Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN Help Please

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    5 Posts 2 Posters 661 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      CheezyAdmin
      last edited by

      Hello everyone!

      I am trying to convert a Fortinet/Fortigate network into a PFsense network.
      I am having difficulty getting things to work.
      If I can make this setup work without VLAN's that would be a bonus.
      Here is the network scheme I plan to use:

      • Main - 10.1.0.1 to 10.1.15.254 - 255.255.240.0
      • Phones - 10.1.16.1 to 10.1.31.254 - 255.255.240.0
      • Public - 10.1.48.1 to 10.1.63.254 - 255.255.240.0
      • Security - 10.1.96.1 to 10.1.111.254 - 255.255.240.0
      • IoT - 10.1.240.1 to 10.1.255.254 - 255.255.240.0

      I plan to use PFsense (Currently an SG-3100, but could do a virtual machine) as the main router and HP smart switches (L2/L3 capable)

      I have managed to:

      • Setup the VLANs
      • Setup DHCP servers in each VLAN
      • Setup firewall rules to allow VLAN to VLAN cummunication (I think)

      I have not figured out:

      • Why devices cannot talk outside of thier VLAN
      • How to get devices to get DHCP from the correct VLAN

      Thanks for any and all help provided.

      Shawn

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @CheezyAdmin
        last edited by

        @cheezyadmin said in VLAN Help Please:

        Why devices cannot talk outside of thier VLAN

        You need a filter to allow that. By default different subnets cannot talk to each other.

        How to get devices to get DHCP from the correct VLAN

        You should be setting up a DHCP server for each subnet. You should see the different networks listed along the top of the DHCP server config page.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        C 1 Reply Last reply Reply Quote 0
        • C
          CheezyAdmin @JKnott
          last edited by

          @jknott said in VLAN Help Please:

          @cheezyadmin said in VLAN Help Please:

          Why devices cannot talk outside of thier VLAN

          You need a filter to allow that. By default different subnets cannot talk to each other.

          That is what the firewall rules are for, correct?
          Anything in the main subnet trying to contact an address in IoT subnet gets forwarded to the IoT subnet and vice versa.

          How to get devices to get DHCP from the correct VLAN

          You should be setting up a DHCP server for each subnet. You should see the different networks listed along the top of the DHCP server config page.

          If you read the section "I have managed to:", I noted that each VLAN has a DHCP server setup.
          Problem is, everything gets a DHCP address from the main network instead of the VLAN it belongs in.

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @CheezyAdmin
            last edited by

            @cheezyadmin said in VLAN Help Please:

            Problem is, everything gets a DHCP address from the main network instead of the VLAN it belongs in

            Then maybe you have the VLANs misconfigured somewhere.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • C
              CheezyAdmin
              last edited by

              @JKnott Looks like you are mostly correct.
              I factory defaulted all of my equipment and setup everything from scratch again.
              Looks like I am able to issue DHCP to each VLAN correctly.

              Thank you!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.