Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN and that dirty word... *bridges*

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 1.0k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O Offline
      OGsadpanda
      last edited by

      basically using this

      Wireless Access Points with pfSense

      with vlans... (38min mark or so)

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @OGsadpanda
        last edited by

        @OGsadpanda said in VLAN and that dirty word... *bridges*:

        Create desired VLANs one by one on all desired interfaces with no ip address (mgmt vlan10/vpn vlan20 on interface igb1/2/3, wifi guest/iot only on igb2/3)
        bridge the VLANs together

        You bridge all together? So why did you create separate VLANs?

        @OGsadpanda said in VLAN and that dirty word... *bridges*:

        but vlan pass rules are not working.

        Why vlan rules? It should be a bridge rules? You have added your rules to the bridge, didn't you? How want you separate the VLANs here?

        1 Reply Last reply Reply Quote 0
        • O Offline
          OGsadpanda
          last edited by OGsadpanda

          not everything bridged, bridges just created across each vlan

          ie bridge0 = VL10_igb1, VL10_igb2, VL10_igb3

          so one set of rules (and subnet) would apply to bridge

          sorry, not 'vlan' pass rules at that point, 'bridge' pass rules

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Put your APs on switch ports.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            O 1 Reply Last reply Reply Quote 0
            • O Offline
              OGsadpanda @Derelict
              last edited by

              @Derelict

              I found this answer you posted a while back
              https://forum.netgate.com/topic/75815/wifi-and-lan-on-same-subnet-solved/33

              which seems like what I have operating now... I just cant get vlans to work 'as is' with tuneables and no firewall rules on the member.

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by Derelict

                If you have a switch you should use it and not do silly bridging.

                If you insist on using a wireless card like that and want the wireless and wired on the same broadcast domain you have no choice but to bridge them.

                You have a MUCH BETTER choice which is to just use the switch for that which it is intended and designed to do.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, I expect that to work. Though there can always be strangeness when bridges are involved.

                  What won't work is bridging the parent interfaces in an attempt to carry all the vlans. I've tried it.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • O Offline
                    OGsadpanda
                    last edited by

                    I'm not using wireless cards, I'm using wireless APs and switches that are vlan capable and have a router/pf device with multiple ports.

                    Im a self proclaimed n00b but it seems to me that for a software router, a bridge is like adding all<>all rule with broadcasting across all specified interfaces.

                    The goofy rule catching I'm seeing makes me think the vlan tags are not persistent in this situation.

                    So.... Why sell hardware that has multiple ports and/or have the option to bridge or the software tuneables if it doesn't work

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      There is also the potential for broadcast domain "leakage" between VLANs. pfSense bridges are not switches and should not be used as such. It is, in general, a Bad Idea (tm).

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        There are legitimate reasons for bridges such as bridging two interfaces to create a transparent proxy. That is a legitimate purpose (and it works just fine).

                        You are attempting the equivalent of driving a screw with a carrot. Your switch is a perfectly good screwdriver and it's right over there.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.