Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Interface Assignment with VLAN

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    3 Posts 3 Posters 726 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      eeebbune
      last edited by eeebbune

      Dear Professionals,

      When I assign interface port on Firewall, there are some options that I can choose like this :

      • VLAN 50 on ix0
      • VLAN 100 on ix0

      What is this for? Is this kind of 'access port' conceptually?
      If I create ix0 interface port with VLAN50 on ix0, that means packets only tagged 50 are able to passing this port?
      What happened to other tagged packets? Those are discarded even if ix0 has allow any to any rule?

      Thank you for your response.

      keyserK bingo600B 2 Replies Last reply Reply Quote 0
      • keyserK
        keyser Rebel Alliance @eeebbune
        last edited by

        @eeebbune said in Interface Assignment with VLAN:

        Dear Professionals,

        When I assign interface port on Firewall, there are some options that I can choose like this :

        • VLAN 50 on ix0
        • VLAN 100 on ix0

        What is this for? Is this kind of 'access port' conceptually?
        If I create ix0 interface port with VLAN50 on ix0, that means packets only tagged 50 are able to passing this port?
        What happened to other tagged packets? Those are discarded even if ix0 has allow any to any rule?

        Thank you for your response.

        VLAN 50 on ix0 creates a logical pfSense firewall Interface for frames tagged with VLAN50 on ix0.

        By default pfSense will block/drop all frames on a physical interface - tagged or not - unless you have created an identifying logical pfSense Interface to accept it.

        So a “pure” ix0 pfSense interface is for untagged frames on the physical interface. VLAN X on ix0 is for frames tagged with VLAN x on ix0. All other tagged frames are dropped unless you create a interface for them.

        Love the no fuss of using the official appliances :-)

        1 Reply Last reply Reply Quote 1
        • bingo600B
          bingo600 @eeebbune
          last edited by

          @eeebbune
          The vlan asignment (L2) on a pfSense (router/firewall) , is usually followed up by an IP interface assignment, to the vlan created.
          And now you have a working L3 interface, with Vlanxx tagging activated.
          Note: The pfSense physical interface require a vlan enabled device (switch etc.) in the other end (of the cable) , in order to "encode/decode" the tagged frames.

          See short example here
          https://forum.netgate.com/post/944383

          /Bingo

          If you find my answer useful - Please give the post a 👍 - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.