Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Move default LAN to a vlan

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 5 Posters 1.2k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN Offline
      NogBadTheBad @alan.t
      last edited by

      @alan-t said in Move default LAN to a vlan:

      @JKnott
      mmmm .... the LAN/vlan is going to a managed switch that does understand VLAN’s. Everything is plugged in to that switch, so that should not be a problem ?

      BRgds/Alan

      It’s what I do, I just don’t use LAGG.

      I changed the use of the LAN subnet for switch & AP management.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 0
      • A Offline
        alan.t
        last edited by

        Thanks for the input everyone, much appreciated.

        1 Reply Last reply Reply Quote 0
        • GrimetonG Offline
          Grimeton
          last edited by

          Hi,

          I might be a bit late to the party, but:

          There's no problem running the default management interface on a VLAN. This happens all the time, not just with pfSense.

          The only problem with pfSense is that it's a bit complicated to setup. You basically need an open terminal directly on the firewall and disable PF as well as reconfigure the interfaces manually in the console everytime you change something in the WebUI.

          Sadly you cannot create the VLAN interface add the IP-address and everything and do a final "Apply"-click. That'd be too easy I guess.

          It's a problem since day 1 of pfSense and was never addressed. But besides that it's a nice thing to have.

          KR,

          G.

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            alan.t @Grimeton
            last edited by

            @Grimeton .... can you elaborate a bit as to "why" ? I am certainly having trouble making it happen !

            1 Reply Last reply Reply Quote 0
            • GrimetonG Offline
              Grimeton
              last edited by

              IIRC the problem comes up when you have to move the IP address range around or something. At some point you have to make a step in the configuration where you have to apply the changes and this effectively disconnects you from the machine.

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                @alan-t said in Move default LAN to a vlan:

                I am told that it’s not recommended to mix tagged and untagged traffic in an LAGG interface ?

                You brought this up in another thread - do you have link to where you read this? As stated in the other thread. There is no such advice or recommendation that I am aware of.. Such advice doesn't make any sense.. You can for sure run 1 untagged vlan with other tagged vlans on the same interface, doesn't matter if its a lagg or a single interface.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                A 1 Reply Last reply Reply Quote 0
                • A Offline
                  alan.t @johnpoz
                  last edited by

                  @johnpoz Hello,
                  No, just on a youtube video that seems to be otherwise fairly solid. I have asked the guy to check for me, he did say it was in some Netgate documentation somewhere. However, looking like its either incorrect or out of date ...

                  Cheers/Alan

                  JKnottJ 1 Reply Last reply Reply Quote 0
                  • JKnottJ Offline
                    JKnott @alan.t
                    last edited by

                    @alan-t said in Move default LAN to a vlan:

                    No, just on a youtube video

                    Well, that's absolute proof then! 😉

                    BTW, I've seen some Youtube videos where the person obviously doesn't fully know what they're talking about.

                    Bottom line, an Ethernet frame is an Ethernet frame and all gear should pass it equally, with the exception of things like spanning tree, which don't make it past a switch.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    A 1 Reply Last reply Reply Quote 0
                    • A Offline
                      alan.t @JKnott
                      last edited by

                      @JKnott said in Move default LAN to a vlan:

                      Well, that's absolute proof then!

                      Yes, thats why I'm trying to get as much information as possible :)

                      Thanks for the information, very helpful.

                      BRgds/Alan

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        The comment that its easier to fail to untagged vs tagged is a valid statement.. And if your worried about vlan hopping ok... But unless you were in some DOD facility, or had to use known bad switches that drop traffic from tagged to untagged.. It not a "requirement"

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.