Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN can not ping gateway

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    8 Posts 5 Posters 939 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jebzit
      last edited by

      running pfsense 2.7.0 and have it setup with LAN 172.16.5.0/24, VLAN10 172.16.10.0/24 and VLAN100 172.16.0.0/24 and it is connected to a an L2 switch, which is setup on LAN 172.16.5.10. Switch has GW of 172.16.5.1. On the pfsense the VLANs hang off of the LAN interface, and shows that way in routing. the LAN, VLAN10 and VLAN100 all have allow all in FW rules and all 3 have DHCP setup. Odd part is that none of the vlan devices can ping their gateways. Everything in LAN (172.16.5.0/24) works fine, but the VLANs can not ping their own GWs (172.16.10.1, 172.16.0.1). From the switch I can ping everything, but why can't devices in VLANs, which get the correct DHCP address, can not ping their own GW ?

      johnpozJ V 2 Replies Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @jebzit
        last edited by

        @jebzit so you want to route these vlans on your switch? Why would you create them in pfsense then? You would only create vlans in pfsense when they are directly attached.

        if its a L2 switch, its not going to do any routing.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        J 1 Reply Last reply Reply Quote 0
        • J Offline
          jebzit @johnpoz
          last edited by

          @johnpoz the vlans were setup on the pfsense in a router on a stick fashion, the L2 switch had the trunk interface to pfsense, and the interfaces for the devices were placed in their corresponding vlan. For device in vlan 1, everything worked, vlan 10 the device got dhcp address from pfsense as configured, but could not ping its own gw, same with device plugged into interface set as vlan 100. The switch had a mgmt address in vlan 1 so I can sign on to it. From this cli, I could ping all the gw - vlan 1, 10 and 100

          DerelictD 1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate @jebzit
            last edited by

            @jebzit Check the rules. Be sure they are not protocol TCP only or some other common mistake. You might want to post a screen shot here.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • J Offline
              jebzit
              last edited by

              cbe47181-b10e-4aeb-a49a-b9d25b0e5a0b-image.png

              johnpozJ 1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann @jebzit
                last edited by

                @jebzit said in VLAN can not ping gateway:

                From the switch I can ping everything
                the L2 switch had the trunk interface to pfsense

                If the switch really was configured only for L2 the ping to the devices would have to pass pfSense in both directions. Means, the devices has to route the responds to their gateways.
                But I suspect, this is not the case and the switch is not configured properly.
                Maybe it's just leaking L2 traffic.

                You can sniff the traffic on pfSense to investigate this. If there is nothing, what I assume, the switch doesn't work properly.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator @jebzit
                  last edited by johnpoz

                  @jebzit well you have hidden the source on your rules - so can not tell if that is "net" or "address"

                  I don't see any evaluations on the rules - so maybe you have it set to address vs net, which would never trigger.

                  On any interface, the source of the traffic would be net of whatever that network is.

                  A simple way to validate if a rules thing or downstream thing - would be to sniff (packet capture via pfsense diag menu) on that interface for icmp and then ping pfsense IP address on that interface from a client in that network.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    jbsmith1984
                    last edited by

                    @jebzit Did you find a solution to this issue? I'm having the exact same issue with my pfSense box and Cisco 2960x Switch.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.