Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    what's the difference "VLAN1 subnet" to "192.168.1.0/24"

    Scheduled Pinned Locked Moved Firewalling
    11 Posts 4 Posters 636 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Gummi
      last edited by

      Hi there
      I'm a newby to pfsense and have problems to understand the difference:

      I have a VLAN1 with all IP's [192.168.1.x].

      What's the difference when I put the source to:

      1. "VLAN1 subnet"
      2. network "192.168.1.0/24"

      It seems to me as I had to add both rules...

      Thanks!

      Mutzli

      Bob.DigB NogBadTheBadN 2 Replies Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @Gummi
        last edited by

        @Gummi said in what's the difference "VLAN1 subnet" to "192.168.1.0/24":

        It seems to me as I had to add both rules...

        No, you don't, unless you did something wrong.

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @Gummi
          last edited by NogBadTheBad

          @Gummi If you decide to change the IP address of VLAN 1 to 192.168.2.0/24 from 192.168.1.0/24 you wouldn't need to change any firewall rules that listed VLAN1 subnet.

          IMO use XXXXX subnet in your firewall rules whenever you can.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • G
            Gummi
            last edited by

            I would go with you ...

            But I after I added a rule with "VLAN1 subnet", in the logs I found a "failed" entry which I had to copy to the rules; then it passed.

            Comparing the two rules (including "Display Advanced") the only difference I could find was the source...

            Where could the problem be?

            Mutzli

            NogBadTheBadN johnpozJ 2 Replies Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @Gummi
              last edited by

              @Gummi paste in a screenshot of your rule.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @Gummi
                last edited by

                @Gummi as mentioned its best to to use the alias for your networks - because if at some point they change your rules would still be valid.

                You should be able to view what those networks are in the table section.

                networks.jpg

                Only wan and lan will have names on them - the others will just list the actual OPTX network, not what name you put on them.

                But its quite possible depending on the rule you were actually trying to create something was not right, also keep in mind if you put in a block rule, if there was existing state the state would allow the traffic until the state has gone away either due to timeout or you removed it.

                What exactly failed when you tried to add the rule?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • G
                  Gummi
                  last edited by

                  d96ba6b4-c50a-4b30-98c6-cf7ff7f87dfd-image.png

                  The only difference is the source. Now I try to figure out if there is a difference between VLAN1 and the subnet 192.168.1.0/24...

                  Gummi

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gummi
                    last edited by

                    Just realised that the subnet 192.168.1.0 and 192.168.10.0 don't match.
                    But KAILON is VLAN10 and the subnet is 192.168.10.0, which is correct.
                    I wanted to hide the real numbers. ;)

                    Gummi

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @Gummi
                      last edited by

                      @Gummi what is in broadcast_kailon? Broadcasts would not be passed by pfsense anyway.. So not sure what your wanting to allow there? Regardless of the source..

                      What are you wanting to allow.. 137 netbios-ns is a broadcast protocol.. Your not going to get any sort of name resolution across subnets with that..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      G 1 Reply Last reply Reply Quote 0
                      • G
                        Gummi @johnpoz
                        last edited by

                        @johnpoz
                        Since I'm new to firewalls, I wanted in the first run enable all traffic.
                        Afterwards disable one by one to see what is really needed.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @Gummi
                          last edited by

                          @Gummi again broadcast traffic isn't going to pass your router.. Your not going to get name resolution via that across subnets.

                          What rules you put on pfsense isn't going to matter.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.