Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense on esxi 6.7, can get it to work propperly.

    Scheduled Pinned Locked Moved Virtualization
    57 Posts 5 Posters 9.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      three
      last edited by

      I agree, something seems wrong with ESXI setup. Some screenshots could indeed help.

      Just to be on the safe side: Your test with Windows Server 2019 and Virtualbox involved the very same machine? On which you are now operating with ESXI? And you are using the very same physical ethernet port for LAN on this machine?

      1 Reply Last reply Reply Quote 0
      • M
        marcel1988
        last edited by marcel1988

        Yes this is the same machine with esxi 6.7 or with Windows server 2019.
        First off all let me explain this first.

        Since this CPU cant run vt-d i need to disable this at the start with: noiommu in the /bootbank/boot.cfg at the end of the line with kernelopt: http://www.digitalroadies.com/vmware-6-initializing-iov-issues/

        By default the realtek nic card is not working within ESXI so i need to install a driver for it:
        https://networkguy.de/installing-realtek-driver-on-esxi-6-7/

        After that i followed the tutorial: https://docs.netgate.com/pfsense/en/latest/virtualization/virtualizing-pfsense-with-vmware-vsphere-esxi.html for creating the WAN and LAN ports.

        i have made a couple of screenshots for you off the settings that i have made on the WAN - LAN and uploaded it here:
        https://imgur.com/a/IgPD7DU

        Dont mind the link down at the nics, that is correct becuase i have remove the cables.
        When i insert the cables the nics are up.

        I will make some more screenshot of the settings inside PfSense, and the Ubuntu vm.

        1 Reply Last reply Reply Quote 0
        • M
          marcel1988
          last edited by

          Sorry,

          The WAN is a wrong setting. this is the right setting for the WAN.
          It's the WAN of the vmnetwork of the onboard NIC of the motherboard,10.JPG

          1 Reply Last reply Reply Quote 0
          • M
            marcel1988
            last edited by

            and here are some screenshots.

            you can see that the ubuntu instalation on ESXI is working perfectly with internet access.
            it running on the DHCP lease of 10.0.0.X.

            You can also see that my Windows 10 laptop and my Synology NAS wich are connected trough LAN cable on the NIC are not getting the right IP address. so there is no DHCP.

            https://imgur.com/a/ZDUSXnm

            1 Reply Last reply Reply Quote 0
            • T
              three
              last edited by three

              Are both, network adapter 1 and 2, realteks?

              EDIT 1:
              Just saw that wan and lan are Realtek, but VMNetwork is Intel.

              Need to look again ...

              EDIT 2:

              At the time it works, does your WAN (Network Adapter 1) is set to VM Network or WAN?

              M 1 Reply Last reply Reply Quote 0
              • M
                marcel1988 @three
                last edited by

                @three

                It only works when i set the WAN on VM Network.
                When i set it on WAN it wont work.

                1 Reply Last reply Reply Quote 0
                • T
                  three
                  last edited by three

                  Then it is related to the realteks. You somehow need to validate whether they operate properly in ESXI at all. Another option could be, as mentioned by @kiokoman, to change to vmxnet3 in pfsense-VM-settings of ESXI.

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by

                    yeah in any case realtek card are never a good choice for this stuff

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    1 Reply Last reply Reply Quote 0
                    • M
                      marcel1988
                      last edited by

                      ok.

                      In the meantime i have tried to run PfSense directly installed on a SSD.
                      That is running fine, and working woth both the INTEL nic for the WAN and the realtek as the LAN.

                      The devices that are attached trough a LAN kabel are getting 10.0.0.X and internet access,
                      When i tried it with windows 2019 its working perfect without a problem. So i think i need to consider to leave ESXI for what it is. or try a different hyperviser OS.

                      i only want to use it for:

                      1x windows server machine
                      1x firewall machine
                      2-3 linux machines.

                      Any thought?

                      1 Reply Last reply Reply Quote 0
                      • kiokomanK
                        kiokoman LAYER 8
                        last edited by

                        change that realtek card to some intel they are cheap on ebay / amazon after all ☺

                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                        Please do not use chat/PM to ask for help
                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                        1 Reply Last reply Reply Quote 1
                        • T
                          three
                          last edited by

                          Exactly what I would recommend as well. It would cost only a few bucks and will work right out of the box with ESXI. Otherwise you need to spend countless hours or days to get into another hypervisor. Do the math to your liking :)

                          1 Reply Last reply Reply Quote 1
                          • M
                            marcel1988
                            last edited by marcel1988

                            Thank you both for the help :) i will buy a Intel card ;)

                            I just found one of these: https://ark.intel.com/content/www/us/en/ark/products/184824/intel-ethernet-network-adapter-i350-t4-for-ocp-3-0.html for €20 euro.

                            Will this one work?

                            1 Reply Last reply Reply Quote 0
                            • G
                              gcu_greyarea
                              last edited by

                              With ESXi have you tried putting the LAN vSwitch and Port Group into promiscuous mode ?

                              1 Reply Last reply Reply Quote 0
                              • M
                                marcel1988
                                last edited by

                                ok so, i bought this https://ark.intel.com/content/www/us/en/ark/products/184824/intel-ethernet-network-adapter-i350-t4-for-ocp-3-0.html inserted it in the ESXI and booted up. It works perfectly.

                                So now it is running and working like this:

                                Fiber optic > Ubiquiti USG router WAN > Ubiquiti USG router LAN > network port NIC ESXI WAN > network port NIC ESXI LAN > Network switch and accespoint in the house. ( 10.0.0.X range. ) this is working perfect.

                                But i want to remove the Ubiquiti usg router so i can setup the fiber optic directly into the WAN port of the NIC of the ESXI.
                                so i'm working with T-Mobile here in here in the Netherlands. and i have added the VLAN 300 for internet into the PfSense on the interface of the WAN port of the NIC:
                                1.JPG

                                Under interfaces > assigment i have put the new VLAN300 into the WAN:
                                2.JPG
                                But i dont get a IP from the DHCP server of my ISP provider.

                                When i set it back on the normal settings, everything is working perfect and i get a 192.168.1.2 from the Ubiquiti USG.
                                3.JPG

                                1 Reply Last reply Reply Quote 0
                                • kiokomanK
                                  kiokoman LAYER 8
                                  last edited by kiokoman

                                  under esxi did you set the vswitch to vlanid 4095 ?
                                  Immagine.jpg

                                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                  Please do not use chat/PM to ask for help
                                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    marcel1988
                                    last edited by

                                    So i need to edit this one:
                                    40714351-02a8-4df8-a44a-ef2c016611c7-image.png This is the nic port that is comming from the fiber optic.

                                    And can you tell me WHY i need to add VLAN 4095?

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      three
                                      last edited by three

                                      This is a specific of ESXI. If empty, VLAN are NOT supported. 4095 allows ALL VLAN numbers from the VM. I still get confused about VLAN, tagged, untagged, etc. But this should work,

                                      1 Reply Last reply Reply Quote 0
                                      • kiokomanK
                                        kiokoman LAYER 8
                                        last edited by

                                        indeed 4095 means that you set your vswitch as a trunk port letting any vlan pass through

                                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                        Please do not use chat/PM to ask for help
                                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          marcel1988
                                          last edited by

                                          Yes, this did the trick :)

                                          1 Reply Last reply Reply Quote 0
                                          • M
                                            marcel1988
                                            last edited by

                                            so after a few day's working perfectly.
                                            it now randomly stops working.

                                            In the PfSense VM i see this:
                                            c976ee3a-a7be-4787-8189-6d7008e1c6b1-image.png

                                            When i reboot the VM everything works again.
                                            What can this be?

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.