Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    VLAN PVID

    General pfSense Questions
    4
    6
    1261
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kgmoney last edited by

      Hi,

      In pfsense is there a way to configure a PVID (default VLAN) on an interface will multiple tagged vlans.  For example, if an interface is tagged with VLANs 10, 20, and 30, how would I configure pfsense so that any untagged ingress traffic would be automatically tagged for VLAN 10?

      Thanks,
      Kevin

      1 Reply Last reply Reply Quote 0
      • B
        big_D last edited by

        Normally you don't define the default VLAN.

        On our system, the switches and pfSense are set up with Default + 15, 40, 50, 100 and 150. The VLANs are set up and assigned interfaces (on the LAN NIC) in pfSense. Everything else goes over the LAN interface, which is your default and is assigned to the subnet of the default VLAN.

        List looks like following:
        LAN = Default = 192.168.58.0/24
        V15 = Client = 192.168.15.0/24
        V40 = Telefonie = 192.168.40.0/24
        etc.

        The switch is then set to tagged for all VLANs, plus untagged for default traffic.

        1 Reply Last reply Reply Quote 0
        • johnpoz
          johnpoz LAYER 8 Global Moderator last edited by

          "how would I configure pfsense so that any untagged ingress traffic would be automatically tagged for VLAN 10?
          "

          But setting native or pvid of that trunk port that connects to pfsense interface as vlan 10..  The interface native would be in that vlan..

          so you have say your lan on em0, on this interface you have vlan interfaces 20, 30 etc..  On the switch port that connects to em0 set whatever you want as the untagged native vlan.. Make it 10 for example..

          1 Reply Last reply Reply Quote 0
          • K
            kgmoney last edited by

            Thanks for your help.

            @big_D:  I was wondering if that might be the way to do it, I'll give it a try.

            @johnpoz:  That's how it should be setup, but unfortunately my switch is one that has vlan 1 untagged on all ports (hard coded) and I'm trying to find ways to force it be on my management VLAN.

            1 Reply Last reply Reply Quote 0
            • K
              kpa last edited by

              PfSense doesn't even support PVID on the interfaces because the operating system it's based on, FreeBSD, has no support for it. You'll need to use a VLAN capable switch anyway for that.

              1 Reply Last reply Reply Quote 0
              • johnpoz
                johnpoz LAYER 8 Global Moderator last edited by

                "vlan 1 untagged on all ports (hard coded) "

                What kind of shitty switch is that?  Even the 30$ smart switches allows you to change the pvid of the ports..

                Here is a cheap switch I got for I believe like 25$ as you can see I can change the pvid of a port.. So this is the untagged vlan that is on that port.. Which is what you would connect to pfsense port you have your vlans on.  See the ports that are in pvid 20.. That is the native vlan I have on pfsense interface that other vlans run on.

                What is the make and model of this switch your using??


                1 Reply Last reply Reply Quote 0
                • First post
                  Last post

                Products

                • Platform Overview
                • TNSR
                • pfSense
                • Appliances

                Services

                • Training
                • Professional Services

                Support

                • Subscription Plans
                • Contact Support
                • Product Lifecycle
                • Documentation

                News

                • Media Coverage
                • Press
                • Events

                Resources

                • Blog
                • FAQ
                • Find a Partner
                • Resource Library
                • Security Information

                Company

                • About Us
                • Careers
                • Partners
                • Contact Us
                • Legal
                Our Mission

                We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                Subscribe to our Newsletter

                Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                © 2021 Rubicon Communications, LLC | Privacy Policy