Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    segment wifi traffic (guest, IoT, trusted)

    Scheduled Pinned Locked Moved General pfSense Questions
    46 Posts 7 Posters 7.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bingo600B
      bingo600 @farmerjohn
      last edited by bingo600

      @farmerjohn

      On switches you typically have to define the Vlans before you can use them
      Packages/Frames to any Vlan not defined on the switch , will be dropped on entry.

      On my 1100-08 I add a vlan like this

      Click on Add (VID = Vlan ID)
      3d0055bf-b18e-48d9-a773-6d357b3a294d-image.png

      Enter Vlan Number
      Enter Vlan Name (For your own sanity, use the same Vlan name on all units)
      f860059b-d20b-48bc-8f19-ee21b2f20d84-image.png

      Here we are defining Vlan 7 , with a name of VL8-Name (i goofed)
      And in the Port selection boxes below , you see 3 port member types (per port)

      Untagged :
      If this port should behave as a Std. ethernet port (end device) in Vlan 7 , you would tick that.

      Tagged:
      If this port should transport Vlan 7 as tagged frames (typically used if connected to another vlan capable device) - Ie. a switch , you would tick that.

      Not Member:
      If this port has nothing to do with Vlan7 you would tick that.

      A switchport can ONLY transport (be member of) 1 Untagged Vlan , but can transport many tagged vlans.

      Often a switch comes from the factory with a default setting of all ports are "member of Untagged Vlan 1" , that will drive you crazy when you want ie. port 2 , to be a member of untagged Vlan 7 instead. You are NOT allowed to do that !!!!.

      Solution:
      Go to the Vlan 1 definition , and make Port 2 "Not Member" of Vlan 1.
      Now you can make it an Untagged member of Vlan 7.

      /Bingo

      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

      1 Reply Last reply Reply Quote 1
      • bingo600B
        bingo600
        last edited by bingo600

        I have made a dia drawing of what i think you want.

        62e1f967-b031-4204-8ec6-92328f42a136-image.png

        I recommend dia (when you don't have visio) , or are running linux like me.

        Get dia here
        http://dia-installer.de/

        And the shapes (symbols) here
        http://dia-installer.de/diashapes/index.html.en

        On my linux mint (ubuntu) they are in the std pkg repos.

        fjohn-dia-draw.zip

        Edit: I have no Netgears - So no idea about how2 configure that one.

        Edit2: I made a super short vlan intro here.
        https://forum.netgate.com/post/944383

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        F 1 Reply Last reply Reply Quote 1
        • F
          farmerjohn @bingo600
          last edited by

          @bingo600 said in segment wifi traffic (guest, IoT, trusted):

          Everything seems to be working - thanks to your images and explanations. I like the dlink web UI more than the netgear, but the netgear GS108Tv2 was released many years ago.

          So i just gave them a static ip.

          is working for the moment - hopefully will be persistent.

          Get dia here

          I'll will try it as soon as my head stops hurting - thanks for making everything clear.

          bingo600B 1 Reply Last reply Reply Quote 0
          • bingo600B
            bingo600 @farmerjohn
            last edited by

            @farmerjohn

            Glad you got it working ....

            Now when you get the AP AC Pro's - You might have a bit of initial trouble.

            Until recently the mgmt net of the AP AC Pro had to be "untagged" , and the Wifi-Vlans could be tagged. That's how i run mine.

            But @johnpoz mentioned that with a recent firmware it would be possible to run mgmt as a tagged vlan too.

            If/when you get them and have "challenges" give us a "ping" ....

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            JKnottJ johnpozJ 2 Replies Last reply Reply Quote 1
            • JKnottJ
              JKnott @bingo600
              last edited by

              @bingo600 said in segment wifi traffic (guest, IoT, trusted):

              mentioned that with a recent firmware it would be possible to run mgmt as a tagged vlan too.

              I have set up networks, with Adtran gear, where the management interface was on a VLAN. Not having that option is dumb for business installs.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @bingo600
                last edited by johnpoz

                @bingo600 said in segment wifi traffic (guest, IoT, trusted):

                with a recent firmware it

                Wasn't all that recent - quite some time ago that feature was added. I don't recall the min required firmware or controller software. But if your running the current version you can yes run tagged management...

                Here you go
                https://help.ui.com/hc/en-us/articles/360046773733-UniFi-Using-VLANs-with-UniFi-Wireless

                You have to adopt via untagged.. But
                "As of Controller software version 5.8, access points and switches can be set to tagged VLANs"

                While I concur it should be a requirement for equipment to support if expected to be use in a true enterprise.. Running a vlan untagged is not really an issue where unifi stuff would be most used, small business, small offices, homes, etc. It mostly would be a concern where some sort of company security policy required tags..

                I have not bothered to change my home setup. While I have multiple tagged vlans, the vlan that my APs are on for managment is untagged for the connection to the APs

                5.8.X was released stable over 3 years ago.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.