Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Accessing VLAN from LAN

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 4 Posters 723 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      ypapouin
      last edited by ypapouin

      Hi,

      I've just added a VLAN 192.168.68.0/24 to my pfsense router but I would like to be able to access a PBX (192.168.68.2) from my LAN 192.168.1.0/24.
      I tried to create a NAT rule to access the webserver but it is not working.

      What is the best way to achieve this ?

      JKnottJ 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        @ypapouin said in Acessing VLAN from LAN:

        've just added a VLAN 192.168.68.0/24 to my pfsense router bu

        Why would you create a NAT rule, its RFC1918 address space?

        Post a screenshot of your LAN and VLAN rules.

        It could be an issue with your switch.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @ypapouin
          last edited by

          @ypapouin

          Why do you need NAT? It's just plain routing. You just have to create a rule that allows your traffic to get from one network to the other.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            The PBX may not be accessible from outside it's own subnet. In that case an outbound NAT rule on the vlan would allow it but it would be better to configure the pbx to allow the traffic instead.

            Otherwise, yeah, you should need nothing other than a firewall rule on LAN to pass that traffic.

            Steve

            1 Reply Last reply Reply Quote 0
            • Y
              ypapouin
              last edited by ypapouin

              You are right, I don't know why I was focused on creating a NAT rule instead of a direct one.
              I created a rule without restricting any IP/Protocol/Port that works perfectly.
              Thank you for leading me to the right way.

              pfsense-lan-to-vlan.png

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                You could narrow that destination to just the PBX IP if that's the only thing you need access to in that subnet.

                Steve

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.