Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port tagging on APU2?

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    56 Posts 5 Posters 12.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      orangehand
      last edited by

      On my APU2 box there is no Switch GUI in the Interfaces menu. How do I take the LAN port with a VLAN?
      Many thanks

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @orangehand
        last edited by

        @orangehand
        https://forum.netgate.com/post/944426

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        1 Reply Last reply Reply Quote 0
        • O
          orangehand
          last edited by

          Forgive me if I am being stupid but I don't understand what you are specifically pointing me to.
          I get that you:
          Create VLAN
          Add it to an interface
          Add a DHCP server to it
          Add a pass rule
          But then you have to tag the LAN network port don't you?

          On the Sg-1100 I set up yesterday there was a switch submenu in Interfaces where you added the tags. On my APU2 box there isn't a switch submenu so where do I do the tagging?

          bingo600B JeGrJ 2 Replies Last reply Reply Quote 0
          • bingo600B
            bingo600 @orangehand
            last edited by bingo600

            @orangehand said in Port tagging on APU2?:

            But then you have to tag the LAN network port don't you?

            pfSense can do tagging on an interface, meaning you can transport several vlan(s) data ... down the same wire.
            But i'm not sure if you can do something like "native vlan"

            On a switch you can make an interface an untagged member of a VLAN.
            That i'm not sure you can do on a "Non-Switch interface" ..
            I know of no way to do it.

            I describe a bit aboyt tagging here
            https://forum.netgate.com/post/944383

            On the Sg-1100 I set up yesterday there was a switch submenu in Interfaces where you added the tags. On my APU2 box there isn't a switch submenu so where do I do the tagging?

            You might want to start with what you want to achieve here.

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            • O
              orangehand
              last edited by

              I just want to get a guest VLAN working. The devices get an IP via the tagged SSID on Unifi, but no traffic passes

              JKnottJ 1 Reply Last reply Reply Quote 0
              • O
                orangehand
                last edited by

                Screenshot 2020-11-28 at 17.53.21.png Screenshot 2020-11-28 at 17.50.03.png image url)

                1 Reply Last reply Reply Quote 0
                • bingo600B
                  bingo600
                  last edited by bingo600

                  Do they get an ip belonging to Guest Vlan , or Lan ?

                  If you have Lan & Guest Vlan on the same IGB1 port , how do you connect both the Lan devices and the Unifi AP ... (To the same port) ??

                  If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                  pfSense+ 23.05.1 (ZFS)

                  QOTOM-Q355G4 Quad Lan.
                  CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                  LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                  1 Reply Last reply Reply Quote 0
                  • O
                    orangehand
                    last edited by

                    Guest VLAN

                    1 Reply Last reply Reply Quote 0
                    • bingo600B
                      bingo600
                      last edited by bingo600

                      Don't you have a spare port in the APU , for the Unifi ?
                      How do you connect that AP

                      Are you using a switch also ?

                      Right now you are transporting on (IGB1)
                      LAN - Untagged
                      Guest - Tagged Vlan20

                      It should work for your wifi ...

                      But how do you connect LAN devices ??

                      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                      pfSense+ 23.05.1 (ZFS)

                      QOTOM-Q355G4 Quad Lan.
                      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                      1 Reply Last reply Reply Quote 0
                      • O
                        orangehand
                        last edited by

                        I want the untagged normal traffic AND the tagged VLAN traffic to be sent to the switches and the APs, and just the guest access via Wifi by choosing the relevant SSID (if that make sense!)

                        bingo600B 1 Reply Last reply Reply Quote 0
                        • bingo600B
                          bingo600 @orangehand
                          last edited by bingo600

                          @orangehand

                          If you have setup a switch correct to receive untagged (lan) and Tagged vlan20,
                          that would make sense.

                          Then you have another switch port where the unifi is connected ?

                          Are you running tagged vlans to the Unifi (ssids)

                          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                          pfSense+ 23.05.1 (ZFS)

                          QOTOM-Q355G4 Quad Lan.
                          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                          1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @orangehand
                            last edited by

                            @orangehand said in Port tagging on APU2?:

                            I just want to get a guest VLAN working. The devices get an IP via the tagged SSID on Unifi, but no traffic passes

                            I recently set up a Unifi AP with pfsense on an old computer. I had previously set it up for another AP, but it works the same. You add a VLAN to the pfsense interface and use the same VLAN ID at the AP. If you have a managed switch in between, you will also have to configure the same VLAN on the ports connected to pfsense and the AP.

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • O
                              orangehand
                              last edited by

                              That is already set up - Guest SSID with a VLAN tag of 20. A device connected to that SSID gets an IP from the right DHCP pool, but the traffic doesn't get out of the LAN, hence it's useless!

                              bingo600B JKnottJ 2 Replies Last reply Reply Quote 0
                              • bingo600B
                                bingo600 @orangehand
                                last edited by bingo600

                                @orangehand said in Port tagging on APU2?:

                                That is already set up - Guest SSID with a VLAN tag of 20. A device connected to that SSID gets an IP from the right DHCP pool, but the traffic doesn't get out of the LAN, hence it's useless!

                                I suppose you mean WAN ??

                                Can you ping the pfSense Guest interface from a Wifi client ?
                                Can you ping 8.8.8.8

                                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                pfSense+ 23.05.1 (ZFS)

                                QOTOM-Q355G4 Quad Lan.
                                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                O 1 Reply Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @orangehand
                                  last edited by

                                  @orangehand said in Port tagging on APU2?:

                                  That is already set up - Guest SSID with a VLAN tag of 20. A device connected to that SSID gets an IP from the right DHCP pool, but the traffic doesn't get out of the LAN, hence it's useless!

                                  Here's what I have for my rules:

                                  Screenshot_20201128_131914.png

                                  These work well. They block the guest from accessing anything on my network, other than pinging the VLAN3 interface.

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  O 1 Reply Last reply Reply Quote 0
                                  • O
                                    orangehand @bingo600
                                    last edited by

                                    @bingo600 Yes, I meant out from the LAN to the WAN

                                    bingo600B 1 Reply Last reply Reply Quote 0
                                    • bingo600B
                                      bingo600 @orangehand
                                      last edited by

                                      @orangehand

                                      We are talking about the WiFi clients , that cant access the internet ??
                                      Or did you mean LAN ?

                                      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                      pfSense+ 23.05.1 (ZFS)

                                      QOTOM-Q355G4 Quad Lan.
                                      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                      O 1 Reply Last reply Reply Quote 0
                                      • O
                                        orangehand @JKnott
                                        last edited by

                                        @JKnott I'm pretty sure it isn't rules that is the issue. Yours are simply rather more elegant versions of mine! I still cannot get onto the Internet from the guest vlan

                                        bingo600B 1 Reply Last reply Reply Quote 1
                                        • bingo600B
                                          bingo600 @orangehand
                                          last edited by

                                          @orangehand
                                          And you're sure it's not an DNS issue ?

                                          can you ping : dns.google.com
                                          does it resolve ?

                                          Can you ping : 8.8.4.4

                                          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                          pfSense+ 23.05.1 (ZFS)

                                          QOTOM-Q355G4 Quad Lan.
                                          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                          O 1 Reply Last reply Reply Quote 0
                                          • O
                                            orangehand @bingo600
                                            last edited by

                                            @bingo600 Yes, Wifi clients. (sorry for delay - it's not letting me post more than once every 2 mins)

                                            bingo600B 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.