Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Bridged VLAN not passing parent MAC in ARP response

    L2/Switching/VLANs
    1
    2
    126
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      follysuperscript last edited by follysuperscript

      Hello,

      Thank you for this incredible software package. I use it constantly and appreciate all the hard work that goes into it. I've spent enough time searching these forums to know that questions related to bridging often elicit frustrated responses. Questions related to VLANs and bridging at the same time garner even more frustrated responses. So it is with great hesitation I explain my issue.

      I have a VLAN interface bridged...
      The parent bridge is assigned an IP address and a MAC address.
      The VLAN interface has no configured IP, the MAC section is grayed out, stating "The MAC address of a VLAN interface must be set on its parent interface"
      Related system tunables have been set
      net.link.bridge.pfil_member to 0.
      net.link.bridge.pfil_bridge to 1.

      When I boot up a host in this bridge, it gets an IP address, ARPs for the gateway and the gateway responds with the bridge MAC address. No further uni-cast traffic makes it to the bridge or VLAN interface according packet captures.

      If I change the bridge address (dangerously?) to the VLAN member's parent (duplicate) mac, all traffic starts flowing. No firewall issues. It seems like a L2 MAC / ARP issue.

      It seems that the MAC address of the VLAN interface is what is needed to for host communications to flow, but the bridge interface MAC address gets stored in the host's ARP cache and doesn't work.

      Any ideas on how to get this to work without a duplicate MAC? I'm sure there is a simple network concept that I'm not aware of that can resolve this (please don't say "buy a switch", although I'm sure it will be comment 1).

      Any help appreciated!

      1 Reply Last reply Reply Quote 0
      • F
        follysuperscript last edited by

        After thinking about how MAC addresses work on a switch, I replicated the MAC across all bridge members and the bridge itself, and things began working!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post

        Products

        • Platform Overview
        • TNSR
        • pfSense Plus
        • Appliances

        Services

        • Training
        • Professional Services

        Support

        • Subscription Plans
        • Contact Support
        • Product Lifecycle
        • Documentation

        News

        • Media Coverage
        • Press
        • Events

        Resources

        • Blog
        • FAQ
        • Find a Partner
        • Resource Library
        • Security Information

        Company

        • About Us
        • Careers
        • Partners
        • Contact Us
        • Legal
        Our Mission

        We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

        Subscribe to our Newsletter

        Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

        © 2021 Rubicon Communications, LLC | Privacy Policy