Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense HA LAN Interfaces Only

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    91 Posts 2 Posters 21.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @CloudNode
      last edited by

      @iptvcld
      Out of curiosity, which devices are belonging to your NOT subnet?

      C 1 Reply Last reply Reply Quote 0
      • C
        CloudNode @viragomann
        last edited by

        @viragomann
        That is my Network of Things VLAN which I have Smart switch devices such as Tasmota bulbs/switches that i dont want them to reach out to the internet or other devices on my lan. They are all internal controlled/accessed devices.

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @CloudNode
          last edited by

          @iptvcld said in pfSense HA LAN Interfaces Only:

          That is my Network of Things VLAN which I have Smart switch devices such as Tasmota bulbs/switches that i dont want them to reach out to the internet or other devices on my lan.

          Ahh. I don't have such devices in my network. All I have want to access at least internet.

          C 1 Reply Last reply Reply Quote 0
          • C
            CloudNode @viragomann
            last edited by

            @viragomann
            For that i have the Internet of Things VLAN which those devices have internet access but cannot talk to other vlans/networks on my LAN (inter-chatter)

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @CloudNode
              last edited by

              @iptvcld
              Yes, I have an IOT subnet as well. On this only access to none-RFC1918 is allowed.

              C 1 Reply Last reply Reply Quote 0
              • C
                CloudNode @viragomann
                last edited by

                @viragomann said in pfSense HA LAN Interfaces Only:

                none-RFC1918

                I have this - i guess pretty much the same; IOT can talk to each other on the same vlan but cannot chat to others outside of IOT including the firewall it self

                9b9c3513-ee03-4e2f-b86f-521cd34dad85-image.png

                19b9c008-0ad3-4393-9710-8b72afd5e845-image.png

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @CloudNode
                  last edited by

                  @iptvcld
                  I use an RFC1918 alias on pfSense which simply includes all private networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
                  So I'm still save, when I add or change a subnet without the need of modifying the alias.

                  C 1 Reply Last reply Reply Quote 1
                  • C
                    CloudNode @viragomann
                    last edited by

                    @viragomann
                    This makes sense!

                    1 Reply Last reply Reply Quote 0
                    • C
                      CloudNode @viragomann
                      last edited by

                      @viragomann
                      I was able to locate a video as per below that advises that both Master and backup nodes will share the DHCP lease information and also both hand out IP's

                      YouTube link at the section he talks about that..
                      https://youtu.be/Ac6U4xMFaxY?t=2423

                      V 1 Reply Last reply Reply Quote 1
                      • V
                        viragomann @CloudNode
                        last edited by

                        @iptvcld
                        Interestingly. Didn't know that. Was assuming only the master is handing out DHCP leases and only the lease state is synced to the other node.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.