Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Please help me to understand VLANs finally :/

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    4 Posts 2 Posters 260 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fhegedus
      last edited by

      Hello,

      I'm a networking noob who is trying to be better without not much success :) . I'm running pfSense on an esxi 6.7 host where I assigned the 4095 VLAN id to the port group which is assigned to the pfSense vm. My goal with the 4095 id was to pass every VLAN to pfSense.
      b3037a0e-c512-4af6-9ddf-4c6862aed291-image.png
      My Ubiquity ES-8-150 is connected to the pfSense on port8. I created the VLAN50 and added port1,3 and port8(trunk) to it. Port3 is excluded from the default vlan (1) and port 1 is not. My goal with this was to have port3 only belong to vlan 50.
      ecc2e6e5-ec88-479c-9280-3f6699ed0442-image.png
      In pfsense I created the VLAN 50 (parent is the LAN interface) (they both use the same nic which is connected to port8.
      bda9cea5-f5cb-4443-ba99-348802e1ac8c-image.png
      And assigned to interface VLAN50 and enabled it.
      2114b978-7dbc-4a95-81b1-d81e39f7c703-image.png
      Set up the DHCP on VLAN50, do I have add the interface ip as gateway here?
      197ab4ec-963c-4493-ba29-4ccf42393e8f-image.png
      Since I just want to test the vlans my only goal was to get an ipaddress from the 192.168.5.x range if i plug my laptop in port3. On the firewall tab I just created allow all rules:
      LAN:
      a1a8cb3c-04d2-423b-9b9a-36d98d4d8937-image.png
      VLAN50:
      24e5bc40-fa34-4d3d-8a9e-fa24564cbdbe-image.png

      Unfortunately when I connect my laptop to port 3 I did not get any ip assigned and I have no internet connection.

      6c26b60d-9d3d-40c2-b40d-1495ec3f940d-image.png

      What did I wrong?

      Thanks in advance!

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by

        yeah vlan 1 is excluded and vlan50 is still tagged
        you need to set vlan50 untagged on port 3 or set the network card of your laptop to use vlan50

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • F
          fhegedus
          last edited by

          Thanks! Now it's working :)
          So in general when I have an access port it should be untagged? BTW how can I configure my network card under win 10 to use a specific VLAN?

          I'd like to connect my WAP to port1 and configure 2 SSID one with VLAN50 and one with default. In this case how should set my port? Tagged both for VLAN50 and VLAN1?

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by

            it's not always possible but for realtek you need to install Realtek Ethernet Diagnostic Utility
            for intel you do that inside the network card settingswtXcv.jpg vlan3.gif

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.