PFsense dynamic vlan



  • Hello,
    I am now facing a huge problem.
    I run pFsense as router with ubiquiti access point and switch.
    I have two SSID :
    "Secure" with wpa2 entreprise and radius dynamic vlan;
    "Other" with wpa2 personnal (for device such as appleTV, ps4, etc. that don't support wpa2 entreprise;

    Wpa2 entreprise work like a charm.

    But assign a vlan on my "Other" ssid is my problem :
    I can't put them it the right vlan.
    So they end up on the management vlan.
    Is there a way to solve that with pFsense?

    For now I don't care if it need to be done manually.

    I wish I could use radius mac authentification directly on pFsense, but I doubt it's doable.

    Regards,
    Jonathan



  • Are you using pfSense as the default gateway on all your devices or are you doing layer 3 inner-vlan routing on your switch?



  • @jamesonp:

    Are you using pfSense as the default gateway on all your devices or are you doing layer 3 inner-vlan routing on your switch?

    I am using pfSense as the default gateway, there is no L3 vlan routing.
    Every switch port are trunked to access point.



  • There has to have a solution?



  • Solution is to config your switch/ap correctly



  • My access don't support radius mac auth.
    Do you think it can be done by a switch even if it's behind an access point?
    How?

    I am looking for a solution.

    Regards,
    iLevac



  • I don't fully understand what you're trying to do, or what exactly "I can't put them it the right vlan" means, but what I can say is that with a WIFI router with DD-WRT installed it's possible to create multiple VAPs (Virtual Access Points) with tagged VLANs on one or more routers. Combine that with a switch that can do VLANs, and you can setup multiple separate WIFI networks that can be managed with pfSense.


Log in to reply