Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Connecting to VLAN devices

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Dayve
      last edited by

      I have setup a VLAN for all my Surveillance cameras. When I'm connected to my wifi I can access all cameras with no problem. But when I plug in to the Ethernet port to my network and turn off my wifi I can no longer connect to any camera.
      Would this be a firewall rule?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Are you plugging into the same vlan as your wireless network or some other network. How are you trying to access your camera(s)?

        Via some layer 2 discovery protocol - via IP, via some name? What port?

        Out of the box pfsense lan rules are any any. So if you created another network/vlan your lan rules would not block you from accessing anything be it the internet or some other vlan/network attached to pfsense.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • D
          Dayve
          last edited by

          Think I got it. Seems like my LAN card in my laptop locked up. I did a restart and now I can connect to all IP's on the VLAN.
          Now which way is the best to setup the firewall rules? I don't want the VLAN to have access to the internet and I dont want the internet to have access to the VLAN. But I still want access internal.

          This is what I have done for firewall rules. Hope it right.

          0_1534350891791_5e18138a-f7c8-4d39-8d62-2bb2b406615e-image.png

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            The 1st rule allows your surv net to access lan net.. But the 2nd rule is pointless - there would never be inbound traffic into the surv interface from lan net IP range..

            To be honest if all you want to do is access surv net from lan net - and you don't wan surv net to go anywhere or do any sort of internet then you need zero rules on surv interface.

            Your lan net any any rules would allow your lan to talk to surv net.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • D
              Dayve
              last edited by

              Perfect. Deleted both rules and all is good.

              Thank you for your help :)

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                great, enjoy your new vlan and isolated cameras..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • D
                  Dayve
                  last edited by

                  Thanks for your help before.
                  Just wondering if you could help with a little more on my vlan for the cameras.

                  I have a Amcrest NVR that records 24/7 and is accessible through a p2p connection. Now I know that the cameras are isolated from the internet and that no longer works is there a secure way so I could still login to the NVR to view the cameras when I,m outside my network?

                  I have a OpenVPN connection setup already. Is there way to do it through the VPN or would you suggest something better?

                  JKnottJ 1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @Dayve
                    last edited by

                    @dayve said in Connecting to VLAN devices:

                    is there a secure way so I could still login to the NVR to view the cameras when I,m outside my network?

                    In my experience with the recorders is they have 2 ports, one for the cameras and one for remote access. Does yours have that?

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    D 1 Reply Last reply Reply Quote 0
                    • D
                      Dayve @JKnott
                      last edited by

                      @jknott It only has one port.

                      JKnottJ 1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @Dayve
                        last edited by

                        @dayve said in Connecting to VLAN devices:

                        @jknott It only has one port.

                        Then you'll have to set up a route to the camera VLAN. Since you want to be able to access it when away from your network, you could use a VPN and only allow that address to be forwarded to that VLAN.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        D 1 Reply Last reply Reply Quote 0
                        • D
                          Dayve @JKnott
                          last edited by

                          @jknott
                          Thanks. That's what i was thinking. Now I just need to figure out how to do that.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            When you say you have vpn - not talking about some vpn service you have to hide your shit from your isp. Talking about a remote access vpn.

                            https://www.netgate.com/docs/pfsense/vpn/openvpn/openvpn-remote-access-server.html

                            This is how you access your camera's while you are remote..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            D 1 Reply Last reply Reply Quote 0
                            • D
                              Dayve @johnpoz
                              last edited by

                              @johnpoz

                              Yes its a remote access vpn.

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by johnpoz

                                well then if your on your vpn and you have listed your vlan as a local network in your vpn config - you would be able to access it while on your connected to the vpn. As long as this vlan network does not overlap with your vpn clients local network, and or its not the same as your tunnel network used in your vpn connection.

                                example - these are 3 of my vlans I can access while connected to my vpn

                                0_1534509132873_vpnaccesstolocalnetworks.png

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                D 2 Replies Last reply Reply Quote 0
                                • D
                                  Dayve @johnpoz
                                  last edited by

                                  @johnpoz
                                  Sorry I was out of the country for a few weeks. Would have been nice to have this working before I left.
                                  Got it now. Just had to add the subnet in like you said.

                                  Thank you.

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    Dayve @johnpoz
                                    last edited by

                                    @johnpoz

                                    Hey John,

                                    You were so helpful before. Could I ask for some more help?

                                    I'm trying to setup a VPN with Nordvpn service that I subscribe to. The Nordvpn client services is up and running on pfsense.

                                    What I,m trying to do is a separate Wifi ssid on my unifi ap controller with a VLAN 60 to route just to the Nordvpn. Setup of the unifi was easy and working.
                                    0_1537372122291_a2df9c25-d8fa-4881-901a-d96dc68c7728-image.png

                                    What would be the next steps to pfsense to have this work?

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by johnpoz

                                      Setup vlan 60 firewall rules to use your vpn gateway..

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.