgroups will not strip tags if you set the vlan id to 4095.. Then you can bring in a untagged network and tagged network into a vnic on pfsense..

          This would allow you to handle your network native and vlans at pfsense.. How you connect them into pfsense is the big question.. If your to the point you want to play with vlans - then your at the point to get yourself a vlan capable switch to use..

          You can get a vlan capable switch for like $30..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

          L 1 Reply Last reply Reply Quote 0
          • L Offline
            lburns @jimp
            last edited by

            @jimp the ultimate issue is that the home theater gear at this site is driven by Logitech Harmony remote hub units. these ONLY have WiFi access - not wired.

            Whereas the media servers and rokus are all on the WIRED network to ensure 4K strems properly to all devices.

            (This is a 10Gb switched infrastructure)

            The Rokus cannot take controls from the Harmony units due to routing incompatibilities on the logitech side.

            This is why I need to have the LAN present as a separate SSID beside the WiFi network.

            :(

            1 Reply Last reply Reply Quote 0
            • L Offline
              lburns @johnpoz
              last edited by

              @johnpoz you called out the wall i ran smack into...

              I can get the vLAN out to the WAP from the firewall but how I connect it to the existing LAN is maddening.

              1 Reply Last reply Reply Quote 0
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                My roku is wired and not on the same wifi network s the harmony hub..

                Not sure what any of that has to do with the price of tea??

                GET A SWITCH!!!!

                Trunk run whatever vlans you want into the esxi nic, set the portgroup to 4095 and let pfsense handle the vlans.

                This is all basic networking 101 with the addition of simple 30$ switch that support vlans. Allow you to run uplinks on native untagged into different esxi nics or tagged, have devices on any vlan you want. Or uplinks that are tagged can carry multiple networks to the devices that will isolate them like other switches or AP.. Where you could have as many ssid on different vlans you want and them put any wired device on any network you want as well.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                L 1 Reply Last reply Reply Quote 0
                • L Offline
                  lburns @johnpoz
                  last edited by

                  @johnpoz It is related because as I mentioned before, the wired Roku on LAN (.1 network) does not receive commands from the Harmony Hub which lives on the WAP (.2) network without a 5-10 second delay.

                  This is a known issue at Logitech and many have issues with this.

                  The only solution at this time is to ensure the two devices are on the same network.

                  I understand what you say about the switch, however I would like to have been able to simply ride the LAN on an extra vLAN using the current setup without having to go on site and install more gear when it shouldn't be necessary.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Its not EXTRA anything... Its how you do networking... You have an AP that does vlans - you need a switch that does vlans. You don't use freaking interfaces as switch ports.

                    You clearly can afford a freaking 30$ switch to do it CORRECTLY!!!

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                    L 1 Reply Last reply Reply Quote 0
                    • L Offline
                      lburns @johnpoz
                      last edited by

                      @johnpoz

                      wow.

                      I'm surprised your a moderator.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        So am I to be honest!! ;)

                        Some times I wonder why I am even still here after 10+ years of the same shit over and over and over again..

                        You clearly can afford 30$ switch with the gear you have... To do something CORRECTLY being told you by 2 people that do networking for a living.. Myself have been in the business before there were even switches..

                        You want to do vlans.. This is your statement... You need to connect multiple devices = Vlan capable switch! Period!!

                        How is that difficult to understand. Sure you go ahead and bridge 2 of your 6 interfaces.. You could also fix your car with duct tape and bubblegum next time it breaks.. Don't yell at the mechanic when they told you to do it correctly..

                        Have Fun!

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Well this is getting out of hand! ๐Ÿ˜•

                          But I agree, the only reason you would want to be bridging the interfaces in pfSense is if you need to filter between the wired and wireless segments of the .1.X subnet.

                          You should be able to do this just using the vswitches in ESXi anyway. Just bring the connection to the AP in as a tagged port on whatever VLAN you configured for the additional SSID and and make that tagged on the LAN vswitch. All done no problem.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.