Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN Tag not being passed

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    32 Posts 6 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      randy9000 @Derelict
      last edited by

      @derelict

      That makes sense. I'll try to follow what's in the guide and report back.

      Thanks

      1 Reply Last reply Reply Quote 0
      • R
        randy9000 @Derelict
        last edited by randy9000

        @derelict

        I followed those instructions and still nothing. See attached screen shots..

        I configured firewall rules to pass all traffic.

        Please help!

        Screen Shot 2021-03-18 at 5.02.05 PM.jpg

        Screen Shot 2021-03-18 at 5.00.49 PM.jpg

        Screen Shot 2021-03-18 at 5.00.30 PM.jpg

        Screen Shot 2021-03-18 at 5.00.12 PM.jpg

        Screen Shot 2021-03-18 at 4.51.49 PM.jpg

        DerelictD 1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate @randy9000
          last edited by Derelict

          @randy9000 Don't set a Port VID for a tagged VLAN. The Port VID is for the untagged VLAN on that port. Just leave the Port VID at 1 on port 2.

          And whatever you are connecting to port 2 has to be configured tagged VLAN 30, too.

          You also need a DHCP server and firewall rules to pass traffic on the VLAN30_Port2 interface.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          R 1 Reply Last reply Reply Quote 0
          • R
            randy9000 @Derelict
            last edited by

            @derelict

            That didn't work either.

            1 Reply Last reply Reply Quote 0
            • N
              NOCling
              last edited by

              It works with the SG-3100, i use 10 VLANs with it over Lan1.
              7d9cdc71-1091-4c24-9f6c-564356ad313d-image.png

              You have to tag it right:
              16eb2663-df03-41bd-95e1-015d8ab67ee6-image.png

              And the same on the Switch Uplinkt to the SG-3100 LAN Port.

              Thats all.

              Netgate 6100 & Netgate 2100

              R 1 Reply Last reply Reply Quote 0
              • R
                randy9000 @NOCling
                last edited by

                @nocling

                What configuration changes do I need to make in the example you provided to use Port #2 - LAN 2?

                Thanks

                1 Reply Last reply Reply Quote 0
                • N
                  NOCling
                  last edited by

                  Pic 2 -> Member 1t replace by 2t

                  Netgate 6100 & Netgate 2100

                  R 2 Replies Last reply Reply Quote 0
                  • R
                    randy9000 @NOCling
                    last edited by

                    @nocling

                    That’s how it’s currently configured and it’s not working. See images previously posted.

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @randy9000
                      last edited by

                      @randy9000 Again, the switch port has to be expecting tagged traffic on that port.

                      This stuff works 100%.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      R 1 Reply Last reply Reply Quote 0
                      • R
                        randy9000 @Derelict
                        last edited by

                        @derelict

                        Okay. Retrying again.

                        1 Reply Last reply Reply Quote 0
                        • R
                          randy9000 @NOCling
                          last edited by

                          @nocling & @Derelict

                          On the Netgear switch, am I to only tag "T" the port that the cable is in and untag "U" the others with on the VLAN? Or, Tag "T" all of the ports that will be used on the VLAN?

                          DerelictD 1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate @randy9000
                            last edited by Derelict

                            @randy9000 Everything tagged on the pfsense switch side needs to be tagged on the switch port you are connecting to it.

                            VLAN-pfSense copy.png

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              randy9000 @Derelict
                              last edited by

                              @derelict

                              It seems as though the issue is with me netgear smart switch. If I plug a pc directly into port 2 of the Netgate 3100 I can get and ip address and internet. However, when I connect it to the netgear switch I get nothing.

                              I also noticed that in order for my laptop to get and ip address the port 2 tagged check box but be unchecked and the port 5 box must be checked.

                              DerelictD 1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate @randy9000
                                last edited by

                                @randy9000 That is how it works. Client devices like laptops almost exclusively get connected to single-VLAN, untagged ports.

                                Tagged ports are for connections to other VLAN-aware devices like switches and access points and router ports with VLAN tags configured.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                R 1 Reply Last reply Reply Quote 0
                                • R
                                  randy9000 @Derelict
                                  last edited by

                                  @derelict

                                  I think I may have confused you.

                                  It works when I connect the laptop to the router on port 2. However, when I connect the router port 2 to the Netgear switch port 24 (Vlan tagged ) and the laptop to the netgear port 23 (untagged) The laptop cannot communicate with the router for an ip address etc.

                                  DerelictD 1 Reply Last reply Reply Quote 0
                                  • N
                                    NOCling
                                    last edited by

                                    Your Port 2 is not tagged corectly.

                                    Do this and it will work.
                                    I use 10 VLANs over LAN 1 and here all works fine.

                                    Netgate 6100 & Netgate 2100

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      randy9000 @NOCling
                                      last edited by

                                      @nocling

                                      What action are your referring to for me to do?

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate @randy9000
                                        last edited by

                                        If connecting a laptop to a switch port with a tagged VLAN on it gets access for the laptop on that VLAN without taking special measures on the laptop to tag the VLAN on the port then the switch isn't configured like you think it is.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        R 1 Reply Last reply Reply Quote 0
                                        • R
                                          randy9000 @Derelict
                                          last edited by

                                          @derelict & All

                                          Thanks for your help. The issue is resolved.

                                          The problem was the Netgear switch port was being blocked because of STP rules.

                                          Issue Resolved!

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.