Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense between 2 Mikrotik VLAN cannot communicate ?

    Scheduled Pinned Locked Moved Cache/Proxy
    9 Posts 2 Posters 993 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FarukKosovali
      last edited by

      Hello,

      I have setup 2 VLANs between 2 mikrotik routers (1 for WAN and 1 for LAN) that communicates with each other through VLAN10. I put PfSense between these two routers. Now routers cannot communicate with each other and Pfsense acts as an Gateway. I want WAN router VLAN communicates with LAN router VLAN through Pfsense so I can filter their traffic.

      Can you help ? Any suggestions or guidance appreciated.

      Regards,

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Why would you put WAN and LAN on the same VLAN?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • F Offline
          FarukKosovali
          last edited by

          Dear Derelict,

          I have posted the Figure of my existing network and new network below. I provide internet connection to LAN through this VLAN (VLAN10) since this VLAN has configured for specific routes and queue targeting WAN-LAN connection and other networks. (PFSENSE.png image url)

          All I want is to prevent users accessing to some websites in my network without modifying any configuration of my Mikrotik Routers and VLANs.
          The Pfsense will sit between 2 routers but it should allow VLAN10 to communicate between 2 mikrotik routers so it will trace network activities and block specific connection requests (e.g. facebook, youtube, xxx sites etc..) between WAN and LAN network.

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Nonsensical. Sorry.

            What is your purpose.

            What are you trying to accomplish?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • F Offline
              FarukKosovali
              last edited by

              I want to filter the traffic for the VLAN10. That's why I want to use Pfsense. But WAN and LAN communicates each other through VLAN10 so when Pfsense intercepts the network it disconnects LAN from the Internet.

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                What do you mean filter? As a firewall or as a transparent filter?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • F Offline
                  FarukKosovali
                  last edited by

                  Yes, actually it will filter the incoming and outgoing traffic so LAN users will not be able to access Youtube, Facebook, or any other site that I will set as a rule.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    Look up transparent bridging/filtering.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • F Offline
                      FarukKosovali
                      last edited by

                      I will check out..Thank you so much.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.