<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN 255 and SIP bug?]]></title><description><![CDATA[<p dir="auto"><a href="https://www.reddit.com/r/PFSENSE/comments/7rko7s/sip_dual_invites_on_wan_single_on_lan/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.reddit.com/r/PFSENSE/comments/7rko7s/sip_dual_invites_on_wan_single_on_lan/</a></p>
<p dir="auto">Basically VLAN 255 seems to be getting caught in a default deny rule, yet traffic is flowing on a different VLAN. Tested version 2.4.2-P1.</p>
<p dir="auto">I realize I have not reset to defaults and tried just adding VLAN 255 only and seeing what happens.  I hope to do that tomorrow but wanted to post this anyway.</p>
<p dir="auto">Scenario:<br />
Phone is on VLAN 2.<br />
pfSense has VLAN 2 interface, IP structure, rules, outbound NAT, etc.<br />
Everything shows there is no weird switch funkiness or VLAN issues on the LAN side of pfSense.  Pfsense sees VLAN 2.  Sees the phone mac/proper IP in VLAN 2 interface, etc.<br />
Phone can register with provider.<br />
Phone can receive calls.<br />
Phone cannot make calls - pcap on LAN side - VLAN 2 interface - on pfsense shows single invite, yet on WAN side, shows dual SIP messages (INVITES, OKs, ACKS, etc, same call-id) so the provider is rejecting due to overlapping requests.<br />
Other VLANs in 2xx exist on the pfSense box.</p>
<p dir="auto">When a call is made, an examination of the default filter shows that inbound sip traffic is being blocked on interface bce1.255.  Yet…none of the traffic goes to/from VLAN 255.  For some reason, the traffic is entering the WAN, and getting associated with 255 instead of 2, where the phone is.  Changing VLAN 255 to another VLAN #, everything works properly.</p>
<p dir="auto">Possible bug?</p>
]]></description><link>https://forum.netgate.com/topic/126025/vlan-255-and-sip-bug</link><generator>RSS for Node</generator><lastBuildDate>Mon, 09 Mar 2026 11:53:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/126025.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 20 Jan 2018 20:40:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN 255 and SIP bug? on Sun, 21 Jan 2018 17:19:23 GMT]]></title><description><![CDATA[<p dir="auto">Definitely some weird layer 2 issues going on.</p>
<p dir="auto">When I mirror the trunk port on the Dell N2024P switch that goes to pfSense I see one SIP message from VLAN 2 (correct) and immediately after VLAN 255 (incorrect).  So something is splitting traffic up.</p>
<p dir="auto">Strange bug on the Dell side of things.  I'll continue to investigate, but it makes sense as to what pfsense was seeing now.</p>
<p dir="auto"><a href="https://imgur.com/a/LpCmB" target="_blank" rel="noopener noreferrer nofollow ugc">https://imgur.com/a/LpCmB</a></p>
<p dir="auto"><strong>edit</strong><br />
Two solutions, that I'll raise with Dell:<br />
Disable ip routing solves the problem<br />
Also leaving ip routing enabled, but removing the switches default gateway also fixes it.</p>
]]></description><link>https://forum.netgate.com/post/747059</link><guid isPermaLink="true">https://forum.netgate.com/post/747059</guid><dc:creator><![CDATA[replaceyourfirewall]]></dc:creator><pubDate>Sun, 21 Jan 2018 17:19:23 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN 255 and SIP bug? on Sun, 21 Jan 2018 03:07:11 GMT]]></title><description><![CDATA[<p dir="auto">If the switch was sending VLAN 2 as 255, then pfsense would block it regardless, since my rule for that VLAN 255 interface has no rules - so default deny.  So why is some communication getting out then?  Also, the only config change I make to get the phone to work is on pfsense to change the interface tag from 255 to something else (100 is what I tested with) so I don't think that's it.</p>
<p dir="auto">I have a few more things to explore tomorrow help narrow down what is going on.  I'll reset to defaults and just try to setup a single VLAN 255 - and also snag a new POE switch - and see if the problem occurs.  I'll also drop LLDP-MED and do some hard coding of VLANs on the phone.  However, I don't think that's it since the switch and pfsense do see the phone in VLAN 2 as expected.</p>
<p dir="auto">I do agree that it's probably a configuration error - but where remains to be seen!  I'll be sure to report back if I figure out what is going on, or if there was a bone headed thing I did without realizing it.</p>
<p dir="auto">Thanks for your reply.</p>
]]></description><link>https://forum.netgate.com/post/747016</link><guid isPermaLink="true">https://forum.netgate.com/post/747016</guid><dc:creator><![CDATA[replaceyourfirewall]]></dc:creator><pubDate>Sun, 21 Jan 2018 03:07:11 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN 255 and SIP bug? on Sun, 21 Jan 2018 01:35:36 GMT]]></title><description><![CDATA[<p dir="auto">almost certainly not a bug, but a configuration error. If traffic is being blocked it is because it is being blocked.</p>
<p dir="auto">Sounds like your layer 2 is hosed. VLAN2 traffic should not be arriving tagged with 255.</p>
]]></description><link>https://forum.netgate.com/post/747011</link><guid isPermaLink="true">https://forum.netgate.com/post/747011</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Sun, 21 Jan 2018 01:35:36 GMT</pubDate></item></channel></rss>