• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to get pfSense WAN to accept VLAN 0

General pfSense Questions
25
414
206.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    fresnoboy @natbart
    last edited by Feb 7, 2021, 8:42 PM

    @natbart

    I do this with my AT&T fiber connection to get rid of the POS AT&T gateway.

    BTW, another technique to deal with this VLAN0 silliness is to use a cheap switch to strip the VLAN0 from the WAN connection like the Netgear GS108Ev3 . The AT&T bypass thread here: https://forum.netgate.com/topic/99190/att-uverse-rg-bypass-0-2-btc/328 has all sorts of info on dealing with the VLAN0 problem that AT&T Fiber users have to deal with.

    N 1 Reply Last reply Feb 7, 2021, 9:13 PM Reply Quote 2
    • S
      stephenw10 Netgate Administrator @JKnott
      last edited by Feb 7, 2021, 8:48 PM

      There are some providers who require a priority tag on WAN but I've never seen that without a, valid, vlan tag.

      Steve

      1 Reply Last reply Reply Quote 0
      • N
        natbart @fresnoboy
        last edited by Feb 7, 2021, 9:13 PM

        @fresnoboy said in How to get pfSense WAN to accept VLAN 0:

        Netgear GS108Ev3

        I will continue to read the ATT bypass solutions. My service provider does not have all the WPA supplicant / certificate requirements that ATT users have, so was trying to distinguish the required element from that fix.

        I have thought about putting a switch in the mix, but a Netgear GS108 is another $75 CDN on Amazon and adds another layer to the solution as well as cost.

        What requirements does the switch need to solve my problem? Does it make more sense to throw on VMware and at least deal with one piece of hardware.

        F T 2 Replies Last reply Feb 7, 2021, 10:34 PM Reply Quote 0
        • F
          fresnoboy @natbart
          last edited by Feb 7, 2021, 10:34 PM

          @natbart

          These switches are usually available on ebay or even Craigslist for a lot less. I'm not saying it's the best solution, but it works without having to run vmware, etc...

          Good luck!

          1 Reply Last reply Reply Quote 1
          • S
            stephenw10 Netgate Administrator
            last edited by Feb 7, 2021, 10:38 PM

            Yeah, it should work with netgraph because there are no restrictions really. You can do whatever you want there unlike ifconfig.

            It shouldn't be that hard either. Another think that uses it is QinQ. If you create a QinQ interface and then check in /tmp you can see the file with the netgraph commands used to create it.

            Or indeed the example given here.

            Steve

            N 1 Reply Last reply Feb 8, 2021, 12:15 AM Reply Quote 1
            • N
              natbart
              last edited by Feb 7, 2021, 10:44 PM

              Running packet capture on the WAN port all I see is a DHCP discovery broadcast (by my unit) and a DHCP offer by provider which unit never responds to but causes it to put another Discover out there.

              Offers are tagged:

              802.1Q Virtual LAN, PRI: 7, DEI: 0, ID: 0

              1 Reply Last reply Reply Quote 0
              • T
                tquade @natbart
                last edited by Feb 7, 2021, 11:12 PM

                @natbart

                A GS105NA can be had for around $45 on amazon.ca.

                Ted

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Feb 7, 2021, 11:33 PM

                  If you didn't have to priority tag it on the USG you wonl't have to here.

                  This is going to be like a 5 line script but Netgraph always makes my brain hurt!
                  Just hitting errors right now....

                  N 1 Reply Last reply Feb 8, 2021, 12:11 AM Reply Quote 0
                  • N
                    natbart @stephenw10
                    last edited by Feb 8, 2021, 12:11 AM

                    @stephenw10 the only setting i set on the Unifi USG3 was "Use VLAN ID" and I set it to "0"

                    🔒 Log in to view

                    I was able to do a temp work around with a 24 port Cisco Small Business switch that I had and put it between ONT and pfSense. This allowed me to grab a DHCP address from provider and surf. Overkill solution.

                    Will continue to look at the netgraph option... as this seems like the cleanest option. I just need to wrap my head around how netgraph work and how to compile as I dont have a system running FreeBSD (outside of this pfSense box).

                    1 Reply Last reply Reply Quote 0
                    • N
                      natbart @stephenw10
                      last edited by Feb 8, 2021, 12:15 AM

                      @stephenw10 will read up at provided link. Thank you for the continued engagement.

                      J 1 Reply Last reply Feb 8, 2021, 4:46 AM Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator @natbart
                        last edited by johnpoz Feb 8, 2021, 4:50 AM Feb 8, 2021, 4:46 AM

                        Just to point out - unifi doesn't make this as easy as made out to be..

                        🔒 Log in to view

                        They might support it on some versions of the controller software in some places - but like most applications 0 and 4095 are not really valid

                        Is there a feature request for this? If there are ISPs that want/need this - and freebsd allows for it, etc. I would expect if there was a feature request for it - it would/could be looked at implementing in the gui as a check box, or something.

                        But in 30 some years in the biz - sorry but setting vlan 0 is not a common thing.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        N 2 Replies Last reply Feb 8, 2021, 4:52 AM Reply Quote 1
                        • N
                          natbart @johnpoz
                          last edited by Feb 8, 2021, 4:52 AM

                          @johnpoz having this as an option would be amazing. Would be simple than some of the other work arounds.

                          Hard to believe others haven’t asked for it based on ATT also needing it (amongst other config). Not used what other ISPs are similarly config’ed.

                          J 1 Reply Last reply Feb 8, 2021, 4:55 AM Reply Quote 0
                          • J
                            johnpoz LAYER 8 Global Moderator @natbart
                            last edited by johnpoz Feb 8, 2021, 4:56 AM Feb 8, 2021, 4:55 AM

                            I haven't combed through redmine yet - but yeah if you want/need this - then it should be submitted to redmine as a feature request..

                            If it can be done, and there is desire for it - why would it not be implemented.

                            But to be honest - I do believe part of the reason for such a deployment would be making it harder for isp customers to use non isp hardware.. Since setting vlan id 0 is not really something that is common

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            N 1 Reply Last reply Feb 8, 2021, 5:35 AM Reply Quote 0
                            • N
                              natbart @johnpoz
                              last edited by Feb 8, 2021, 5:31 AM

                              @johnpoz I configured in the initial USG config. Not using the controller software.

                              1 Reply Last reply Reply Quote 0
                              • N
                                natbart @johnpoz
                                last edited by Feb 8, 2021, 5:35 AM

                                @johnpoz sorry, I am not sure who/ what Redmine is. This is my first post and I just got pfSense installed this week. I am very new to since. My initial excitement did fizzle somewhat when I ran into this issue.

                                1 Reply Last reply Reply Quote 0
                                • C
                                  Cool_Corona
                                  last edited by Feb 8, 2021, 5:37 AM

                                  Question:

                                  Why not run it in transparent mode and let pfsense handle WAN??

                                  N 1 Reply Last reply Feb 8, 2021, 6:09 AM Reply Quote 0
                                  • N
                                    natbart @Cool_Corona
                                    last edited by Feb 8, 2021, 6:09 AM

                                    @cool_corona not sure I understand what you mean. New to pfSense can you elaborate?

                                    C 1 Reply Last reply Feb 8, 2021, 9:34 AM Reply Quote 0
                                    • C
                                      Cool_Corona @natbart
                                      last edited by Feb 8, 2021, 9:34 AM

                                      @natbart You put the Nokia in bridge mode and connect the pfsense WAN on RJ45.

                                      Then handle WAN via DHCP to see if it works. And then you are rid of the USG

                                      N 2 Replies Last reply Feb 8, 2021, 3:12 PM Reply Quote 0
                                      • S
                                        stephenw10 Netgate Administrator
                                        last edited by Feb 8, 2021, 11:54 AM

                                        As I understand it that is the plan here. But the ISP requires the traffic tagged as VLAN0 and pfSense does not currently have any way to set that.

                                        Netgraph still defeating me!

                                        Steve

                                        N 2 Replies Last reply Feb 9, 2021, 5:08 PM Reply Quote 0
                                        • N
                                          natbart @Cool_Corona
                                          last edited by Feb 8, 2021, 3:12 PM

                                          This post is deleted!
                                          1 Reply Last reply Reply Quote 0
                                          27 out of 414
                                          • First post
                                            27/414
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.