• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

VLAN - basics for a newbie [Solved]

Scheduled Pinned Locked Moved L2/Switching/VLANs
17 Posts 5 Posters 1.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    PM_13
    last edited by PM_13 Jan 1, 2021, 1:09 AM Dec 31, 2020, 9:45 PM

    Hi,

    I just started with VLAN and can use some help with basics. Here is my pfSense configuration:

    WAN
    LAN-1
    LAN-2
    LAN-3
    LAN-5 (runs a static IP subnet of 192.168.5.0)
    
    On LAN-5 I created an interface 55VLAN (tag: 55) and enabled it with DHCP server
    

    I am using a 8-port Trendnet managed switch, on this device I did following:

    
    1. Port-1 of managed switch is connected to LAN-5 of pfSense with cable
    2. On switch created a VLAN with tag 55 using Port-2 of the switch
    3. Added Port-1 to VLAN55 (as Static tagged)
    4. Added Port-2 to VLAN55 (as Static Untagged)
    
    

    The good news is that above arrangement is working fine & client machine connected to Port-2 of switch got a 192.168.55.x DHCP lease......bravo 2020 was not a lost cause after all 😊

    Now my question where I am getting confused due lack of in-depth knowledge.
    If I create another VLAN on switch say 33VLAN and use Port-1 as Static Tagged and Port-3 as Static Untagged.

    Question: Is there a way for packets that are coming from switch port-3 (with tags 33) to be transferred from LAN-5 port of PfSense to LAN-3 port where I could run another VLAN with 33 tag?

    I tried it but it did not work and I just want to know two things:

    1. Is this even doable?
    2. If yes then few pointers would be welcome!!

    Thanks!!

    J 1 Reply Last reply Dec 31, 2020, 10:07 PM Reply Quote 0
    • J
      JKnott @PM_13
      last edited by Dec 31, 2020, 10:07 PM

      @pm_13

      Traffic will not pass between VLANs, unless appropriate routing has been set up. You'd have to configure pfsense to route between 1 & 5.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      P 1 Reply Last reply Dec 31, 2020, 11:37 PM Reply Quote 0
      • P
        PM_13 @JKnott
        last edited by Dec 31, 2020, 11:37 PM

        @jknott Thanks for your input.

        Please see this topology that I think will solve the problem for my home network:

        topology.png

        Right now it is not working for me but based on my rudimentary understanding of VLANs, this topology should be working. Please correct me if I am wrong with my assumption or have incorrect understanding of VLANs.

        Apologies for the handwritten diagram but I was struggling to explain it in words.

        1 Reply Last reply Reply Quote 0
        • P
          PM_13
          last edited by Jan 1, 2021, 1:09 AM

          I got the above topology to work so got my answer!!

          VLANs are great, suddenly network topology seems more practical than even before 😁

          J 1 Reply Last reply Jan 1, 2021, 1:45 AM Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @PM_13
            last edited by Jan 1, 2021, 1:45 AM

            You should move one of the managed switches to where you have that unmanaged switch... It's fine to use a dumb switch downstream of a managed switch when all devices on the dumb switch are in the same vlan.

            I would not do it how you have it..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            P 1 Reply Last reply Jan 1, 2021, 2:57 AM Reply Quote 0
            • P
              PM_13 @johnpoz
              last edited by Jan 1, 2021, 2:57 AM

              @johnpoz thanks for excellent suggestion. It would also nip the problem in bud i.e how to confine IoTs to its own LAN.

              As I am configuring VLANs is there a good way to document details? I am not a network guy and just curious what professionals use to manage documentation for the network.

              Thanks for again for a very useful tip, have a great new year and happy 2021!!!

              J 1 Reply Last reply Jan 1, 2021, 4:12 AM Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator @PM_13
                last edited by Jan 1, 2021, 4:12 AM

                I would draw up your network with all the details on it. Even if its just a hand drawing like you have posted.

                You can get really fancy with something like visio.. I should really post up a pic of one of works DCs lan diagrams ;) have to pull out all the details before I could post it - but could be an interesting look for some.. But there are plenty of different software packages to help you maintain an diagram for from free to thousands of dollars.

                For IP management there are many different tools.. With differing budgets.. We use BT Diamond IP to manage IP space in the DC and different customers networks. But could be as simple as notepad doc..

                For my home network there really isn't much documentation because its only 8 vlans and all the ports in my managed switched are labeled in the switch software, etc. And keep in simple for vlan IDs where they match up with the 3 octet of the IP space being used.. For example one of my vlans is 192.168.6/24 - guess what the vlan ID is ;) 6

                If you really want to get fancy, you might want to look at something like https://github.com/netbox-community/netbox

                And its FREE ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                P B 2 Replies Last reply Jan 1, 2021, 4:49 AM Reply Quote 0
                • P
                  PM_13 @johnpoz
                  last edited by Jan 1, 2021, 4:49 AM

                  @johnpoz Excellent tip!!!

                  "For example one of my vlans is 192.168.6/24 - guess what the vlan ID is ;) 6"

                  I am convinced that I will forget the VLAN IDs (even more so if it works properly) but I will likely have IP subnets etched in my brain so using subnet seems like a practical way to remember VLAN ID.

                  Thanks!

                  1 Reply Last reply Reply Quote 0
                  • B
                    bingo600 @johnpoz
                    last edited by Jan 2, 2021, 9:34 AM

                    @johnpoz said in VLAN - basics for a newbie [Solved]:

                    If you really want to get fancy, you might want to look at something like https://github.com/netbox-community/netbox

                    And its FREE ;)

                    Nice one ...

                    If you find my answer useful - Please give the post a 👍 - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    1 Reply Last reply Reply Quote 0
                    • P
                      PM_13
                      last edited by Jan 2, 2021, 9:47 AM

                      Since starting this thread, I have become little mature 😊

                      The challenge with handwritten topology is that anytime you change details it might mean starting from scratch. The links are useful and I am amazed that there are services making money offering IP management, well make sense when you are running a large network.

                      I found that writing things in a spreadsheet (not Word) is good enough for small networks like a home lan. It is easy to use a cell as a port (for diagram) with option to color code and use the zoom or resize feature to type in notes or tables!!!

                      B J C 3 Replies Last reply Jan 2, 2021, 10:18 AM Reply Quote 0
                      • B
                        bingo600 @PM_13
                        last edited by bingo600 Jan 2, 2021, 10:28 AM Jan 2, 2021, 10:18 AM

                        @pm_13

                        I'we been glaring at Dia , for a non Visio package
                        https://wiki.gnome.org/Apps/Dia

                        Seems to be usable , but nothing beats Visio.

                        Untested by me :
                        Shapes for libreoffice
                        https://www.vrt.com.au/downloads/vrt-network-equipment

                        Prob ends up costing a few $
                        https://www.lucidchart.com/pages/visio-linux-alternative

                        Another
                        https://opensource.com/life/14/6/tools-diagramming-fedora

                        If you find my answer useful - Please give the post a 👍 - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • B
                          bingo600
                          last edited by Jan 2, 2021, 11:12 AM

                          5 minutes in dia
                          It does have some usefull shapes that we all know.

                          89c36dc8-51d3-4dbf-9d49-baaa690162f1-image.png

                          If you find my answer useful - Please give the post a 👍 - "thumbs up"

                          pfSense+ 23.05.1 (ZFS)

                          QOTOM-Q355G4 Quad Lan.
                          CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                          LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                          P 1 Reply Last reply Jan 2, 2021, 11:20 AM Reply Quote 1
                          • P
                            PM_13 @bingo600
                            last edited by Jan 2, 2021, 11:20 AM

                            @bingo600 Is this GNS UI?

                            If so then I overlooked it as an option and might be worth reviewing again.
                            Thanks 😊 👍

                            B 1 Reply Last reply Jan 2, 2021, 11:39 AM Reply Quote 0
                            • B
                              bingo600 @PM_13
                              last edited by Jan 2, 2021, 11:39 AM

                              @pm_13

                              Nope

                              It's dia (diagram writer) - on a linux Mint
                              https://wiki.gnome.org/Apps/Dia

                              apt install dia

                              If you find my answer useful - Please give the post a 👍 - "thumbs up"

                              pfSense+ 23.05.1 (ZFS)

                              QOTOM-Q355G4 Quad Lan.
                              CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                              LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                              1 Reply Last reply Reply Quote 1
                              • J
                                johnpoz LAYER 8 Global Moderator @PM_13
                                last edited by Jan 2, 2021, 12:57 PM

                                @pm_13 said in VLAN - basics for a newbie [Solved]:

                                I am amazed that there are services making money offering IP management

                                When you have 1000's of networks to manage, yeah you really need something other than a spreadsheet ;).

                                There are many an options for sure - many are pretty freaking pricey if you ask me ;)

                                If you have a windows 2016 server in your network - MS added IPAM..

                                If just wanting ipam - another pretty well rounded tool for free is https://www.gestioip.net/

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                1 Reply Last reply Reply Quote 0
                                • C
                                  cburbs @PM_13
                                  last edited by Jan 6, 2021, 2:48 PM

                                  @pm_13 For drawings you could also try the following.
                                  https://online.visual-paradigm.com
                                  https://app.diagrams.net/

                                  P 1 Reply Last reply Feb 17, 2021, 2:12 AM Reply Quote 0
                                  • P
                                    PM_13 @cburbs
                                    last edited by Feb 17, 2021, 2:12 AM

                                    @cburbs , @johnpoz & @bingo600 for all the suggestions!

                                    I ended up using LibreOffice Draw, the start was clunky but once I got the hang of its drawing toolbar it became a breeze. Also realized that by documenting details, it took that extra level of time and scrutiny made me think through the topology functionally and not use my standard "do first then think later" approach 😁

                                    It is also easy to edit and make changes so for a free solution and a simple network like mine it worked out great, here is a blurred screenshot for your delight!!!

                                    screen.png

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      This community forum collects and processes your personal information.
                                      consent.not_received