Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port tagging on APU2?

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    56 Posts 5 Posters 12.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      orangehand @bingo600
      last edited by

      @bingo600 Screenshot 2020-11-28 at 19.28.17.png Anything not shown is default

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @orangehand
        last edited by bingo600

        @orangehand

        Then something is fishy ....

        Did you remove the Lan block rule , and tried to ping lan IF and maybe a lan device.

        Edit:

        Now that you have removed the 9.9.9.9 & 1.1.1.1 as DNS , can you resolve DNS now?

        I mean what does ie. ping dns.google.com show ?

        Does it resolve like here , where it resolves to 8.8.4.4

        $ ping dns.google.com
        PING dns.google.com (8.8.4.4) 56(84) bytes of data.
        

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        O 2 Replies Last reply Reply Quote 1
        • O
          orangehand @bingo600
          last edited by orangehand

          @bingo600 Yes. I can ping devices on both subnets from the guest subnet when that rule is disabled

          bingo600B 1 Reply Last reply Reply Quote 0
          • O
            orangehand @bingo600
            last edited by

            @bingo600 and @JKnott You are stars for trying; thanks so much. I need to go out to dinner now. Any further thoughts much appreciated!

            bingo600B JKnottJ 2 Replies Last reply Reply Quote 0
            • bingo600B
              bingo600 @orangehand
              last edited by bingo600

              @orangehand
              Then def-gw ought to be set correct.

              Can you ping the WAN IF ?

              How is your outbound NAT set ?

              ac2653fc-edab-42ae-814f-1671508b729f-image.png

              Do you have "Auto created XXX to wan" for all the interfaces ?

              Especially look at Guest , if it's missing there

              Maybe post a screenshot

              If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

              pfSense+ 23.05.1 (ZFS)

              QOTOM-Q355G4 Quad Lan.
              CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
              LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

              1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @orangehand
                last edited by

                @orangehand

                Did you get this solved ?

                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                O 1 Reply Last reply Reply Quote 0
                • O
                  orangehand @bingo600
                  last edited by

                  @bingo600 No. Here is the Outbound NAT screenshot: Screenshot 2020-11-29 at 10.02.19.png

                  bingo600B 2 Replies Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @orangehand
                    last edited by

                    @orangehand said in Port tagging on APU2?:

                    I need to go out to dinner now. Any further thoughts much appreciated!

                    I like pizza. šŸ˜‰

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • JeGrJ
                      JeGr LAYER 8 Moderator @orangehand
                      last edited by

                      @orangehand said in Port tagging on APU2?:

                      On the Sg-1100 I set up yesterday there was a switch submenu in Interfaces where you added the tags. On my APU2 box there isn't a switch submenu so where do I do the tagging?

                      Just for anyone else wondering: SG1100, 2100, 3100 and 7100 have built in Switch chipsets! Those ports are actually switched internally that's why they have a special pfsense version from Netgate to include the config of said switch chip. You don't have that on any other hardware!

                      Other than that @JKnott and @bingo600 seem to have things under control, wouldn't want to intrude and confuse everyone :)

                      Don't forget to upvote šŸ‘ those who kindly offered their time and brainpower to help you!

                      If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                      O 1 Reply Last reply Reply Quote 0
                      • O
                        orangehand @JeGr
                        last edited by

                        @JeGr Thanks for that! So in the absence of that switch config, how does one tag the lan interface so that VLAN traffic flows through it?

                        JKnottJ 1 Reply Last reply Reply Quote 0
                        • JKnottJ
                          JKnott @orangehand
                          last edited by

                          @orangehand

                          If you don't have a managed switch, you tag not only the LAN interface on pfsense, but also on every device you want to use the VLAN. This is easy enough to do with computers, but many other devices don't support VLANs.

                          These days, go with managed switches. They're cheap, but avoid TP-Link.

                          PfSense running on Qotom mini PC
                          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                          UniFi AC-Lite access point

                          I haven't lost my mind. It's around here...somewhere...

                          O 1 Reply Last reply Reply Quote 0
                          • O
                            orangehand @JKnott
                            last edited by

                            @JKnott all my switches are Unifi

                            JKnottJ 1 Reply Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @orangehand
                              last edited by

                              @orangehand

                              I have a Unifi AP and a Cisco switch.

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              1 Reply Last reply Reply Quote 0
                              • Raffi_R
                                Raffi_
                                last edited by Raffi_

                                I have an APU2 and a unifi ap as well. I can confirm the APU2 and pfsense VLANing does work since my unifi main wifi network is a VLAN coming from pfSense. However, I also had issues creating a seperate wifi VLAN with the unifi. I think it's mostly my not understanding the unifi stuff or something odd with the unifi since at one point I couldn't even get it to work at all after what I thought was a small change. I had to completely reset it.

                                I don't have a unifi switch however, mine is a Dlink. I would say make sure all your unifi software and firmware is up to date. Not sure if this video might help? His videos are very good and it sounds like exactly what you're trying to do.
                                https://www.youtube.com/watch?v=LNAAfja_ZOY

                                Edit, it also might be worth making sure your BIOS is up to date on the APU2 or at least check the release notes to be sure your not missing some fix that could be related to this.

                                JKnottJ 1 Reply Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @Raffi_
                                  last edited by

                                  @Raffi_

                                  Yeah, the Unifi config is a bit strange. However, working with VLANs is fairly simple. Just make sure your VLANs match across all devices, including any switch you pass through. I have my guest WiFi on VLAN 3, so I configured that on my AP, switch and pfsense.

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 1
                                  • bingo600B
                                    bingo600 @orangehand
                                    last edited by bingo600

                                    @orangehand

                                    Why do you use Manual nat , and not Hybrid ?

                                    It seems like you are missing outbound nat for your guest lan : 192.168.34.0/24

                                    Re: Switches & stuff.
                                    Since you can ping devices on your Lan , and you get ip addresses on your guest WiFi. I'd say your switch & Vlan works fine.

                                    The reason you can't go on Inet from WiFi , seems to be that you are not doing outbound nat for that /24. And trying to send an RFC1918 ip to you ISP would not lead to anything good.

                                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                    pfSense+ 23.05.1 (ZFS)

                                    QOTOM-Q355G4 Quad Lan.
                                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                    1 Reply Last reply Reply Quote 1
                                    • Raffi_R
                                      Raffi_
                                      last edited by

                                      @bingo600 said in Port tagging on APU2?:

                                      Why do you use Manual nat , and not Hybrid ?

                                      Was wondering this also.

                                      @bingo600 said in Port tagging on APU2?:

                                      It seems like you are missing outbound nat for your guest lan : 192.168.34.0/24

                                      Good catch.

                                      1 Reply Last reply Reply Quote 0
                                      • bingo600B
                                        bingo600 @orangehand
                                        last edited by bingo600

                                        @orangehand

                                        Not that it matters "much" .. nitpicking
                                        But your 3CX NAT rule at the top, is covered by the 192.168.33.0/24 NAT rule further down.

                                        @Raffi_
                                        Thnx 😊

                                        This was a "tricky one" ..
                                        I'm 99% sure it's solved after OP makes the missing NAT rule.

                                        /Bingo

                                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                        pfSense+ 23.05.1 (ZFS)

                                        QOTOM-Q355G4 Quad Lan.
                                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                        O 1 Reply Last reply Reply Quote 1
                                        • O
                                          orangehand @bingo600
                                          last edited by

                                          @bingo600 Thank you all so much - that did the trick in Outbound NAT!
                                          Screenshot 2020-12-01 at 09.18.21.png

                                          No idea why it wasn't auto created though

                                          bingo600B 1 Reply Last reply Reply Quote 0
                                          • bingo600B
                                            bingo600 @orangehand
                                            last edited by

                                            @orangehand said in Port tagging on APU2?:

                                            No idea why it wasn't auto created though

                                            In your outbound NAT settings you have "tick'ed" Manual NAT (the round dots in top)
                                            That means no automatic nat is done.

                                            You should use either automatic or hybrid (hybrid let's you get automatic + you can add some your self)

                                            /Bingo

                                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                            pfSense+ 23.05.1 (ZFS)

                                            QOTOM-Q355G4 Quad Lan.
                                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                            O 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.