Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN on WAN - not working

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    6 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tadpole
      last edited by tadpole

      Hello,

      We use an XG 7100 - PF 2.4.3. We added 2 VLAN (10 and 30). There are configured to create a PPPOE session and a DHCP session. However they do not receive any IP. The PPPOE session states that the connection timed out. The DHCP session states no DHCPOFFERS received. The firewall is directly linked to the modem of the provider.

      Because it did not work, we tried to change the default WAN interface with VLAN 4090. When we configured it as PPPOE or DHCP it worked. When we changed the default VLAN 4090 for example to 10, 11 or 30 it gave the same error as before (connection timed out and no dhcpoffers received).

      Could someone please me this behavior?

      Thank you.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • jahonixJ
        jahonix
        last edited by

        The provider modem doesn't seem to use those VLAN IDs - OR untags the traffic already for you. Check the modem's WebUI if possible.

        I can assure you that VLANs on WAN work hassle free. I (have to) use VLAN7 for my PPPoE connection on WAN and it's working consistently for years.

        1 Reply Last reply Reply Quote 0
        • T
          tadpole
          last edited by

          This is what the modem shows:

          0_1531584653211_d7d762a2-fb95-4bbf-b5b3-585da14bca88-image.png
          0_1531584666460_dd74fa4f-1b0f-4b0e-bdfa-8cb67a1c91f6-image.png
          0_1531584674867_11a67789-7f46-42d7-8d76-0ff8d1366460-image.png
          0_1531584681518_be0ed672-ed3a-4c22-8693-70abfa464275-image.png

          PFSense is using PPPOE via default VLAN 4090. If I change that VLAN to 10, it does nothing.
          The ISP uses VLAN 10 for internet and VLAN 30 for IPTV. In order to make the decoders work, I need to create a separate VLAN. The decorders have to get their IP address from the ISP DHCP and not from my internal DHCP.

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @tadpole
            last edited by

            @tadpole

            ISPs do not normally support VLANs, except on dedicated connections. Also, VLANs do not pass over IP. I have set up several VLANs where the carrier was providing a fibre connection to the customer, but that was done at the Ethernet level. Please note that if there are any routers along the path, a VLAN will not work. PPPoE is considered layer 2 or "Ethernet", in that PPP can carry almost any protocol, including Ethernet, if so configured. If they're providing a VLAN, you have to use the one they provide, as the ones you want to use may be used elsewhere. Given that it works with 4090, but not others, I suspect that may be the case. Call your ISP to find out what your options are.

            Carriers & ISPs often use VLANs to separate customers and may use 2 levels of VLAN (Q in Q), so that the customer can use VLANs on top of the carrier's VLAN.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • T
              tadpole
              last edited by

              Ok thanks.

              If the ISP modem is connected with pfSense, could i manage in some way that the decorder receives an (internal) IP (10.10.*) from the ISP DHCP?

              The information that i received tells me that the ISP sends out VLAN 10 (internet)/30(IPTV) to the modem and from there on the traffic is untagged. The traffic is received untagged by pfSense. So I will use the internal switches to create the right vlan traffic.

              The only thing i don't understand is the pfSense setup. Could someone help me out?

              1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott
                last edited by JKnott

                The ISP may very well use VLANs to separate different types of traffic. However, that's not normally visible to a user. Again, you'll have to contact your ISP to see what they provide and then configure for it. Until we know what they require, we can't offer advice.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.