• 0 Votes
    7 Posts
    2k Views
    johnpozJ

    @autourdupc said in VLAN to LAN ping always possible despite rules:

    Next time, i will ask community before spending soo much time !

    What we are here for.. If there is some issue you have question on - or not sure if your understanding something correctly.. Yup just stop on by, here to help.

  • 0 Votes
    7 Posts
    2k Views
    A

    @johnpoz

    Yap! You are right... Some times we don’t think as it should be. It’s exactly the same situation that I’ve with the printer – just an IP assign and everything is working.

    As far as I know, TrueNAS (before FreeNAS) has not any internal firewall. At least configurable with the GUI. I’ll investigate deeper.

    Maybe it’s the gateway (I’ve some doubts that is wrong), so I’ve to confirm.

    For testing, I’ll also change the NAS to the LAN (same net where I’ve also the pfSense) and check if anything changes.

  • 0 Votes
    1 Posts
    611 Views
    No one has replied
  • Slow inter-VLAN Traffic

    L2/Switching/VLANs
    2
    0 Votes
    2 Posts
    929 Views
    hydrianH

    Nevermind. It was traffic shaper mucking me up.

  • RTSP no video only audio on VLAN

    Firewalling
    2
    0 Votes
    2 Posts
    626 Views
    C

    OK i got it! when i block UDP traffic from LAN see rule (or image below) to the IPcam ipaddress it works as it should. what i think happened is that default UDP doesn't work, still don't know why btw, then the camera is forced to use TCP. Its just a guess.

    alt text

  • New 7100 setup

    Moved Official Netgate® Hardware
    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S

    @andyrh said in New 7100 setup:

    I moved the WAN by changing the parent interface for the default WAN VLAN.

    The VLAN on WAN, 4090 by default, only applies to the internal switch. So simply moving the VLAN parent to ix0 or igb3 would only work if VLAN 4090 is defined correctly on the external switch they are connected to.
    If that's not the case the new WAN interface would be directly ix0 or igb3 without a VLAN.

    Steve

  • 0 Votes
    2 Posts
    979 Views
    R

    @djohnson
    This is a late reply but it may assist someone else in future.
    The VOIP audio traffic (RTP) require separate UDP ports to be open. The exact range will vary depending on your VoIP system.

    Hence, if the RTP ports are not open, you can experience a "working" system, but with a complete lack of audio.

  • 0 Votes
    4 Posts
    1k Views
    M

    @johnpoz

    The switch = Cisco WS-C3560E-48PD-SF. Also running a 2960-CG

    Re: There is really no reason for it
    I am well aware that what I'm doing falls in the realm of completely unnecessary for a home network. Just a learning exercise.

    I figured out the answer to my convoluted post from yesterday. You touched on it in your post but I'll type it out in my words...

    From what I can tell, the pfSense LAN is the only untagged network available on the router. Changing the native VLAN on a switch, for example, to VLAN 20, would require that the ip address assigned to that VLAN be in the address range of the LAN network on the pfSense box (because it also is untagged) to maintain web access to the switch.

    Key takeaway - the native VLAN on switch (untagged) should not be assigned to a VLAN network (tagged) on a pfSense box (else one loses web access to the switch). Also, the ip address assigned to native VLAN on switch must be in the same subnet as the router LAN.

    Thank you. -jeff

  • 0 Votes
    6 Posts
    1k Views
    stephenw10S

    You can only choose a switch port on one interface as you found. If you leave unset it will use the actual VLAN status which takes it's state from the parent interface. In this case though that's the in internal port which is always UP.

    No, there's no private VLAN type function. That would need to be on a switch where hosts are connected directly.

    Steve

  • Some VLANS Route and some don't

    L2/Switching/VLANs
    3
    0 Votes
    3 Posts
    1k Views
    johnpozJ

    @marvosa said in Some VLANS Route and some don't:

    but the IP Range for the MGMT VLAN is incorrect.

    Yeah 10.0.12/22 or 255.255.252 would be 10.0.12.0 - 10.0.15.255

    What are the rules you put on these vlans?

    And yes a drawing would be most helpful.. Your saying the devices pull the correct info via dhcp.. If so that would point to connectivity being good, so first thing that comes to mind is wrong rules or lack of rules on the vlan interfaces.

  • 0 Votes
    2 Posts
    643 Views
    A

    Use Captive Portal along with FreeRadius. Create a user and restrict no of simultaneous devices to 3. Share the username and password with all the users.... at a time only 3 will be able to connect.

    Regards,
    Ashima

  • Static Routing | ZeroTier

    pfSense Packages
    1
    0 Votes
    1 Posts
    482 Views
    No one has replied
  • Use WAN dhcp server on a vlan

    DHCP and DNS
    4
    0 Votes
    4 Posts
    823 Views
    V

    @gsemet
    In Interfaces > Bridges you can define a new bridge and add interfaces to it. The go to Interface Assignments, assing an interface to the new bridge and enable it. No further settings are needed on the bridge interface.
    But befor you have to ensure that there is no configuration on the vlan 10 interface. It has only to be enabled.

    However, with this setting results in the vlan 10 going down, when WAN goes down. To avoid that you can move the IP settings from the WAN interface to the bridge.

  • multi-vlan on a port

    L2/Switching/VLANs
    1
    0 Votes
    1 Posts
    487 Views
    No one has replied
  • Add Tag button missing on VLANs page?

    General pfSense Questions
    1
    0 Votes
    1 Posts
    200 Views
    No one has replied
  • Broadband router & VLAN in PPPoE

    Moved General pfSense Questions
    4
    0 Votes
    4 Posts
    756 Views
    R

    Thank you both for your suggestions, I've been away so I didn't have time to test. I'll try both approaches (believe the one suggested by @fireodo will do the trick).

  • 0 Votes
    6 Posts
    1k Views
    JKnottJ

    @godhead83

    Start simple. Get the main LAN going first, including DHCP. Once that is done, you can do the same with the VLANs, including a DHCP server for each one. By doing things one step at a time, it's easier to resolve problems. Also, you should get handy with Wireshark, to see what's actually happening on the wire. You can also enable a column in it to display VLAN ID.

  • I need help with VLAN

    L2/Switching/VLANs
    17
    0 Votes
    17 Posts
    2k Views
    S

    I solved the issue a while ago and forgot to answer here.
    After entering the IP in Captive Portal / Allowed IP Addresses, everything was perfect.
    As my CP is authenticated, so I believe that the question was precisely at that point. The other end had no way to authenticate itself to be able to pass and from the moment I released the IP there, he started to communicate. I even thought about doing a test of this type, taking the CP's authentication to see if it worked directly, but I ended up not having time.

    Anyway ... it's resolved.
    Thanks to everyone who was willing to try to help.

  • Comunicação entre rede LAN e VLANS

    Portuguese
    17
    0 Votes
    17 Posts
    3k Views
    M

    @gabriel-silveira Se você tem 2 provedores, os 2 estão conectados no pfsense, certo?
    O Gateway group permite você configurar essas saídas de Internet em failover por exemplo, caso provedor A caia, utilize o provedor B até que o A seja restabelecido.

    Ou caso você queria por exemplo que a VLAN20 utilize o provedor A apenas, você adiciona na regra de Firewall que permite o acesso a Internet dessa VLAN o gateway apontando para o gateway do provedor A.

    Você fez alguma configuração nesse sentido?

    Pois caso tenha feito, você precisará criar regras de Firewall, permitindo a conexão entre as VLANs, com gateway sem alteração, ou seja, em default, e essa regra deverá estar no topo.

    Ela precisa estar antes das regras que permitem o acesso a Internet com gateway específico, ou seja, que não seja default.

    Uma recomendação para que possamos te ajudar melhor, é sempre postar uma topologia do ambiente. Estou tendo que fazer suposições sobre o problema e o ambiente.

  • 0 Votes
    5 Posts
    2k Views
    H

    Good day,
    I think it is necessary to solve it on the switch via ACL ... I don't have a UniFi switch, so I can't advise it much. I only have UniFi AP AC RL. I don't have any NETGATE devices yet, I'm just getting ...