Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1 vlan over 2 switches

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    31 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @michael178212
      last edited by

      @michael178212 said in 1 vlan over 2 switches:

      But if i need a ap that can handle vlans then I best get looking haha

      As I mentioned, should you go that route, avoid TP-Link. Some of their gear doesn't work properly with VLANs. This applies to both APs and managed switches.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • M
        michael178212
        last edited by

        Thanks guys, got it all well sort of working now.

        Both switches that I've assigned a port to vlan2 work so what gets plug into it is on vlan2 and has the subnet 10.10.10.1/24 which is what I wanted. Only problem I have which I find a tad weird is if i connect to the wifi ap downstairs first then I connect, if I walk upstairs then my phone connects to the wifi ap upstairs as i was hoping for and works but the weird part is if I'm upstairs and disconnect my phone from the wifi and then reconnect then I can't connect and dont get assigned an ip but If I go downstairs I can connect

        As the vlan side of it is working the I'm Putting it down to the fact I'm using bt routers as aps and not proper aps.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Did you change the PVID of the ports that you moved to new vlan... You would hope the switch would auto do that, but you might have to change do it by hand... Make sure whatever vlan you put a port in that is untagged, that you change the pvid of that port to the vlan you assign untagged.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • M
            michael178212
            last edited by

            vlans setup

            Downstairs switch

            port 1 is tagged ( trunk between both switchs )
            Port 2 is tagged and goes to pfsense.
            Port 8 is untagged, goes to the wifi
            All other ports are left untagged

            Upstairs switch

            Port 1 is tagged ( trunk )
            Port 8 is untagged and goes to wifi
            Port 7 is untagged and is for unraid
            All other ports are left untagged

            Only ports that have a pvid are ports 8 on both switch which have are pvid 2 and port 7 of the upstairs switch which has a pvid of 20

            If this helps

            Downstairs switch

            Port 1 - 2 - 8 are in vlan2. Ports 1 and 2 are tagged, port 8 untagged and has pvid2

            Ports 1 and 2 are tagged and are in vlan20

            Upstairs switch

            Ports 1 and 8 are in vlan2 port 1 tagged and 8 untagged with 8 having pvid2

            Ports 1 and 7 are in vlan20 with port 1 being tagged and 7 untagged and has pvid20

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              @michael178212 said in 1 vlan over 2 switches:

              if I'm upstairs and disconnect my phone from the wifi and then reconnect then I can't connect and dont get assigned an ip

              When you say can't connect - you mean you can not auth and connect to the wifi, or you actually connect to the wifi but just don't get an IP and end up with 169.254.x.x as your IP?

              If you can not actually auth and associate to the wifi, then no you wouldn't get an IP.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • M
                michael178212
                last edited by

                My phones tries to connect as it says connecting but just dosnt connect both passwords are the same and ssids along with same WPA encryption. After a few attempts it gives me a 'cant get ip' message and ask me to reboot router.

                Would this work.

                Make another vlan Id from the downstairs switch. Connect another ethernet cable from the wifi router to the switch and then just trunk my up to the other wifi router upstairs?

                So it'll go like this

                Downstairs switch

                Vlan2 ports 2 and 8, 2 being tagged and going into pfsense and 8 being untagged and going into wifi router with pvid2 ( as that's setup in pfsense )

                Make a new vlan so let's call this one vlan50
                Vlan50 has ports 7 and 1. 1 being trunk and tagged and 7 being tagged and goes into a spare port of the wifi router

                Upstairs switch

                Make a new vlan, vlan50

                Ports 1 and 8 in vlan50 with 1 be tagged ( trunk ) and 8 being untagged and going into wifi router ?

                Didnt think itll be this hard

                1 Reply Last reply Reply Quote 0
                • M
                  michael178212
                  last edited by

                  Or am I just over complicating things and the actual setup of the vlans are correct and it can just be somthing to do with the wifi routers

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    @michael178212 said in 1 vlan over 2 switches:

                    gives me a 'cant get ip' message and ask me to reboot router.

                    When you do that look on pfsense - do you see a discover for IP or request... Pfsense can not hand out an IP if doesn't see the discover or request...

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • M
                      michael178212
                      last edited by

                      In system logs under dhcp I'm getting dhcp requests and dhcpacks but have had a few of this messages

                      uid lease 10.10.10.103 for client a8:db:03:e4:a9:5a is duplicate on 10.10.10.0/24

                      Am I right in thinking that this is basically saying. You cant give that mac address ( my phones mac address ) that ip as it already has an ip ( static 10.10.10.10) ? If so then this would stop the ip from being released wont it or am I completely wrong lol?

                      1 Reply Last reply Reply Quote 0
                      • M
                        michael178212
                        last edited by

                        Now I'm home, I've looked at the logs again and I do have some dhcp discoverys, offers, requests and acks but still have that duplicate message. So what I ll try is disconnect the downstairs wifi router and see what the logs say.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          @michael178212 said in 1 vlan over 2 switches:

                          a8:db:03:e4:a9:5a

                          Who owns this mac - what device is it? Look up shows its a Samsung device
                          https://hwaddress.com/oui-iab/A8-DB-03/

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • M
                            michael178212
                            last edited by

                            Sorry yeah it's a samsung phone.. just tried how I said I would and with just one ( upstairs wifi router ) connected, my phone will connect to the wifi and on the right subnet but without internet. Tried changing dns, that didnt work so not a dns issue.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.