Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CAN NOT PING IN SAME VLAN ?

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    10 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      atcm89
      last edited by

      I have 3 vlan. VLAN 1 ( 172.16.46.0/24), Vlan 2 (172.16.52.0/21), Vlan 3 (11.11.11.0/24).
      I setup rule on vlan2 can connect to vlan 1 and vlan 3 ( it's working). My laptop (172.16.54.161) on vlan 2 can ping to ip address : 172.16.52.9 (vlan 2) but can not ping to address 172.16.54.223 (vlan2) (same vlan). Host 172.16.54.223 can connect to internet. What wrong with me?

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by chpalmer

        First thing.. 11.x.x.x/anything is most likely not yours to use.

        Unless your with the DOD..

        VLAN 2 covers 172.16.48.1 - 172.16.55.254 /21

        Nothing in this range trying to connect to something else in this range would touch the firewall. This would not be a pfsense issue. Most likely client firewall or incorrect subnet setup.

        What kind of device is 54.223?

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        chpalmerC 1 Reply Last reply Reply Quote 0
        • A
          atcm89
          last edited by atcm89

          Thank for answer.
          54.223 is a desktop using win 10.
          I'll turn off the firewall in this machine but same error.
          IP of it get from DHCP of pfsense.

          ed37e390-1bb8-46c8-aceb-e18f8634dcf9-image.png

          eeda1b5e-dcdf-4629-87fb-6dc26f526107-image.png

          chpalmerC 1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer @atcm89
            last edited by

            @atcm89

            What kind of switch and how is it set up?

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            chpalmerC 1 Reply Last reply Reply Quote 0
            • A
              atcm89
              last edited by atcm89

              It is cisco SG300-28.
              (VLAN2 is 2690(id)
              78ded5a6-d111-4e1c-aa5b-48d02c054dab-image.png

              18c02f9d-1a58-4775-80e4-6c3d68d8d3f1-image.png[link text]

              1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer @chpalmer
                last edited by chpalmer

                @chpalmer said in CAN NOT PING IN SAME VLAN ?:

                And which port is the suspect client computer plugged into?

                Have you tried a different ethernet cable?

                Can this client ping the switch?

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                1 Reply Last reply Reply Quote 0
                • A
                  atcm89
                  last edited by

                  I think this is not problem from the switch. I try change ip host to 172.16.52.253. I can ping host from host in vlan 1:
                  c7e85ec9-6602-4ed9-90c4-68f04d2fa194-image.png

                  But can not ping from my laptop:

                  3fc0eea1-e50c-46c1-b1ee-ba37bb04b077-image.png

                  0460419b-adfa-4947-88ae-6b35bea8fa85-image.png

                  1 Reply Last reply Reply Quote 0
                  • chpalmerC
                    chpalmer @chpalmer
                    last edited by

                    @chpalmer said in CAN NOT PING IN SAME VLAN ?:

                    ...

                    You do understand how subnetting works right?

                    If your clients (on the same subnet) and switch are configured correctly then traffic between the two clients will never touch the firewall. Period.

                    Client - Switch - Client.

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    1 Reply Last reply Reply Quote 0
                    • A
                      atcm89
                      last edited by

                      Thank very much!
                      I was fix my problem.
                      Vlan 2 i connected to wifi unifi, in unifi I was set range ip /24 (vlan subnet /21).
                      Tks very much againt about suggestion of you!

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        @atcm89 said in CAN NOT PING IN SAME VLAN ?:

                        Vlan 3 (11.11.11.0/24).

                        Unless that is a typo - or your hiding public space you actually own - that should be changed.. Its not good idea to use public space that is not actually yours.

                        There really is not good reason to do that either - since there is plenty of rfc1918 you could use..

                        10.10.10/24 would be valid rfc1918 space you could use.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.