Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need help setting up VLANs (pfsense router, unifi switch, AP-AC-PRO WAP)

    L2/Switching/VLANs
    4
    8
    665
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      codybadger
      last edited by

      Hi All,

      I'm looking to get some support on setting up my first VLAN. I figured the easiest way to do this was to try and make a guest WIFI network on a VLAN. The problem I'm having is that when I connect a device to my VLAN, it will receive an IP address from the pfsense DHCP service, but it won't have any access to the internet. I can ping devices on the same VLAN, on my private LAN (that's on a different subnet), and ping from my private LAN to a device on the VLAN. I just can't load anything from the outside world.

      I've followed these two tutorials:

      • https://www.youtube.com/watch?v=hhPGN4UJHAM
      • https://www.youtube.com/watch?v=b2w1Ywt081o

      They're both pretty straightforward, and I'm pretty sure I've set everything up correctly. The VLAN I'm trying to setup is called "GUEST" and is on the 192.168.55.x subnet. My LAN interface passes me to the internet fine. I'm also running the pfBlocker ad blocking package and run an openVPN.

      Here are a few screenshots of my setup. I figured there's a setting somewhere that I've got wrong, and hoping someone here can help me find it.

      VLAN interface setup:

      6ae75436-bd7f-4c0a-94dd-7f8b22d465c6-image.png

      VLAN firewall rules:

      43010cbb-bb38-4b01-8972-a27b1339c800-image.png

      VLAN DHCP service:

      9b2891ac-8df6-40ee-8a91-5c49c6de1281-image.png

      Outbound NAT Rules (I don't really know what this is - noticed there isn't anything here about the 192.168.55.x subnet, possibly the culprit?):

      4b258efa-7af1-4348-a0ec-4122dfbb2ef3-image.png

      Unifi networks:

      399cd07a-bba7-401d-8c5d-93cea55fb02b-image.png

      Unifi WIFI networks:

      b43b23db-0a3c-4d64-b6b8-8083a68ca6f1-image.png

      Anyway, would love some help/input if anyone has some time. Let me know what else you need to know.
      Thank you!

      JKnottJ V 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @codybadger
        last edited by

        @codybadger

        You'll need a route to get to the Internet and also a rule to allow it.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @codybadger
          last edited by

          @codybadger
          You're missing an Outbound NAT rule on WAN for that VLAN.
          Why do you have your Outbound NAT in manual mode?

          1 Reply Last reply Reply Quote 0
          • C
            codybadger
            last edited by

            @JKnott and @viragomann thanks for the responses.

            so would that be a duplicate of my fifth (from top) NAT rule, but for 192.168.55.x instead of 44? I did try that, but it didn't seem to work for me either.

            V 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              @viragomann said in Need help setting up VLANs (pfsense router, unifi switch, AP-AC-PRO WAP):

              Why do you have your Outbound NAT in manual mode?

              Because most of the idiot vpn service guides say to do that - arrrgghhhh!!!

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • C
                codybadger
                last edited by

                @johnpoz yes, that's exactly what happened. I kind of set the NAT up without really knowing what it means.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  @codybadger said in Need help setting up VLANs (pfsense router, unifi switch, AP-AC-PRO WAP):

                  without really knowing what it means.

                  Yup that is part of the problem for sure - also the fact that the idiots writing the guides don't have a clue either ;)

                  You can tell that from shit like this..

                  idiot.jpg

                  WTF!! No your not going to use your self signed web gui cert as your auth client cert - JFC!!! That should be the cert they give, you, or be set to none if just using username/password..

                  That anyone thinks these are companies that have any clue to security at all is just beyond me...

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @codybadger
                    last edited by

                    @codybadger said in Need help setting up VLANs (pfsense router, unifi switch, AP-AC-PRO WAP):

                    so would that be a duplicate of my fifth (from top) NAT rule, but for 192.168.55.x instead of 44? I did try that, but it didn't seem to work for me either.

                    This is for outgoing over the WAN. If it should also work when the OpenVPN client is connected (assuming it's the default gateway then) you need an additional rule for OpenVPN like the sixth one.
                    However, it's recommended to assign an interface to the OpenVPN client instance first and add the outbound NAT rule to this specific interface, cause OpenVPN is an interface group which covers all OpenVPN instances you're running, i.e. all clients and all servers.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.