<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN to WAN]]></title><description><![CDATA[<p dir="auto">I have set up five VLANS and get correct IP from each VLAN, but iam not able to ping or use internet when im in any of VLAN, only LAN work.</p>
<p dir="auto">I cant ping from pfsense or the pc in VLAN.</p>
]]></description><link>https://forum.netgate.com/topic/16232/vlan-to-wan</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 16:47:30 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/16232.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 24 Jun 2009 11:48:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN to WAN on Thu, 30 Jul 2009 15:27:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<blockquote>
<p dir="auto">Did you enable advanced outbound NAT?</p>
<p dir="auto">(Firewall –&gt; NAT --&gt; outbound --&gt; "Manual Outbound NAT rule generation (Advanced Outbound NAT (AON))"</p>
</blockquote>
<p dir="auto">Automatic outbound NAT rule generetion (IPsec passthrough)</p>
]]></description><link>https://forum.netgate.com/post/204133</link><guid isPermaLink="true">https://forum.netgate.com/post/204133</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Thu, 30 Jul 2009 15:27:45 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Thu, 30 Jul 2009 15:11:38 GMT]]></title><description><![CDATA[<p dir="auto">Did you enable advanced outbound NAT?</p>
<p dir="auto">(Firewall –&gt; NAT --&gt; outbound --&gt; "Manual Outbound NAT rule generation (Advanced Outbound NAT (AON))"</p>
]]></description><link>https://forum.netgate.com/post/204132</link><guid isPermaLink="true">https://forum.netgate.com/post/204132</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Thu, 30 Jul 2009 15:11:38 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Thu, 30 Jul 2009 15:07:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ktims">@<bdi>ktims</bdi></a>:</p>
<blockquote>
<p dir="auto">I think you need to stop using id 1, switch that to another id like 10. ID 1 is special and some equipment treats it differently, it's not a good idea to use it for anything.</p>
<p dir="auto">Your configuration is okay I think. Can your VLAN clients ping their gateway (pfSense VLAN ip)?</p>
</blockquote>
<p dir="auto">Yes, all VLANs are ping their gateways. Ping ip's not for the Internet.</p>
]]></description><link>https://forum.netgate.com/post/204130</link><guid isPermaLink="true">https://forum.netgate.com/post/204130</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Thu, 30 Jul 2009 15:07:22 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Thu, 30 Jul 2009 10:22:43 GMT]]></title><description><![CDATA[<p dir="auto">I think you need to stop using id 1, switch that to another id like 10. ID 1 is special and some equipment treats it differently, it's not a good idea to use it for anything.</p>
<p dir="auto">Your configuration is okay I think. Can your VLAN clients ping their gateway (pfSense VLAN ip)?</p>
]]></description><link>https://forum.netgate.com/post/204097</link><guid isPermaLink="true">https://forum.netgate.com/post/204097</guid><dc:creator><![CDATA[ktims]]></dc:creator><pubDate>Thu, 30 Jul 2009 10:22:43 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Thu, 30 Jul 2009 04:48:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ktims">@<bdi>ktims</bdi></a>:</p>
<blockquote>
<p dir="auto">172.168.0.0/10 is AOL address space. You shouldn't use this on your LAN interface. You're probably looking for something inside 172.16.0.0/12 (or just mistyped the post).</p>
<p dir="auto">Don't use VLAN 1 for any tagged traffic. I seem to recall that these 3com switches don't behave nicely when you do that, and it's generally a bad idea anyway. Don't mix tagged and untagged traffic on xl0; you said you wanted rl0 for LAN, so set that in the Interface assignment.</p>
<p dir="auto">Do you have automatic NAT rule generation enabled?</p>
</blockquote>
<p dir="auto">Thanks.</p>
<p dir="auto">The ip of my LAN is 172.16.2.1. My NAT is enabled automatically.</p>
<p dir="auto">In that I am missing to make the internet for VLANs?</p>
<p dir="auto">I have 3 interfaces as described.</p>
<p dir="auto">You think I have only one interface to the port of Tagged and another switch for VLANs (untagged)? This will solve my problem of internet in VLANs?</p>
<p dir="auto">Remembering that I do not speak English. I'm using google translator.</p>
]]></description><link>https://forum.netgate.com/post/204072</link><guid isPermaLink="true">https://forum.netgate.com/post/204072</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Thu, 30 Jul 2009 04:48:24 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 21:17:30 GMT]]></title><description><![CDATA[<p dir="auto">172.168.0.0/10 is AOL address space. You shouldn't use this on your LAN interface. You're probably looking for something inside 172.16.0.0/12 (or just mistyped the post).</p>
<p dir="auto">Don't use VLAN 1 for any tagged traffic. I seem to recall that these 3com switches don't behave nicely when you do that, and it's generally a bad idea anyway. Don't mix tagged and untagged traffic on xl0; you said you wanted rl0 for LAN, so set that in the Interface assignment.</p>
<p dir="auto">Do you have automatic NAT rule generation enabled?</p>
]]></description><link>https://forum.netgate.com/post/204057</link><guid isPermaLink="true">https://forum.netgate.com/post/204057</guid><dc:creator><![CDATA[ktims]]></dc:creator><pubDate>Wed, 29 Jul 2009 21:17:30 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 20:14:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<blockquote>
<p dir="auto">Do you both actually have a VLAn capable switch and the port going to the pfSense configured as trunk for the VLANs in question?</p>
</blockquote>
<p dir="auto">Pfsense =</p>
<p dir="auto">fxp0 = wan &gt; 192.168.1.254    gw: 192.168.1.1<br />
rl0= Lan &gt; 172.168.2.1<br />
xl0= Vlans</p>
<p dir="auto">My switch is a 3Com 4226T.</p>
<p dir="auto">Is configured as:</p>
<p dir="auto">Vlan Default = 1,4-23,25-26 Untagget    24 Tagget</p>
<p dir="auto">Vlan 2 (A22) = 2 U      24 T<br />
Vlan 3 (A28) = 3 U      24 T</p>
<p dir="auto">network cable connected between pfsense (xl0 - vlans) and port 24 (switch)<br />
network cable connected between host-vlan2 and port 2 (switch)<br />
network cable connected between pfsense (fxp0 - Wan) and Cable Modem.</p>
<p dir="auto">Get successfully ping the VLAN for ip´s Wan + gw e Lan</p>
<p dir="auto">I can not ping addresses for public (internet)</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/post/204052</link><guid isPermaLink="true">https://forum.netgate.com/post/204052</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Wed, 29 Jul 2009 20:14:34 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 19:29:38 GMT]]></title><description><![CDATA[<p dir="auto">To facilitate the search for help</p>
<p dir="auto">Screenshots</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/Interfaces.JPG" alt="Interfaces.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Interfaces.JPG_thumb" alt="Interfaces.JPG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/WAN.JPG" alt="WAN.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/WAN.JPG_thumb" alt="WAN.JPG_thumb" class=" img-fluid img-markdown" /><br />
![Regra WAN.JPG](/public/<em>imported_attachments</em>/1/Regra WAN.JPG)<br />
![Regra WAN.JPG_thumb](/public/<em>imported_attachments</em>/1/Regra WAN.JPG_thumb)<br />
![Regra LAN.JPG](/public/<em>imported_attachments</em>/1/Regra LAN.JPG)<br />
![Regra LAN.JPG_thumb](/public/<em>imported_attachments</em>/1/Regra LAN.JPG_thumb)<br />
![Regra Vlan - A22.JPG](/public/<em>imported_attachments</em>/1/Regra Vlan - A22.JPG)<br />
![Regra Vlan - A22.JPG_thumb](/public/<em>imported_attachments</em>/1/Regra Vlan - A22.JPG_thumb)</p>
]]></description><link>https://forum.netgate.com/post/204043</link><guid isPermaLink="true">https://forum.netgate.com/post/204043</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Wed, 29 Jul 2009 19:29:38 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 19:18:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<blockquote>
<p dir="auto">Do you both actually have a VLAn capable switch and the port going to the pfSense configured as trunk for the VLANs in question?</p>
</blockquote>
<p dir="auto">Thanks.</p>
<p dir="auto">yes.</p>
<p dir="auto">I want to:</p>
<p dir="auto">1 - All access to VLANs interntet</p>
<p dir="auto">2 - All VLANs isolated. A VLAN can not access the other. This step you have helped me a few days ago.</p>
]]></description><link>https://forum.netgate.com/post/204041</link><guid isPermaLink="true">https://forum.netgate.com/post/204041</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Wed, 29 Jul 2009 19:18:23 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 18:58:20 GMT]]></title><description><![CDATA[<p dir="auto">Do you both actually have a VLAn capable switch and the port going to the pfSense configured as trunk for the VLANs in question?</p>
]]></description><link>https://forum.netgate.com/post/204038</link><guid isPermaLink="true">https://forum.netgate.com/post/204038</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 29 Jul 2009 18:58:20 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 29 Jul 2009 15:17:27 GMT]]></title><description><![CDATA[<p dir="auto">Hello, I'm sorry but I do not speak English. I'm using google translator.</p>
<p dir="auto">I'm not getting. VLANs are not my internet.</p>
<p dir="auto">I created a rule equal to the Dragon II but did not work.</p>
<p dir="auto">I think it has something to be done before this, there in NAT. What do you think?</p>
]]></description><link>https://forum.netgate.com/post/204009</link><guid isPermaLink="true">https://forum.netgate.com/post/204009</guid><dc:creator><![CDATA[flanandorj]]></dc:creator><pubDate>Wed, 29 Jul 2009 15:17:27 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 24 Jun 2009 13:58:57 GMT]]></title><description><![CDATA[<p dir="auto">Yes. There is a screenshot on VLAN 3.<br />
<img src="http://i39.tinypic.com/2rqn6gm.jpg" alt="" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/201131</link><guid isPermaLink="true">https://forum.netgate.com/post/201131</guid><dc:creator><![CDATA[DragonII]]></dc:creator><pubDate>Wed, 24 Jun 2009 13:58:57 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN to WAN on Wed, 24 Jun 2009 12:35:49 GMT]]></title><description><![CDATA[<p dir="auto">Did you create appropriate firewall rules to allow users on the VLANs out?</p>
]]></description><link>https://forum.netgate.com/post/201114</link><guid isPermaLink="true">https://forum.netgate.com/post/201114</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 24 Jun 2009 12:35:49 GMT</pubDate></item></channel></rss>