Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I cannot route between LAN and VLAN

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 4 Posters 445 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      greymouser
      last edited by

      I have a basic pfSense router setup:
      pfsense_router.PNG

      I'm trying to setup a separate network to be used by my IOT devices. Does it even need to be a VLAN if it's on it's own port? Anyway here's my setup and here are my firewall rules:

      firewall_rules2.PNG

      I have a simple device on my IOT network using static IP 192.168.1.206 and I'm not able to access it from my LAN network. I am able to ping the IOT gateway which is 192.168.1.1. but if I attempt to ping 192.168.1.206 it just times out.

      I'm new to pfSense, but I've followed what documentation I've been able to find and setup my IOT VLAN as much like my LAN network. What am I missing?
      When I setup a firewall rule that says LAN net can allow ANY access to my IOT net, that should include all VLAN communications as well right?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • G
        gertty
        last edited by

        Random guess: Are you using a /24 subnet or /16? I've seen this sort of problem when a device has an interface with a 255.255.0.0. subnet mask while everything else has 255.255.255.0. The result of this would be that device wouldn't bother trying to route thru a gateway because it thinks the destination is on the same subnet.

        1 Reply Last reply Reply Quote 0
        • N
          NOCling
          last edited by

          GW settings of the IoT Device?

          No GW no answer from other Subnet.

          Netgate 6100 & Netgate 2100

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @greymouser
            last edited by

            @greymouser said in I cannot route between LAN and VLAN:

            Does it even need to be a VLAN if it's on it's own port?

            No it doesn't - but what are you connecting these ports too? You can not just connect them to a dumb switch.. You need to either use different dumb switches for your different networks. Or you need to be connecting to a single device.

            If your connecting into a switch - then you will need to setup up vlans on the switch for your different ports.. Pfsense doesn't have to know anything about them.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.