• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple VLANS across physical Interfaces

Scheduled Pinned Locked Moved Firewalling
3 Posts 3 Posters 3.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    B3Technology
    last edited by Nov 7, 2016, 10:11 PM

    I am trying to setup a pfSense box that has 4 physical Interfaces (em0 - em3). The first Interface (em0) goes to the Internet. The second (em1) and third (em2) Interfaces go to separate managed switches. Each of these switches has various VLANs configured but for the ease of describing my problem lets limit it to 3 VLANs (VLAN2, VLAN3 and VLAN4). We are using the pfSense firewall for all DHCP services.

    NOTE: We will also be adding a third switch on the forth (em3) interface that will only need access to the other 2 switches via VLAN3.

    What I need to do is have all three VLANs traverse to the Internet and have VLAN3 traverse between switches via the firewall. I also would like PC1 and PC2 to be able to pull from the same DHCP server.

    I was able to creatre the VLANs for VLAN2 and VLAN4 and route these to the Internet. I am having issues correctly setting up VLAN3 between the 2 different interfaces and still use the same DHCP service and Firewall RULES. It seems that I have to handle these under separate Interfaces.

    –---              -----
            | PC1 |            | PC2 |
            /-----/            /-----/
            -----              -----
              |                  |
        -----------          -----------
      | Switch #1 |        | Switch #2 |
        -----------          -----------
      VLan    \                /  VLan
      2 & 3    \              /    3 & 4
                \ em0    em1/
                  ------------
                | pfSense FW |
                  ------------
                      |
                    -------
                  | Modem |
                    -------

    Any thoughts would be helpful.

    1 Reply Last reply Reply Quote 0
    • J
      jahonix
      last edited by Nov 8, 2016, 12:00 AM

      You can have each VLAN on one physical interface/trunk only in pfSense.
      Put a managed core-switch in front of your pfSense and distribute the VLANs on dedicated trunks to each access-switch.

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Nov 8, 2016, 12:24 PM

        Yeah that is not how you would do that..

        Use a switch to distribute the vlans to access switches.  The connection to pfsense can be a trunk with all the vlans on it, or from the distribution switch you can have uplinks for every vlan to physical or mix and match depending on what your intervlan traffic will be - you wouldn't want intervlan traffic having to hairpin, etc.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received