<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN setup question]]></title><description><![CDATA[<p dir="auto">Hello all!</p>
<p dir="auto">I am really sorry because I know these should be really basic questions but for some reason I'm having major problems with my VLAN setup.</p>
<p dir="auto">I have been using pfsense for some time now and I love it! I just updated to newest 2.3.4 release and it is working great.</p>
<p dir="auto">But I have problems configuring my VLANs. I have not had VLANs before but I would like to have them now for reason that are long :)</p>
<p dir="auto">Currently I have<br />
WAN<br />
LAN 192.168.1.1</p>
<p dir="auto">Here is what I would like to have:</p>
<p dir="auto">WAN<br />
VLAN10 - IP 10.10.10.1<br />
VLAN20 - IP 10.10.20.1<br />
VLAN30 - IP 10.10.30.1<br />
VLAN40 - IP 10.10.40.1</p>
<p dir="auto">and all the VLANs are on the same physical port on my pfsense box. This port has been LAN previously. I followed this guide</p>
<p dir="auto">https://www.highlnk.com/2014/06/configuring-vlans-on-pfsense/</p>
<p dir="auto">and it is great until it tells me to set DHCP servers for all the VLAN interfaces. There is only one and that is VLAN10 and this is the one that was previously LAN. I noticed this topic here</p>
<p dir="auto">https://forum.pfsense.org/index.php?topic=130059.0 Unable to enable DHCP server for OPT1 interface</p>
<p dir="auto">and in there it was said "When an interface has StaticIPv4 and a static IPv4 address and CIDR then there should be a tab for that interface in DHCP Server.". I do not know if I have CIDR on these interfaces since I could not locate anything related to that in the menus but I do have static IPv4 addresses for all of them.</p>
<p dir="auto">If I just move forward and connect my managed switch and set up VLANs there, nothing works and no device connected to the switch are able to connect internet. I had configured my switch so that my Wireless AP (port 2 on switch) had Tagged and for example my Xbox (port 3 on switch) has Untagged but neither is working.</p>
<p dir="auto">I think that the problem, or at least the biggest problem, is pfsense configuration and DHCP servers? Could you tell me how to properly set up VLANs on pfsense with newest GUI or if it is even possible to do what I am trying to do? I do manage to connect the webGUI on WAN port.</p>
<p dir="auto">Thank you in advance!</p>
<p dir="auto">Edit:<br />
And just to add that on my switch I have just copied my VLAN information from pfsense and then tagged the ports for all the VLANs and left the default VLAN1 just as it is</p>
<p dir="auto">Edit2: Okay I got the answer for the DHCP server thing from the other topic. I too had /32 there. But I do not know if this helps to get the whole thing working. I will try.</p>
]]></description><link>https://forum.netgate.com/topic/115267/vlan-setup-question</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 10:48:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/115267.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 06 May 2017 14:35:28 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN setup question on Mon, 15 May 2017 17:00:38 GMT]]></title><description><![CDATA[<p dir="auto">EDIT: This is working. Problem was wrongly configured management in switch.</p>
]]></description><link>https://forum.netgate.com/post/699532</link><guid isPermaLink="true">https://forum.netgate.com/post/699532</guid><dc:creator><![CDATA[sampr12]]></dc:creator><pubDate>Mon, 15 May 2017 17:00:38 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN setup question on Sun, 07 May 2017 13:31:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lebernd">@<bdi>lebernd</bdi></a>:</p>
<blockquote>
<p dir="auto">Yes it is probably more of a switch setting then pfsense setting issue.<br />
Turn on tagged VLAN on the switch-port connected to pfsense. (it depends - is there a standard VLAN on the switch? If it is 10, 20… you only have to tag the others)</p>
<p dir="auto">My guess</p>
</blockquote>
<p dir="auto">After I added ipv6 to firewall rules it started working and now I have everything up and running! Only problem is that all the VLANs can talk to each other so I need to block it with firewall rules.</p>
<p dir="auto">But thank you everyone for your help! Everything is great now and I have my VLANs!</p>
]]></description><link>https://forum.netgate.com/post/697885</link><guid isPermaLink="true">https://forum.netgate.com/post/697885</guid><dc:creator><![CDATA[sampr12]]></dc:creator><pubDate>Sun, 07 May 2017 13:31:28 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN setup question on Sun, 07 May 2017 13:01:35 GMT]]></title><description><![CDATA[<p dir="auto">Yes it is probably more of a switch setting then pfsense setting issue.<br />
Turn on tagged VLAN on the switch-port connected to pfsense. (it depends - is there a standard VLAN on the switch? If it is 10, 20… you only have to tag the others)</p>
<p dir="auto">My guess</p>
]]></description><link>https://forum.netgate.com/post/697879</link><guid isPermaLink="true">https://forum.netgate.com/post/697879</guid><dc:creator><![CDATA[lebernd]]></dc:creator><pubDate>Sun, 07 May 2017 13:01:35 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN setup question on Sun, 07 May 2017 13:32:15 GMT]]></title><description><![CDATA[<p dir="auto">Okey so I have made progress but still not working.</p>
<p dir="auto">What I have done is I left my LAN is it is so I have WAN &amp; LAN normally and working. But I added new interface (my PFSense has 4 ethernets) and added the VLANs to that.</p>
<p dir="auto">/Deleted obsolete img/</p>
<p dir="auto">I have added DHCP serveres to all the VLANs. Problem now is that my managed switch is not able the get IP from DHCP. If I remove VLAN10 from OPT5 and just put em2 on it, the switch is able to get IP from DHCP but VLANs are not working.</p>
<p dir="auto">What I am doing wrong here?</p>
<p dir="auto">I have also added the firewall rules like it is adviced on the link in my first post.</p>
<p dir="auto">Edit: Question - Should I add the ethernet port that is connected from PFSense to switch into trunk port or no?</p>
<p dir="auto">Edit2: I modified firewall rules on one VLAN from "Protocol IPv4" to "Protocol IPv4+6" and now one of my VLANs are working fine… Or at least my console is able to get IP through switch and that IP is in one of my VLANs</p>
]]></description><link>https://forum.netgate.com/post/697861</link><guid isPermaLink="true">https://forum.netgate.com/post/697861</guid><dc:creator><![CDATA[sampr12]]></dc:creator><pubDate>Sun, 07 May 2017 13:32:15 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN setup question on Sat, 06 May 2017 16:54:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phil.davis">@<bdi>phil.davis</bdi></a>:</p>
<blockquote>
<p dir="auto">You also need to make sure to check the "Enable" box at the top of the interface page.<br />
If the interface is not enabled, then it will not show you a DHCP tab.</p>
<p dir="auto">And CIDR <a href="https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing" target="_blank" rel="noopener noreferrer nofollow ugc">https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing</a> refers to "CIDR notation" which is the way of putting "/24" at the end of an IP address. It effectively specifies the netmask, which is 255.255.255.0 in that case.</p>
<p dir="auto">I tend to write CIDR, because if I say netmask then I feel like someone could quite rightly go looking for a place to type in 255.255.255.0 or 11111111.11111111.11111111.00000000</p>
</blockquote>
<p dir="auto">I have enabled them so that is not the problem. I will try tomorrow!</p>
]]></description><link>https://forum.netgate.com/post/697767</link><guid isPermaLink="true">https://forum.netgate.com/post/697767</guid><dc:creator><![CDATA[sampr12]]></dc:creator><pubDate>Sat, 06 May 2017 16:54:29 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN setup question on Sat, 06 May 2017 15:38:12 GMT]]></title><description><![CDATA[<p dir="auto">You also need to make sure to check the "Enable" box at the top of the interface page.<br />
If the interface is not enabled, then it will not show you a DHCP tab.</p>
<p dir="auto">And CIDR <a href="https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing" target="_blank" rel="noopener noreferrer nofollow ugc">https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing</a> refers to "CIDR notation" which is the way of putting "/24" at the end of an IP address. It effectively specifies the netmask, which is 255.255.255.0 in that case.</p>
<p dir="auto">I tend to write CIDR, because if I say netmask then I feel like someone could quite rightly go looking for a place to type in 255.255.255.0 or 11111111.11111111.11111111.00000000</p>
]]></description><link>https://forum.netgate.com/post/697752</link><guid isPermaLink="true">https://forum.netgate.com/post/697752</guid><dc:creator><![CDATA[phil.davis]]></dc:creator><pubDate>Sat, 06 May 2017 15:38:12 GMT</pubDate></item></channel></rss>