Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN and bridges don't mix?

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    3 Posts 3 Posters 207 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • TitaniumCoder477T
      TitaniumCoder477
      last edited by

      I have a firewall with one WAN port and two LAN ports. The LAN ports are in a bridge to effectively connect two network branches together.

      Today I setup VLAN 4 on both LAN ports, created a bridge for them, and setup DHCP on the bridge. My goal was to simply ensure that any tagged traffic coming over either LAN port will be handled appropriately.

      Two test endpoints, coming off the same LAN port, pull the right IPs from the VLAN bridge DHCP server and communicate with each other without issue. However, they cannot ping the bridge IP (i.e. gateway/DHCP server IP), nor the LAN IP, nor 8.8.8.8, etc.

      (Yes--it makes no sense that they can communicate with the VLAN bridge gateway to pull an IP but then can't ping it.)

      For firewall rules, I have a IPv4+6 wildcard protocol/source/dest rule on the bridge. I also have the same on the VLAN interfaces.

      Any thoughts on what I'm missing? Seems like this should be a simple/standard setup.

      1 Reply Last reply Reply Quote 0
      • C
        coxhaus
        last edited by

        To me bridging is not efficient. I would rather use VLANs with local routing. I actually use a layer 3 switch but you don't have to.

        1 Reply Last reply Reply Quote 0
        • G
          GeorgePatches
          last edited by GeorgePatches

          When I was setting up VMs on my TrueNAS Core (also FreeBSD based) I discovered a limitation of bridging where an interface could bridge untagged trafffic or VLAN tagged traffic, but not both. My ongoing solution has been to move all my untagged traffic onto a tagged VLAN and just assign that VLAN to the various ports on the switch. So none of the downstream devices see the the VLAN tagging, but to the pfsense and truenas everything is tagged. Without looking through your whole setup, I'd bet that's what you're running into.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.