Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port tagging on APU2?

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    56 Posts 5 Posters 12.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bingo600B
      bingo600
      last edited by bingo600

      I suppose JKnott is taking over here
      He's repeating most of what i suggested

      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

      JKnottJ 1 Reply Last reply Reply Quote 1
      • JKnottJ
        JKnott @bingo600
        last edited by

        @bingo600

        No, just making sure he's not missing anything.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        bingo600B 1 Reply Last reply Reply Quote 1
        • bingo600B
          bingo600 @orangehand
          last edited by bingo600

          @orangehand

          Since you don't get the pfSense box as DNS servers on your WiFi clients , you must have changed the default DHCP Server settings.

          You haven't changed the DHCP Server Gateway option , have you ?

          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

          O 1 Reply Last reply Reply Quote 1
          • O
            orangehand @bingo600
            last edited by

            @bingo600 No - Screenshot 2020-11-28 at 19.05.29.png

            And to follow your checklist, I can ping the VLAN gateway when on the VLAN SSID. I cannot get any further than that.

            1 Reply Last reply Reply Quote 0
            • bingo600B
              bingo600
              last edited by bingo600

              Did you try to remove/disable the LAN block rule on the Guest Vlan ?
              Can you then ping the Lan IF , and/or a Lan device ?

              Something is fishy ....
              Smells of missing or wrong def-gw.

              But if you havent touched Anything besides what you have posted in the dhcp screenshot. PfSense should hand out the interface address as def-gw.

              And that you can ping.

              Hey ...

              That screenshot is not DHCP Server , that's the IF
              You haven't set any upstream gw on the if ... have you
              Dooh missed it was set to none

              If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

              pfSense+ 23.05.1 (ZFS)

              QOTOM-Q355G4 Quad Lan.
              CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
              LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

              O 1 Reply Last reply Reply Quote 0
              • O
                orangehand @bingo600
                last edited by

                @bingo600 I removed the custom DNS addresses from the DHCP server and that made no difference. What I am wondering is why the SG-1100 has a switch submenu in Interfaces to enable port tagging, and this APU2 does not. Might that be the crux of this?

                bingo600B 1 Reply Last reply Reply Quote 0
                • bingo600B
                  bingo600 @orangehand
                  last edited by bingo600

                  @orangehand said in Port tagging on APU2?:

                  @bingo600 I removed the custom DNS addresses from the DHCP server and that made no difference.

                  I expected that , as your DNS servers are on the INET , and INET can't be reached.

                  What I am wondering is why the SG-1100 has a switch submenu in Interfaces to enable port tagging, and this APU2 does not. Might that be the crux of this?

                  Nope .. I'm running a Unifi on a pfSense wo. switch menu , and JKnott does the same (see further up).

                  Your tagging is working , since you get a Guest Ip address (in Vlan 20)

                  Post a picture of your DHCP Server settings for Guest

                  You don't have any group or floating rules , do you ?

                  If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                  pfSense+ 23.05.1 (ZFS)

                  QOTOM-Q355G4 Quad Lan.
                  CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                  LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                  O 1 Reply Last reply Reply Quote 0
                  • O
                    orangehand @bingo600
                    last edited by

                    @bingo600 Screenshot 2020-11-28 at 19.28.17.png Anything not shown is default

                    bingo600B 1 Reply Last reply Reply Quote 0
                    • bingo600B
                      bingo600 @orangehand
                      last edited by bingo600

                      @orangehand

                      Then something is fishy ....

                      Did you remove the Lan block rule , and tried to ping lan IF and maybe a lan device.

                      Edit:

                      Now that you have removed the 9.9.9.9 & 1.1.1.1 as DNS , can you resolve DNS now?

                      I mean what does ie. ping dns.google.com show ?

                      Does it resolve like here , where it resolves to 8.8.4.4

                      $ ping dns.google.com
                      PING dns.google.com (8.8.4.4) 56(84) bytes of data.
                      

                      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                      pfSense+ 23.05.1 (ZFS)

                      QOTOM-Q355G4 Quad Lan.
                      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                      O 2 Replies Last reply Reply Quote 1
                      • O
                        orangehand @bingo600
                        last edited by orangehand

                        @bingo600 Yes. I can ping devices on both subnets from the guest subnet when that rule is disabled

                        bingo600B 1 Reply Last reply Reply Quote 0
                        • O
                          orangehand @bingo600
                          last edited by

                          @bingo600 and @JKnott You are stars for trying; thanks so much. I need to go out to dinner now. Any further thoughts much appreciated!

                          bingo600B JKnottJ 2 Replies Last reply Reply Quote 0
                          • bingo600B
                            bingo600 @orangehand
                            last edited by bingo600

                            @orangehand
                            Then def-gw ought to be set correct.

                            Can you ping the WAN IF ?

                            How is your outbound NAT set ?

                            ac2653fc-edab-42ae-814f-1671508b729f-image.png

                            Do you have "Auto created XXX to wan" for all the interfaces ?

                            Especially look at Guest , if it's missing there

                            Maybe post a screenshot

                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                            pfSense+ 23.05.1 (ZFS)

                            QOTOM-Q355G4 Quad Lan.
                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                            1 Reply Last reply Reply Quote 0
                            • bingo600B
                              bingo600 @orangehand
                              last edited by

                              @orangehand

                              Did you get this solved ?

                              If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                              pfSense+ 23.05.1 (ZFS)

                              QOTOM-Q355G4 Quad Lan.
                              CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                              LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                              O 1 Reply Last reply Reply Quote 0
                              • O
                                orangehand @bingo600
                                last edited by

                                @bingo600 No. Here is the Outbound NAT screenshot: Screenshot 2020-11-29 at 10.02.19.png

                                bingo600B 2 Replies Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @orangehand
                                  last edited by

                                  @orangehand said in Port tagging on APU2?:

                                  I need to go out to dinner now. Any further thoughts much appreciated!

                                  I like pizza. šŸ˜‰

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 0
                                  • JeGrJ
                                    JeGr LAYER 8 Moderator @orangehand
                                    last edited by

                                    @orangehand said in Port tagging on APU2?:

                                    On the Sg-1100 I set up yesterday there was a switch submenu in Interfaces where you added the tags. On my APU2 box there isn't a switch submenu so where do I do the tagging?

                                    Just for anyone else wondering: SG1100, 2100, 3100 and 7100 have built in Switch chipsets! Those ports are actually switched internally that's why they have a special pfsense version from Netgate to include the config of said switch chip. You don't have that on any other hardware!

                                    Other than that @JKnott and @bingo600 seem to have things under control, wouldn't want to intrude and confuse everyone :)

                                    Don't forget to upvote šŸ‘ those who kindly offered their time and brainpower to help you!

                                    If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                                    O 1 Reply Last reply Reply Quote 0
                                    • O
                                      orangehand @JeGr
                                      last edited by

                                      @JeGr Thanks for that! So in the absence of that switch config, how does one tag the lan interface so that VLAN traffic flows through it?

                                      JKnottJ 1 Reply Last reply Reply Quote 0
                                      • JKnottJ
                                        JKnott @orangehand
                                        last edited by

                                        @orangehand

                                        If you don't have a managed switch, you tag not only the LAN interface on pfsense, but also on every device you want to use the VLAN. This is easy enough to do with computers, but many other devices don't support VLANs.

                                        These days, go with managed switches. They're cheap, but avoid TP-Link.

                                        PfSense running on Qotom mini PC
                                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                        UniFi AC-Lite access point

                                        I haven't lost my mind. It's around here...somewhere...

                                        O 1 Reply Last reply Reply Quote 0
                                        • O
                                          orangehand @JKnott
                                          last edited by

                                          @JKnott all my switches are Unifi

                                          JKnottJ 1 Reply Last reply Reply Quote 0
                                          • JKnottJ
                                            JKnott @orangehand
                                            last edited by

                                            @orangehand

                                            I have a Unifi AP and a Cisco switch.

                                            PfSense running on Qotom mini PC
                                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                            UniFi AC-Lite access point

                                            I haven't lost my mind. It's around here...somewhere...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.