• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Cannot ping new vlan interface

Scheduled Pinned Locked Moved L2/Switching/VLANs
21 Posts 5 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    feisal
    last edited by Jun 13, 2023, 2:51 PM

    I have a D-Link DGS-1210 connected to a Ubiquiti Edgerouter-X with a VLAN 10 in the Edgerouter. I can ping from the 192.168.10(main network), the VLAN interface 192.168.4.1 and the rest of the 192.168.4.0 network.

    Replaced the EdgeRouter with a Netgate 4100, the LAN interface is assigned 192.168.1.1 and the child of the LAN is VLAN10 with IP 192.168.4.1.
    I can ping the VLAN10 interface from the main network but nothing else in the 192.168.4.0 network.
    And machines in the 192.168.4.0 network cannot access the VLAN10 interface.
    I am assuming that the rules must be correct since the pings to the interface work but not sure why I cannot get to the 192.168.4.0 network.

    The rules are any to any for now.

    It been bugging me for several days now. Anyone have any ideas?

    M V 2 Replies Last reply Jun 13, 2023, 3:29 PM Reply Quote 0
    • M
      michmoor LAYER 8 Rebel Alliance @feisal
      last edited by Jun 13, 2023, 3:29 PM

      @feisal Anything in the firewall logs?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      1 Reply Last reply Reply Quote 0
      • F
        feisal
        last edited by Jun 13, 2023, 3:58 PM

        That's the weird thing, nothing in the logs, I see no access.

        M 1 Reply Last reply Jun 13, 2023, 4:02 PM Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @feisal
          last edited by Jun 13, 2023, 4:02 PM

          @feisal Hmm that would usually mean that flows are not making it to the firewall in that case.
          Can you post your firewall rules?

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          1 Reply Last reply Reply Quote 0
          • V
            viragomann @feisal
            last edited by Jun 13, 2023, 5:26 PM

            @feisal said in Cannot ping new vlan interface:

            And machines in the 192.168.4.0 network cannot access the VLAN10 interface.

            So there is probably an L2 issue.

            What do you get exactly, when you try?

            F 1 Reply Last reply Jun 13, 2023, 5:40 PM Reply Quote 0
            • F
              feisal @viragomann
              last edited by Jun 13, 2023, 5:40 PM

              @viragomann![ ]Screenshot 2023-06-13 at 13.35.45.png Screenshot 2023-06-13 at 13.36.42.png

              Here are the rules.
              I get host unreachable when I try

              V F 2 Replies Last reply Jun 13, 2023, 5:57 PM Reply Quote 0
              • V
                viragomann @feisal
                last edited by Jun 13, 2023, 5:57 PM

                @feisal
                So I suspect that the layer 2 isn't working properly on that VLAN.

                If you have it set up correctly on pfSense the failure is probably outside of it.

                You can sniff the ARP traffic on the VLAN interface, while you try to ping a device in that VLAN, for further investigation.
                You should see ARP requests from pfSense, unless the entry is already in its ARP table. And if there are request you should also see responses if the L2 is working.

                F 1 Reply Last reply Jun 13, 2023, 11:09 PM Reply Quote 0
                • F
                  feisal @feisal
                  last edited by Jun 13, 2023, 6:27 PM

                  @feisal can it be that the parent of the VLAN interface is in use? I am going to try a different (unused parent) later and report back.

                  1 Reply Last reply Reply Quote 0
                  • K
                    kiokoman LAYER 8
                    last edited by Jun 13, 2023, 7:15 PM

                    my 2 cent,
                    the cable from pfsense to the switch is not on the right port ? like tagget / untagged / not member ?
                    the port on the switch should be vid 1 untagged / vid 10 tagged

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    1 Reply Last reply Reply Quote 0
                    • F
                      feisal @viragomann
                      last edited by Jun 13, 2023, 11:09 PM

                      @viragomann
                      I get these
                      19:07:23.685373 ARP, Request who-has 192.168.4.3 tell 192.168.4.1, length 28
                      19:07:27.685263 ARP, Request who-has 192.168.4.3 tell 192.168.4.1, length 28

                      So it looks like a L2 problem, but I am not sure how to solve that.

                      J 1 Reply Last reply Jun 14, 2023, 1:43 AM Reply Quote 0
                      • J
                        Jarhead @feisal
                        last edited by Jun 14, 2023, 1:43 AM

                        @feisal Show your switch config.
                        As said above, you probably are tagging/untagging ports correctly.

                        F 1 Reply Last reply Jun 14, 2023, 11:46 AM Reply Quote 0
                        • F
                          feisal @Jarhead
                          last edited by Jun 14, 2023, 11:46 AM

                          @Jarhead I am quite sure of that now, I have screwed around with the config so much now that posting it would not be helpful. I will explain what I want to accomplish and maybe someone with more knowledge will have an insight.

                          I am connecting to a DGS-1210 web managed switch.

                          Port 24 - traffic from 192.168.1.x (untagged) and VLAN tagged 10 traffic from 192.168.4.x (PBX and its gateway)
                          Port 6 - untagged phone traffic from 192.168.4.x which I want to tag using a PVID 10
                          Port 1 - connection to Netgate 4100
                          other ports - untagged traffic from 192.168.1.x

                          I want the VLAN10 tags preserved along with the untagged traffic sent via port 1 to the Netgate 4100 which has the 192.168.1.1 interface and VLAN10 192.168.4.1 along with their respective DHCP servers.
                          The phones don't need to get to the Internet just to the PBX which does need to get to the Internet for updates etc. This I can control using firewall rules.

                          V 1 Reply Last reply Jun 14, 2023, 12:28 PM Reply Quote 0
                          • V
                            viragomann @feisal
                            last edited by Jun 14, 2023, 12:28 PM

                            @feisal said in Cannot ping new vlan interface:

                            I want the VLAN10 tags preserved along with the untagged traffic sent via port 1 to the Netgate 4100 which has the 192.168.1.1 interface and VLAN10 192.168.4.1 along with their respective DHCP servers.

                            So configure the port equal to port 24.

                            However, I'm wondering, why you have VLAN 10 tagged on 24. Is the PBX also configured for tagged VLAN?

                            F 1 Reply Last reply Jun 14, 2023, 12:43 PM Reply Quote 0
                            • F
                              feisal @viragomann
                              last edited by Jun 14, 2023, 12:43 PM

                              @viragomann
                              PBX along with other servers are VMs under Proxmox. So the PBX traffic is tagged with VLAN10 to separate it from the other servers.
                              The phones and the SIP box from the phone company are on the 192.168.4.x network

                              what do you mean by "So configure the port equal to port 24."?

                              V 1 Reply Last reply Jun 14, 2023, 12:50 PM Reply Quote 0
                              • V
                                viragomann @feisal
                                last edited by Jun 14, 2023, 12:50 PM

                                @feisal said in Cannot ping new vlan interface:

                                what do you mean by "So configure the port equal to port 24."?

                                Port 1, which you've connected to pfSense. It needs the settings equal to port 24.
                                LAN 192.168.1.x untagged, VLAN 10 tagged.

                                F 1 Reply Last reply Jun 14, 2023, 12:56 PM Reply Quote 0
                                • F
                                  feisal @viragomann
                                  last edited by Jun 14, 2023, 12:56 PM

                                  @viragomann
                                  Thank you, will try it after when everyone has stopped work this evening and let you know.

                                  K 1 Reply Last reply Jun 14, 2023, 4:42 PM Reply Quote 0
                                  • K
                                    kiokoman LAYER 8 @feisal
                                    last edited by kiokoman Jun 14, 2023, 4:48 PM Jun 14, 2023, 4:42 PM

                                    @feisal
                                    Port 1 -> vid 1 untagged / vid 10 tagged
                                    Port 2-5 -> vid 1 untagged / vid 10 not member (or tagged)
                                    Port 6 -> vid 1 not member (or tagged) / vid 10 untagged
                                    port 7-23 -> vid 1 untagged / vid 10 not member (or tagged)
                                    port 24 -> vid 1 untagged / vid 10 tagged (PBX and gateway must have the network card set to vlan10)
                                    2023-06-14_18h45_49.jpg

                                    2023-06-14_18h44_55.jpg

                                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                    Please do not use chat/PM to ask for help
                                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                    F 1 Reply Last reply Jun 15, 2023, 2:38 PM Reply Quote 0
                                    • F
                                      feisal @kiokoman
                                      last edited by Jun 15, 2023, 2:38 PM

                                      @kiokoman
                                      Unfortunately, it did not work, same issue, I can ping everything on the VLAN10 from within the VLAN10 except from the PFsense 192.168.4.1 interface.
                                      ARP traffic does not want to go down two lines, I guess?

                                      I ended up taking all the 192.168.4.x phones and put them in the Mikrotik switch on VLAN10. The Mikrotik switch is connected to a Mikrotik 10G router which is connected to all the VMs.

                                      I made a diagram of what I ended up with.
                                      network.png

                                      V 1 Reply Last reply Jun 15, 2023, 4:35 PM Reply Quote 0
                                      • F
                                        feisal
                                        last edited by Jun 15, 2023, 3:41 PM

                                        Looking back at the diagram, I wonder if what I was trying to do is impossible and an L3 switch/router was the correct solution.

                                        1 Reply Last reply Reply Quote 0
                                        • V
                                          viragomann @feisal
                                          last edited by Jun 15, 2023, 4:35 PM

                                          @feisal said in Cannot ping new vlan interface:

                                          ARP traffic does not want to go down two lines, I guess?

                                          No, that's not the issue. ARP packets for the VLAN are tagged as well. So they are separated from the untagged LAN.
                                          I still think, there must be something wrong in the VLAN setup on either end.

                                          However, you can try to bring your LAN into a VLAN as well.

                                          Also since you have obviously enough NIC on pfSense, you can split your primary switch into two virtual switches and connect both to different NICs on pfSense. So you can set up all this without any need of a VLAN.

                                          F 1 Reply Last reply Jun 16, 2023, 7:32 PM Reply Quote 0
                                          20 out of 21
                                          • First post
                                            20/21
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received