• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Virtual Interface

Scheduled Pinned Locked Moved HA/CARP/VIPs
9 Posts 2 Posters 773 Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    Simon 3
    last edited by Simon 3 May 20, 2024, 3:47 PM May 20, 2024, 3:43 PM

    Hi, i would like to know if anyone can tell me how to create a second temporary virtual interface which Zyxel defines as Virtual Interface, on the LAN which allows me to simulate a second gateway.
    Example I have the LAN on 192.168.5.0/24 with pfsense with IP 192.168.5.254/32, I would like to have a second IP to assign as Gateway on 192.168.3.1/32 but I don't understand how to do it.
    I tried to create it with the Virtual IP as Alias but I can't make it work.
    If anyone can give me a hand I thank them in advance.

    V 1 Reply Last reply May 20, 2024, 6:08 PM Reply Quote 0
    • V Offline
      viragomann @Simon 3
      last edited by May 20, 2024, 6:08 PM

      @Simon-3 said in Virtual Interface:

      Example I have the LAN on 192.168.5.0/24 with pfsense with IP 192.168.5.254/32

      The mask of the interface IP has to be /24 as well, otherwise it would not be able to communicate with any other device in this subnet.

      I would like to have a second IP to assign as Gateway on 192.168.3.1/32

      Same here

      I tried to create it with the Virtual IP as Alias but I can't make it work.

      Yes, that's the way to achieve this, however, even if such set up is not recommended.
      Don't you have another free interface on pfSense?

      S 1 Reply Last reply May 23, 2024, 8:20 AM Reply Quote 0
      • S Offline
        Simon 3 @viragomann
        last edited by May 23, 2024, 8:20 AM

        @viragomann said in Virtual Interface:

        do per raggiungere questo obiettivo, anche se tale impostazione non è consigliata.
        Non hai un'altra interfaccia gratuita su pfSense?

        I don't have a second free interface, at least it's not usable, it's just a temporary configuration; I assigned a Virtual IP /24 but I still have the problem that the virtual network does not appear on the internet.
        68194e8c-72e6-47c7-983c-75f4ad1773bb-image.png

        V 1 Reply Last reply May 23, 2024, 10:07 AM Reply Quote 0
        • V Offline
          viragomann @Simon 3
          last edited by May 23, 2024, 10:07 AM

          @Simon-3 said in Virtual Interface:

          I assigned a Virtual IP /24 but I still have the problem that the virtual network does not appear on the internet.

          What do you mean? A device in this subnet has no internet access?

          Check the firewall rules. Ensure access from the additional subnet is allowed on LAN.
          If so, I expect, that you can ping the virtual IP from a connected device.

          If it has still no internet access check if pfSense has added an outbound NAT rule if the outbound NAT is in automatic mode. Maybe you have to switch into hybrid mode and add a proper rule manually.

          S 1 Reply Last reply May 23, 2024, 10:28 AM Reply Quote 0
          • S Offline
            Simon 3 @viragomann
            last edited by May 23, 2024, 10:28 AM

            @viragomann

            23db1702-125d-4d04-9d5b-fe741fa3f9ae-image.png

            I allowed the subnet on the firewall on the LAN but unfortunately it doesn't allow me to ping, it was only allowed when the single address was set in the virtual IP configuration i.e. /32 while with the entire subnet /24 it doesn't allow me to ping.

            V 1 Reply Last reply May 23, 2024, 10:43 AM Reply Quote 0
            • V Offline
              viragomann @Simon 3
              last edited by May 23, 2024, 10:43 AM

              @Simon-3 said in Virtual Interface:

              I allowed the subnet on the firewall on the LAN but unfortunately it doesn't allow me to ping

              To ping what?

              The pass rule is showing traffic and states, so obviously some traffic matches it.
              bb8eeda6-73f6-4365-b09e-0ed58fd27a9e-grafik.png

              S 1 Reply Last reply May 23, 2024, 10:50 AM Reply Quote 0
              • S Offline
                Simon 3 @viragomann
                last edited by May 23, 2024, 10:50 AM

                @viragomann

                If from a device on the virtual subnet with manually set IP address 192.168.3.x and gateway 192.168.3.1, I try to ping 192.168.3.1, it gives me an expired request, and I don't understand why.

                V 1 Reply Last reply May 23, 2024, 11:15 AM Reply Quote 0
                • V Offline
                  viragomann @Simon 3
                  last edited by May 23, 2024, 11:15 AM

                  @Simon-3
                  Did you set the network mask correctly on the device?

                  This is straight forward. If the network is configured properly the device and you ping the interface IP, the device requests the belonging MAC address, adds it to its ARP table and then send the request packet.

                  Can you see the gateway in its ARP table? I suspect, you can't due to a layer 2 failure.

                  On pfSense you can sniff the ARP traffic. But I assume, there is nothing to see due to a misconfiguration.

                  S 1 Reply Last reply May 23, 2024, 11:42 AM Reply Quote 0
                  • S Offline
                    Simon 3 @viragomann
                    last edited by May 23, 2024, 11:42 AM

                    @viragomann
                    The network card configuration is correct, what surprised me is that only towards Virtual IP 192.168.3.1/24 I had the problem. If I create another one like 192.168.88.1/24 the problem doesn't exist, I solved it simply by running a reboot of pfsense. But I still don't understand why this happened. Thank you very much for helping

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received