Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN connectivity Issue

    Scheduled Pinned Locked Moved Firewalling
    vlancisco switch
    4 Posts 3 Posters 700 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jcubio
      last edited by

      Hi All,

      I'm trying to set up a VLAN in our network using pFsense and cisco switches. The VLAN is to be used for guest wifi.

      Please see the diagram for the setup.
      vlan issue.jpg
      PFsense Config:
      pfsense vlan.png
      firewall.png
      Switch Config:

      SW1 VLAN and PORT Assignment
      vlan.png
      sw1 port.png
      In pfSense, the Guest VLAN interface has the DHCP Server enabled and the laptop is able to get the IP address.

      Behavior:

      1. Laptop can't ping the gateway, can't connect to the internet.
      2. Firewall can ping the laptop
      3. My workstation from default VLAN 1 can ping the gateway and the laptop
      4. Firewall logs, default deny rule is blocking traffic from laptop's ip
        firewall log.png

      Please advice
      Thank you

      1 Reply Last reply Reply Quote 0
      • D
        drehmini
        last edited by drehmini

        Your screenshot your Firewall rule only allows IPv4 TCP you'll want to change this to IPv4 - Any Protocol, not just TCP.

        1 Reply Last reply Reply Quote 1
        • J
          jcubio
          last edited by

          Found the issue, Disabled the captive portal and it now works.
          Now I need to work with the captive portal.

          1 Reply Last reply Reply Quote 1
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            While captive portal could be blocking.. You clearly have issue there with only allowing tcp.. Unless your client is doing doh or dot there is now way he could get any dns.. DNS runs on UDP 53..

            You can see right there in your block 53 to 8.8.8.8 was blocked.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.