Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    1. Home
    2. Tags
    3. vlan
    Log in to post
    • All categories
    • E

      Can’t access WebGUI from inside a VLAN?
      General pfSense Questions • vlan boot web gui • • EChumBucket

      4
      0
      Votes
      4
      Posts
      53
      Views

      stephenw10

      I assume you only have one NIC in that device?

      You can still leave LAN assigned as the parent interface directly and assign VLAN99 as an OPT interface.

      Steve

    • M

      LAN vs VLAN w/ unifi switch and UDM PRO
      L2/Switching/VLANs • pfsense firewal unifi vlan • • mr.singh

      12
      0
      Votes
      12
      Posts
      188
      Views

      M

      @johnpoz Can DNS be an issue? My LAN interface has private 10.160.15.1/24 and IoT 11.160.30.1/24.

      By any ways can these conflicting with anything?
      I am also running pfblocker

    • L

      VLAN over a Bridged Wifi Router?
      L2/Switching/VLANs • vlan bridge guest • • LeiShen

      15
      0
      Votes
      15
      Posts
      397
      Views

      L

      @johnpoz : Linksys EA7300 - You said it would work, but it doesn't!!! 😆 🤣

      Not listed as supported on the DD-WRT web site. 😞

      But it is supported on OpenWRT with vLan! Yay!

      So, cool beans! I can (probably) take it from here.
      Thanks for your, and everyone's, help!!!

    • R

      pfsense, web server and VLAN's
      General pfSense Questions • web server static ip vlan switch • • Rockyuk

      42
      0
      Votes
      42
      Posts
      435
      Views

      stephenw10

      No worries, glad you're up and running. 👍

    • P

      Entregar IP diferente de VLAN, amarrando ao MAC
      Portuguese • vlan mac ubiquiti unifi wifi • • P4ul0R0s4

      1
      0
      Votes
      1
      Posts
      224
      Views

      No one has replied

    • L

      Captive Portal on specific VLAN prevents routing to other networks (since 22.01)
      Routing and Multi WAN • captiveportal vlan routing • • lorenzom

      4
      0
      Votes
      4
      Posts
      286
      Views

      L

      @gertjan The suggested system patch fixed the issue. Thank you!

    • C

      Configurazione OpenFiber WAN - PPPoE VLAN
      Italiano • openfiber wan pppoe vlan • • chpiero

      1
      0
      Votes
      1
      Posts
      188
      Views

      No one has replied

    • N

      Multiple VLANs in HA config
      HA/CARP/VIPs • vlan high availabili • • nick.loenders

      10
      0
      Votes
      10
      Posts
      736
      Views

      N

      @viragomann said in Multiple VLANs in HA config:

      So ensure the VLAN is also properly configured on the switch.

      omg , so stupid :)

      Thx it all works now

    • W

      FTTH (AON): Fritz!Box 5530 works, pfSense not
      General pfSense Questions • ftth fiber fritzbox sfp vlan • • waldy327

      27
      0
      Votes
      27
      Posts
      432
      Views

      stephenw10

      @waldy327 said in FTTH (AON): Fritz!Box 5530 works, pfSense not:

      Or is it enough to disable
      "Hardware TCP Segmentation Offloading"
      "Hardware Large Receive Offloading"

      Those should be disabled anyway, they are disabled by default so definitely disabled them if you have set them enabled.

      Hardware offloading requires the driver and hardware to work correctly together. Something that works on an igb NIC might work on ix. It might not even work on a different NIC that also uses the igb driver.
      They usually do though because those Intels are the best supported. Intel contributes their own driver code to FreeBSD.

      To disable that as a test you can run at the command line:

      ifconfig ix0 -vlanhwfilter -vlanmtu -vlanhwtag -vlanhwcsum

      I had assumed your igb NICs are not SFP?

      Steve

    • Q

      Wireless: Getting the MAC to the Right Interface & DHCP Server
      Wireless • interface vlan wireless dhcp mac-address • • Quasaur

      13
      0
      Votes
      13
      Posts
      221
      Views

      stephenw10

      Yes you could use pools in one subnet and filter them differently using aliases but you can't filter traffic between the clients on one subnet that way. Traffic would just go between them directly without passing through pfSense. Only one interface.
      Really you need to use VLANs in there to separate the traffic at layer 2.

      Steve

    • Autourdupc

      VLAN to LAN ping always possible despite rules
      L2/Switching/VLANs • vlan lan ping access bug • • Autourdupc

      7
      0
      Votes
      7
      Posts
      231
      Views

      johnpoz

      @autourdupc said in VLAN to LAN ping always possible despite rules:

      Next time, i will ask community before spending soo much time !

      What we are here for.. If there is some issue you have question on - or not sure if your understanding something correctly.. Yup just stop on by, here to help.

    • A

      Can’t access TrueNAS machine outside its own VLAN
      General pfSense Questions • vlan openvpn ping truenas • • agomendes

      7
      0
      Votes
      7
      Posts
      376
      Views

      A

      @johnpoz

      Yap! You are right... Some times we don’t think as it should be. It’s exactly the same situation that I’ve with the printer – just an IP assign and everything is working.

      As far as I know, TrueNAS (before FreeNAS) has not any internal firewall. At least configurable with the GUI. I’ll investigate deeper.

      Maybe it’s the gateway (I’ve some doubts that is wrong), so I’ve to confirm.

      For testing, I’ll also change the NAS to the LAN (same net where I’ve also the pfSense) and check if anything changes.

    • R

      Test inter-LAN/VLAN Routing to Verify Firewall Rules
      Firewalling • vlan firewall rules testing routing • • rennit

      1
      0
      Votes
      1
      Posts
      172
      Views

      No one has replied

    • hydrian

      Slow inter-VLAN Traffic
      L2/Switching/VLANs • vlan performance routing • • hydrian

      2
      0
      Votes
      2
      Posts
      315
      Views

      hydrian

      Nevermind. It was traffic shaper mucking me up.

    • C

      RTSP no video only audio on VLAN
      Firewalling • rtsp vlan streaming • • Coen

      2
      0
      Votes
      2
      Posts
      185
      Views

      C

      OK i got it! when i block UDP traffic from LAN see rule (or image below) to the IPcam ipaddress it works as it should. what i think happened is that default UDP doesn't work, still don't know why btw, then the camera is forced to use TCP. Its just a guess.

      alt text

    • AndyRH

      New 7100 setup
      Official Netgate® Hardware • vlan install • • AndyRH

      4
      0
      Votes
      4
      Posts
      269
      Views

      stephenw10

      @andyrh said in New 7100 setup:

      I moved the WAN by changing the parent interface for the default WAN VLAN.

      The VLAN on WAN, 4090 by default, only applies to the internal switch. So simply moving the VLAN parent to ix0 or igb3 would only work if VLAN 4090 is defined correctly on the external switch they are connected to.
      If that's not the case the new WAN interface would be directly ix0 or igb3 without a VLAN.

      Steve

    • D

      IPsec tunnel from remote site, need to pass VLAN traffic for phones?
      IPsec • l2tp vlan ipsec voip vpn • • djohnson

      2
      0
      Votes
      2
      Posts
      349
      Views

      R

      @djohnson
      This is a late reply but it may assist someone else in future.
      The VOIP audio traffic (RTP) require separate UDP ports to be open. The exact range will vary depending on your VoIP system.

      Hence, if the RTP ports are not open, you can experience a "working" system, but with a complete lack of audio.

    • M

      Unable to access cisco switch GUI on pfSense vlan
      L2/Switching/VLANs • vlan vlans vlan interface cisco cisco switch • • maxisthebest55

      4
      0
      Votes
      4
      Posts
      289
      Views

      M

      @johnpoz

      The switch = Cisco WS-C3560E-48PD-SF. Also running a 2960-CG

      Re: There is really no reason for it
      I am well aware that what I'm doing falls in the realm of completely unnecessary for a home network. Just a learning exercise.

      I figured out the answer to my convoluted post from yesterday. You touched on it in your post but I'll type it out in my words...

      From what I can tell, the pfSense LAN is the only untagged network available on the router. Changing the native VLAN on a switch, for example, to VLAN 20, would require that the ip address assigned to that VLAN be in the address range of the LAN network on the pfSense box (because it also is untagged) to maintain web access to the switch.

      Key takeaway - the native VLAN on switch (untagged) should not be assigned to a VLAN network (tagged) on a pfSense box (else one loses web access to the switch). Also, the ip address assigned to native VLAN on switch must be in the same subnet as the router LAN.

      Thank you. -jeff

    • O

      [Solved] SG-3100 Switch Configuration - LAN on VLAN ID1?
      Official Netgate® Hardware • sg-3100 switchports switch vlan solved • • omid_1985

      6
      0
      Votes
      6
      Posts
      293
      Views

      stephenw10

      You can only choose a switch port on one interface as you found. If you leave unset it will use the actual VLAN status which takes it's state from the parent interface. In this case though that's the in internal port which is always UP.

      No, there's no private VLAN type function. That would need to be on a switch where hosts are connected directly.

      Steve

    • A

      Some VLANS Route and some don't
      L2/Switching/VLANs • dell mikrotik unifi vlan • • AidenTheBot

      3
      0
      Votes
      3
      Posts
      257
      Views

      johnpoz

      @marvosa said in Some VLANS Route and some don't:

      but the IP Range for the MGMT VLAN is incorrect.

      Yeah 10.0.12/22 or 255.255.252 would be 10.0.12.0 - 10.0.15.255

      What are the rules you put on these vlans?

      And yes a drawing would be most helpful.. Your saying the devices pull the correct info via dhcp.. If so that would point to connectivity being good, so first thing that comes to mind is wrong rules or lack of rules on the vlan interfaces.

    • B

      Limit the amount of connected users
      General pfSense Questions • vlan limiters connection • • bosefbris

      2
      0
      Votes
      2
      Posts
      117
      Views

      A

      Use Captive Portal along with FreeRadius. Create a user and restrict no of simultaneous devices to 3. Share the username and password with all the users.... at a time only 3 will be able to connect.

      Regards,
      Ashima

    • charles_moody

      Static Routing | ZeroTier
      pfSense Packages • routing vlan zerotier • • charles_moody

      1
      0
      Votes
      1
      Posts
      183
      Views

      No one has replied

    • G

      Use WAN dhcp server on a vlan
      DHCP and DNS • vlan dhcp dns • • gsemet

      4
      0
      Votes
      4
      Posts
      136
      Views

      V

      @gsemet
      In Interfaces > Bridges you can define a new bridge and add interfaces to it. The go to Interface Assignments, assing an interface to the new bridge and enable it. No further settings are needed on the bridge interface.
      But befor you have to ensure that there is no configuration on the vlan 10 interface. It has only to be enabled.

      However, with this setting results in the vlan 10 going down, when WAN goes down. To avoid that you can move the IP settings from the WAN interface to the bridge.

    • S

      multi-vlan on a port
      L2/Switching/VLANs • vlan sg-3100 switch • • smik67

      1
      0
      Votes
      1
      Posts
      160
      Views

      No one has replied

    • J

      Add Tag button missing on VLANs page?
      General pfSense Questions • vlan • • jgq85

      1
      0
      Votes
      1
      Posts
      88
      Views

      No one has replied

    • R

      Broadband router & VLAN in PPPoE
      General pfSense Questions • bridged mode vlan • • reqman

      4
      0
      Votes
      4
      Posts
      145
      Views

      R

      Thank you both for your suggestions, I've been away so I didn't have time to test. I'll try both approaches (believe the one suggested by @fireodo will do the trick).

    • G

      not getting a dhcp address on vlans with new install.
      DHCP and DNS • dhcp unify vlan • • godhead83

      6
      0
      Votes
      6
      Posts
      159
      Views

      JKnott

      @godhead83

      Start simple. Get the main LAN going first, including DHCP. Once that is done, you can do the same with the VLANs, including a DHCP server for each one. By doing things one step at a time, it's easier to resolve problems. Also, you should get handy with Wireshark, to see what's actually happening on the wire. You can also enable a column in it to display VLAN ID.

    • S

      I need help with VLAN
      L2/Switching/VLANs • vlan ping lan • • Snows 0

      17
      0
      Votes
      17
      Posts
      755
      Views

      S

      I solved the issue a while ago and forgot to answer here.
      After entering the IP in Captive Portal / Allowed IP Addresses, everything was perfect.
      As my CP is authenticated, so I believe that the question was precisely at that point. The other end had no way to authenticate itself to be able to pass and from the moment I released the IP there, he started to communicate. I even thought about doing a test of this type, taking the CP's authentication to see if it worked directly, but I ended up not having time.

      Anyway ... it's resolved.
      Thanks to everyone who was willing to try to help.

    • G

      Comunicação entre rede LAN e VLANS
      Portuguese • lan vlan vlans • • Gabriel Silveira

      17
      0
      Votes
      17
      Posts
      388
      Views

      M

      @gabriel-silveira Se você tem 2 provedores, os 2 estão conectados no pfsense, certo?
      O Gateway group permite você configurar essas saídas de Internet em failover por exemplo, caso provedor A caia, utilize o provedor B até que o A seja restabelecido.

      Ou caso você queria por exemplo que a VLAN20 utilize o provedor A apenas, você adiciona na regra de Firewall que permite o acesso a Internet dessa VLAN o gateway apontando para o gateway do provedor A.

      Você fez alguma configuração nesse sentido?

      Pois caso tenha feito, você precisará criar regras de Firewall, permitindo a conexão entre as VLANs, com gateway sem alteração, ou seja, em default, e essa regra deverá estar no topo.

      Ela precisa estar antes das regras que permitem o acesso a Internet com gateway específico, ou seja, que não seja default.

      Uma recomendação para que possamos te ajudar melhor, é sempre postar uma topologia do ambiente. Estou tendo que fazer suposições sobre o problema e o ambiente.

    • C

      inter-VLAN routing with SG-2100
      Official Netgate® Hardware • vlans sg-2100 routing vlan • • completion

      5
      0
      Votes
      5
      Posts
      644
      Views

      H

      Good day,
      I think it is necessary to solve it on the switch via ACL ... I don't have a UniFi switch, so I can't advise it much. I only have UniFi AP AC RL. I don't have any NETGATE devices yet, I'm just getting ...

    • noahajac

      CARP IP is in backup state however it is still answering queries on other VLANs
      HA/CARP/VIPs • carp vlan vip • • noahajac

      1
      0
      Votes
      1
      Posts
      121
      Views

      No one has replied

    • lifeboy

      Hybrid routed and NAT'ed network
      Routing and Multi WAN • public ips routing vlan • • lifeboy

      2
      0
      Votes
      2
      Posts
      92
      Views

      lifeboy

      I have now added a VLAN to the LAN port in proxmox and created a bridge from that. This I have added to pfSense with the first address of the ip subnet which will act as gateway for the /29 addresses from the guests/hosts on the network.

      So far so good.

    • Y

      VLAN Routing with UniFi APs
      L2/Switching/VLANs • netgear unifi vlan • • Yo5hi

      12
      0
      Votes
      12
      Posts
      448
      Views

      bingo600

      @johnpoz

      Luckily i'm in a controlled environment where only PC's and Desktop Phones approved by (me) are allowed to have access via WiFi.

      No phones or personal devices are allowed on that segment.

      /Bingo

    • sololegends

      unbound notice: sendto failed: Invalid argument
      DHCP and DNS • unbound dns vlan dns vlan sendto failed • • sololegends

      1
      0
      Votes
      1
      Posts
      346
      Views

      No one has replied

    • charles_moody

      Trunk/LAGG problem / pfSense UniFi 24-250W PoE Switch and VLANs
      L2/Switching/VLANs • vlan vlan interface trunk lagg unifi • • charles_moody

      2
      0
      Votes
      2
      Posts
      207
      Views

      johnpoz

      @charles_moody said in Trunk/LAGG problem / pfSense UniFi 24-250W PoE Switch and VLANs:

      Can anyone tell me how to get the switch to adopt

      So this is crux of your issue?

      That has nothing to do with pfsense.. Your controller and switch need to be on the same L2 network for adoption... Or you need to use L3 adoption.. This has everything to do with unifi, and not related to pfsense at all.

      https://help.ui.com/hc/en-us/articles/204909754-UniFi-Device-Adoption-Methods-for-Remote-UniFi-Controllers

      behind that about 10 smart-managed Netgear switches

      This seems nuts - are they all in closets somewhere.. How big is this house? If you were running cable - why would all your cables not just home run back to your core switching area? Curious where exactly all these switches are?

      want LAN just for troubleshooting and because it’s often stated that LAN will strip of the VLAN tags from the traffic

      Huh? You can run vlans on lan just like any other interface.. So not sure what your thinking with this statement... Sure you can use lan interface as your management interface.. But it can run vlans on it as well if you want.

    • VivoAzzurro

      Help me configure my first VLAN?
      L2/Switching/VLANs • vlan vlan to lan switch switchports • • VivoAzzurro

      5
      0
      Votes
      5
      Posts
      175
      Views

      VivoAzzurro

      @JKnott

      I tend to heir on the side of caution when it comes to using terminology I'm not 100% familiar with, but I have the basics down that's for sure.

      Regardless, after some extensive troubleshooting I got rid of the Aruba switch and swapped it out with a Ubiquiti.
      Had my network infrastructure team troubleshoot the Aruba... nobody could get it working. They let me know about how others have not been able to use Aruba equipment in the past, so i chalked it up to the switch.

    • J

      VLAN connectivity Issue
      Firewalling • vlan cisco switch • • jcubio

      4
      0
      Votes
      4
      Posts
      122
      Views

      johnpoz

      While captive portal could be blocking.. You clearly have issue there with only allowing tcp.. Unless your client is doing doh or dot there is now way he could get any dns.. DNS runs on UDP 53..

      You can see right there in your block 53 to 8.8.8.8 was blocked.

    • J

      Apply pfBlockerNG DNSBL to one VLAN but not the LAN (or other VLAN)?
      pfBlockerNG • dnsbl vlan dns resolver • • J24

      4
      1
      Votes
      4
      Posts
      773
      Views

      A

      @j24 I added a NAT rule that redirects the DNS requests from the VLAN to a known DNS e.g. 8.8.8.8. It's not the best solution I hope someone can help us separate pfBlocker from the other VLANs.

    • M

      SMB/NFS/iSCSI between VLAN<->LAN only works with synproxy enabled
      Firewalling • vlan firewall rules • • MichaelLong

      1
      0
      Votes
      1
      Posts
      397
      Views

      No one has replied

    • C

      Trying to setup Guest VLAN but not working
      L2/Switching/VLANs • vlan vlan interface dhcp vlan to lan • • CalTommo

      12
      0
      Votes
      12
      Posts
      710
      Views

      JKnott

      @CalTommo

      I don't know how, if you've set up DHCP. It just works. Configuring DHCP on a VLAN is no different than on an Ethernet port. Do you have a computer you can configure for VLAN 80? If so, just plug it into the LAN side of the pfSense box and see what happens.