• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] Problem Vlan Trunk with cisco switch

Scheduled Pinned Locked Moved General pfSense Questions
46 Posts 5 Posters 7.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O
    omarmohammed
    last edited by Apr 1, 2018, 3:23 PM

    Do i need a static route from pfsense to switch ??? the switch is only a layer 2 switch, it cannot manage to make it work ???

    1 Reply Last reply Reply Quote 0
    • O
      omarmohammed
      last edited by Apr 1, 2018, 5:50 PM Apr 1, 2018, 5:12 PM

      when trying to ping from pfsense, there are no arp replies : the router doesnt reply to pfsense ! and this reply is shown on the other side !

      My guess is that the switch doesnt let throught this arp, even his mac address is not showing pfsense mac address interface

      OK WHEN activating ip cef command in the switch those arp begin to pass ! now, i get only vlan 1 behind the mac address of pfsense, still no vlan 10 or 20 even thought the ping starts from the end router and the port connected to it is in vlan 20

      OK i added statically the mac address in the switch, and the arp entry in the end router, the ping request goes throught, the ping response stops at the switch, AND ALSO THE PING REQUEST IS TAGGED VLAN 20 but the ping response is not tagged !!

      1 Reply Last reply Reply Quote 0
      • D
        Derelict LAYER 8 Netgate
        last edited by Apr 1, 2018, 5:59 PM

        Post a screen shot of the pfSense Interfaces > Assignments screen

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • J
          JKnott
          last edited by Apr 1, 2018, 6:16 PM

          the arps are coming from the end router look at the ip adresses it's 10.4.20.1(int VLAN20) and 10.4.20.2(end router) it's you who is confused where do you see an arp coming from the pc

          In your first post, you say:

          the PC has as ip addr: 10.4.10.2

          Maybe I'm confused because I read what you wrote.

          Do i need a static route from pfsense to switch ??? the switch is only a layer 2 switch, it cannot manage to make it work ???

          You don't route to switches.  You route to IP networks.  Switches are transparent, forwarding only on MAC addresses.

          My guess is that the switch doesnt let throught this arp, even his mac address is not showing pfsense mac address interface

          Nonsense.  Switches pass Ethernet frames, no matter what they're carrying.

          AND ALSO THE PING REQUEST IS TAGGED VLAN 20 but the ping response is not tagged !!

          I mentioned that in an earlier reply.  You've got a configuration error somewhere.  I'd suspect the switch.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • O
            omarmohammed
            last edited by Apr 1, 2018, 6:35 PM

            here is the assignements screen attached

            to answer you JKnott 10.4.10.2 is not in the 10.4.20.0/24 subnet and there are NO ARP with the PC address in the wiresharks i provided that's why i dont know what you're talking about

            the switch conf also attached if you want, but i doubt that since its working with the router

            ![Sans titre.png](/public/imported_attachments/1/Sans titre.png)
            ![Sans titre.png_thumb](/public/imported_attachments/1/Sans titre.png_thumb)
            ![Sans titre1.png](/public/imported_attachments/1/Sans titre1.png)
            ![Sans titre1.png_thumb](/public/imported_attachments/1/Sans titre1.png_thumb)
            ![Sans titre2.png](/public/imported_attachments/1/Sans titre2.png)
            ![Sans titre2.png_thumb](/public/imported_attachments/1/Sans titre2.png_thumb)

            1 Reply Last reply Reply Quote 0
            • G
              gjaltemba
              last edited by Apr 1, 2018, 8:19 PM

              When you remove pfSense vm from the testbed, you also remove VMware Workstation and the physical nic from the testbed. I suggest that you make sure the physical nic on the host OS is able to handle a vlan trunk first. Then check that VMware Workstation vSwitch is configured to handle a vlan trunk as well. If all checks out then share the test results here if pfSense is still not handling the vlan trunk.

              I am guessing that the drivers for your nic does not handle vlan trunk.

              1 Reply Last reply Reply Quote 0
              • O
                omarmohammed
                last edited by Apr 1, 2018, 8:37 PM

                Please can you show me how to do that? when i went to the vmnet 7 configured i fould out that priority and vlan tag enabled and no value for vlan id i dont even know if this is there.

                here attached the conf for the VMNET 7 used in the int of pfsense, and also vmnet0 and vmnet 8, as for vmnet 1 to 6 and 9 to end, same config as vmnet 7 but different subnet ip (as shown also in the attached files)

                ![Sans titre.png](/public/imported_attachments/1/Sans titre.png)
                ![Sans titre.png_thumb](/public/imported_attachments/1/Sans titre.png_thumb)
                ![Sans titre1.png](/public/imported_attachments/1/Sans titre1.png)
                ![Sans titre1.png_thumb](/public/imported_attachments/1/Sans titre1.png_thumb)
                ![Sans titre3.png](/public/imported_attachments/1/Sans titre3.png)
                ![Sans titre3.png_thumb](/public/imported_attachments/1/Sans titre3.png_thumb)

                1 Reply Last reply Reply Quote 0
                • G
                  gjaltemba
                  last edited by Apr 1, 2018, 9:52 PM

                  First which OS (windows 10, linux) is hosting VMware Workstation? Which hardware nic is installed (intel i350)? Which driver (intel v23.1)?

                  1 Reply Last reply Reply Quote 0
                  • O
                    omarmohammed
                    last edited by Apr 1, 2018, 10:03 PM

                    windows 10,

                    as for the nic its in the attachement

                    ![Sans titre.png](/public/imported_attachments/1/Sans titre.png)
                    ![Sans titre.png_thumb](/public/imported_attachments/1/Sans titre.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • G
                      gjaltemba
                      last edited by Apr 1, 2018, 11:33 PM

                      Are you sure your nic driver is capable of handling vlan trunk?

                      1 Reply Last reply Reply Quote 0
                      • O
                        omarmohammed
                        last edited by Apr 2, 2018, 12:04 AM Apr 1, 2018, 11:48 PM

                        i dont know, what i'm now kinda sure about is that everything coming from pfsense on that interface goes out UNTAGGED and doesnt reach its destination

                        how can i know ???

                        I updated my nic's driver from 2.1.0.21  to 2.1.0.25… just trying... still dont know if it supports trunk

                        1 Reply Last reply Reply Quote 0
                        • D
                          Derelict LAYER 8 Netgate
                          last edited by Apr 2, 2018, 12:06 AM

                          The way you have it configured, RES will be untagged/native/PVID, VLAN10 will be tagged 10, VLAN20 will be tagged 20. Set the switchport to be the same.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • G
                            gjaltemba
                            last edited by Apr 2, 2018, 12:25 AM

                            @omarmohammed:

                            i dont know, what i'm now kinda sure about is that everything coming from pfsense on that interface goes out UNTAGGED and doesnt reach its destination

                            how can i know ???

                            I updated my nic's driver from 2.1.0.21  to 2.1.0.25… just trying... still dont know if it supports trunk

                            I would suggest running wireshark and check that the packets are tagged.

                            1 Reply Last reply Reply Quote 0
                            • O
                              omarmohammed
                              last edited by Apr 2, 2018, 12:38 AM

                              that s what i did : the coming packets to pfsense are tagged vlan 20, the ones coming out are untagged and bloqued in the switch

                              1 Reply Last reply Reply Quote 0
                              • G
                                gjaltemba
                                last edited by Apr 2, 2018, 1:25 AM

                                Just test the bare metal. Connect a device to a vlan 20 access port and ping win 10. Does it work?

                                1 Reply Last reply Reply Quote 0
                                • O
                                  omarmohammed
                                  last edited by Apr 2, 2018, 1:35 AM

                                  no because EVERY THING coming from pfsense is untagged and the switch wont let through untagged frames wome out of vlan20 interfaces (switch is normal, pfsense interface not working with any tag !)

                                  1 Reply Last reply Reply Quote 0
                                  • O
                                    omarmohammed
                                    last edited by Apr 2, 2018, 1:38 AM

                                    attachements if anything : adapters in gns3, should i use others so that the trunk work in pfsense ?

                                    and also my gns3 local server config (i use local server, not gns3 vm)

                                    ![Sans titre.png](/public/imported_attachments/1/Sans titre.png)
                                    ![Sans titre.png_thumb](/public/imported_attachments/1/Sans titre.png_thumb)
                                    ![Sans titre1.png](/public/imported_attachments/1/Sans titre1.png)
                                    ![Sans titre1.png_thumb](/public/imported_attachments/1/Sans titre1.png_thumb)

                                    1 Reply Last reply Reply Quote 0
                                    • O
                                      omarmohammed
                                      last edited by Apr 2, 2018, 3:47 AM Apr 2, 2018, 3:43 AM

                                      Attachement : WITH pfsense: arp replies with no tag ! every arp request comes with a tag,

                                      WITH router : arp replies with the appropriate tag!

                                      the encapsulation of frames is not working in the pfsense interface !

                                      so either a problem with pfsense, or the interface or some gns3 vmware config : the encapsulation of frames is not working in the pfsense interface !

                                      Edit : ping echo from pfsense comes out untagged, is there any sort of thing such as enable vlans… ???

                                      i also dont know what to do regarding the interfaces used in vmware or gns3 i dont actually know if it is correct if the configs in the screens i provided were correct

                                      [reply (pfsense) no tag.pcapng](/public/imported_attachments/1/reply (pfsense) no tag.pcapng)
                                      [reply (router) with tag.pcapng](/public/imported_attachments/1/reply (router) with tag.pcapng)

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        Derelict LAYER 8 Netgate
                                        last edited by Apr 2, 2018, 3:52 AM

                                        VLAN tagging works fine on pfSense. You are doing it wrong. Look again.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • O
                                          omarmohammed
                                          last edited by Apr 2, 2018, 4:13 AM Apr 2, 2018, 4:06 AM

                                          what did i do wrong >< i cannot seem to find any answer ! i provided everything in all configuration things if i can provide anything more please tell me i'm running out of ideas

                                          Here again everything step by step : (i could provide images, but its the same)

                                          Vlans created : from em3 (the correct interface) : 10 and 20, no description, no priority set

                                          interface created from vlan 10 : named VLAN10, static ip for ipv4 only, ip addr 10.4.10.1 /24, the rest left blank or default (no gateway too)
                                          interface created from vlan 20 : named VLAN20, static ip for ipv4 only, ip addr 10.4.20.1 /24, the rest left blank or default (no gateway too)

                                          the configuration in the RES interface (em3) : name em3, no ip addr, rest is blank or default.

                                          all three interfaces are enabled.

                                          rules : 2 rules for each :

                                          allow ipv4, protocole any, source any to destination any, rest is blank or default
                                          allow ipv4, protocole any, source any to destination any, rest is blank or default

                                          i try to communicate from the end devices to their default gateways using VLAN10 and 20 and the ports are in VLAN10 and 20 but the replies are not tagged

                                          as for gns3 and vmware configs, refer to previous attachements

                                          this is so frustrating…

                                          1 Reply Last reply Reply Quote 0
                                          38 out of 46
                                          • First post
                                            38/46
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received