Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Solved! Has anyone recently (2024) set up a VLAN using pfSense and Unifi Network application and switches? (DHCP back-end has to be ISC)

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    20 Posts 4 Posters 988 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NGUSER6947
      last edited by NGUSER6947

      I tried about a year ago to get a VLAN up and going for isolating a device. Spent quite a bit of time on it and a lot of interaction with folks here but never did get it to work (problem was the device would never get an IP, even though DHCP was enable for the VLAN).

      Anyhow, since Unifi updates their setup screens on a seemingly constant basis, I'd like to try this again using the setup that someone else did recently using the same configuration so that I'm not trying to translate between older support threads here that look nothing (on the Unifi end) that they (the screens) do now.

      I have a Netgate SG-1100 and 2 downstream Unifi 8-port smart switches.

      I set up the VLAN this morning using this guide: guide

      As far as I can see I have everything set up. Interface is enabled, DHCP is enabled, VLAN ID matches what I have on the Unifi end. However, I'm not getting an IP issued when I attempt to connect to that device (separate WiFi network defined in Unifi Network, port is tagged, etc.).

      This is exactly where I got stuck the last time I attempted this.

      G JKnottJ 2 Replies Last reply Reply Quote 0
      • G
        Gblenn @NGUSER6947
        last edited by Gblenn

        @NGUSER6947 Pretty sure there is something misconfigured in your Unifi settings.

        First of all, the port connecting to pfsense needs to be set to TAGGED. Either select Allow all or use Custom to define which ID's should be included. The same is true for the port(s) connecting your AP's (and connecting the two switches), they also need to be TAGGED.

        Under the Wifi settings you create a wifi network for each new VLAN network you want (and have created under Networks).

        Any device that you want to have on a specific VLAN that is directly connected to one of the switches need to have it's port set to Untagged.

        N 1 Reply Last reply Reply Quote 0
        • N
          NGUSER6947 @Gblenn
          last edited by

          @Gblenn Thank you for responding. I think I have things set as you specify:
          8514adeb-685c-4ed3-a0ee-5655f2a0ebd3-image.png

          73321c52-eeb9-4752-b0b3-f18794f26dfe-image.png

          fa01b68c-78fc-4b0f-9ade-fa1e5a3ac462-image.png

          fd29fddb-13c2-4a49-8cdd-175e9f2037d6-image.png

          7652f52e-8851-4caa-91fa-f06fe1575773-image.png

          Port 3 on the switch is the port with the AP.

          G 1 Reply Last reply Reply Quote 0
          • G
            Gblenn @NGUSER6947
            last edited by Gblenn

            @NGUSER6947 That looks ok, and can I assume that port 1 is pfsense and that is also set to TAGGED for VLAN 10, and the same for port 4 (TRUNK to other switch)? If you don't use VLAN 10 on that switch you can leave it but port 1 has to have VLAN 10 TAGGED for it to be able to pass along VLAN traffic to/from pfsense correctly.

            Also I'd turn off the Captive Portal during testing, just to see that things work correctly. And just to be sure, is that something you want and need?

            N 1 Reply Last reply Reply Quote 0
            • N
              NGUSER6947 @Gblenn
              last edited by NGUSER6947

              @Gblenn If I tag Port 1 on the switch for the VLAN like this:
              7fe65637-9c33-4030-bea6-040c01f7ef2f-image.png

              all communication stops. I reset the switch twice, same result. Dead, nothing gets to the pfSense router.

              Wait - this is where Ubiquiti's UI messes with my head - should I have ALL ports green (tagged with 10-Automation (bottom row) and 1=Default should be all blue (top row)?

              Fortunately I have Port 2 unused and I was able to get things back up again by plugging the cable from pfSense into switch Port 2 and restarting the switch.

              I did turn off the Captive Portal as you suggested. No I don't need that. Also the 2nd switch doesn't need to be part of the VLAN so I don't plan to tag any of those ports.

              Ok I updated this and have Port 1 set this way. Is this correct? 6aec6555-fd53-4834-b1ff-da04f41404ba-image.png

              Configured this way, with pfSense plugged back into Port 1, everything works fine... except if I try to connect a device to the Automation wifi it still doesn't get an IP.

              G 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @NGUSER6947
                last edited by

                @NGUSER6947

                I have a Unifi AC Lite AP which I have configured to use with a VLAN & 2nd SSID. I also have a Cisco switch. I enabled the VLAN on the pfSense main LAN interface and on the AP, to connect the VLAN to the 2nd SSID. I also enabled the VLAN on the 2 switch ports it passes through.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                N 1 Reply Last reply Reply Quote 0
                • N
                  NGUSER6947 @JKnott
                  last edited by

                  @JKnott said in Has anyone recently (2024) set up a VLAN using pfSense and Unifi Network application and switches?:

                  @NGUSER6947

                  I have a Unifi AC Lite AP which I have configured to use with a VLAN & 2nd SSID. I also have a Cisco switch. I enabled the VLAN on the pfSense main LAN interface and on the AP, to connect the VLAN to the 2nd SSID. I also enabled the VLAN on the 2 switch ports it passes through.

                  @JKnott I have mine set this way:
                  884af9ce-8ed3-49b7-ace0-a6aa37c8cccf-image.png

                  Are you saying yours is set like this?
                  feb2711d-fc08-4dcc-a6cd-b197f38f5fc9-image.png

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gblenn @NGUSER6947
                    last edited by

                    @NGUSER6947 said in Has anyone recently (2024) set up a VLAN using pfSense and Unifi Network application and switches?:

                    Wait - this is where Ubiquiti's UI messes with my head - should I have ALL ports green (tagged with 10-Automation (bottom row) and 1=Default should be all blue (top row)?

                    Well, since Native means Untagged, it should normally be 1=Default all across the ports. Except when you only want VLAN traffic to exit through that port. Like when you connect a Camera or some device that needs to be in a specific VLAN.

                    And Green means Tagged so it needs to be 10=Automation on port 1 (if that is where pfsense is connecting) and any ports where you have your AP's connected. So your picture is correct what you are showing.

                    If it still doesn't work, I'd suggest you set one of the free ports to 10 Native and connect your PC to that port. Does it get an IP? If not, you need to check your VLAN settings or DHCP for the VLAN in pfsense.

                    In your picture it looks correct with VLAN 10 on mvneta0, if I understand how it should be on those units. Perhaps you can show the rest of the settings for that interface and the DHCP server allocated to it?

                    N 1 Reply Last reply Reply Quote 0
                    • N
                      NGUSER6947 @Gblenn
                      last edited by NGUSER6947

                      @Gblenn So, the way I have Port 1 configured is like this:
                      9c59cd03-b804-4917-9c94-c8f005c8379d-image.png

                      and yeah just looking at this page it appears Port 1 isn't tagged. But! drilling into it shows this for Port 1 and Port 3:
                      9681e000-0ecf-486f-9361-1c8de4a8bc6c-image.png

                      Unless the Unifi UI is once again messing with my brain (quite possible), the way I understand this is that Port 1 and Port 3 are set for Default but also is tagged for the Automation VLAN.

                      If I just tag Port 1 by setting the Native VLAN/Network to Automation, this is when all network comm halts. I assume that's because nothing else on the switch can get to the router (but who knows, that's just my assumption). Nonetheless, that's what I have observed via testing.

                      I did the test you suggested. With a PC plugged into Port 2, set up like this:
                      f4abf3fe-457a-4f1f-8133-78ae947a23b3-image.png

                      it does not get an IP, just spins a bit then gives up.

                      N 1 Reply Last reply Reply Quote 0
                      • N
                        NGUSER6947 @NGUSER6947
                        last edited by

                        Here are the screenshots from pfSense.
                        d9cb79a6-f06c-49d0-9098-d9b32bec4aa1-image.png

                        077f0ac5-1ce1-4f09-a3d7-4906cedbc8ed-image.png

                        33b376f3-57f1-4c1b-ae7b-c6b0bd2a868c-image.png

                        cb033925-4660-4f2b-870e-48491fb95ac1-image.png
                        5b8e023b-8b3e-4bbe-9484-c689906b8981-image.png

                        ed2170b0-9236-4780-a3b4-6da6c0506404-image.png

                        7729ddea-b314-4675-be9b-2cca17f95475-image.png

                        G 1 Reply Last reply Reply Quote 0
                        • G
                          Gblenn @NGUSER6947
                          last edited by Gblenn

                          @NGUSER6947 Well I can't see anything out of the ordinary there. It looks like it's correctly set up in pfsense. Perhaps one more thing... there is a menu item under Interfaces called Switch / VLANs, correct? What does that look like?
                          Aaand, I assume you are connecting the switch to the port with the label LAN on the Netgate device?

                          N 1 Reply Last reply Reply Quote 0
                          • U
                            Uglybrian
                            last edited by

                            In addition to everything that has Been said here. I noticed that you are Using the KEA back end. As a last resort, you may want to try switching the back to ISC and see if that makes any difference. I know the first time you tried to do this you were probably using ISC. Even though that didn’t work out. KEA is still in the detail shop and not ready for the showroom floor.

                            N 1 Reply Last reply Reply Quote 0
                            • N
                              NGUSER6947 @Gblenn
                              last edited by NGUSER6947

                              @Gblenn This is the setup page you asked about:
                              0a59db6c-3cbb-4335-83b6-afe149afbf76-image.png

                              And yes, the switch is plugged into the LAN port on pfSense.

                              N 1 Reply Last reply Reply Quote 0
                              • N
                                NGUSER6947 @Uglybrian
                                last edited by

                                @Uglybrian To change it to ISC where is that, also do I need to restart the router or just save and apply changes?

                                1 Reply Last reply Reply Quote 0
                                • N
                                  NGUSER6947 @NGUSER6947
                                  last edited by

                                  @Gblenn I did some research and apparently with the SG-1100 you have to set up tagging inside Interfaces/Switch/VLANs.

                                  This is how I have it configured now, which exactly matches several of the tutorials I found:
                                  9e73f904-16d7-4180-9906-d20bd078f18d-image.png

                                  Still, no happiness. Neither a wifi device or the PC I have plugged into Port 2 (which is tagged) will obtain an IP.

                                  1 Reply Last reply Reply Quote 0
                                  • U
                                    Uglybrian
                                    last edited by

                                    If you want to give it a try. Go to System> Advanced> Networking. Click on ISC DHCP then save at the bottom. There is no need to restart the router.

                                    N 1 Reply Last reply Reply Quote 0
                                    • N
                                      NGUSER6947 @Uglybrian
                                      last edited by

                                      @Uglybrian Well sure enough, that did it! Man, this has been driving me nuts.

                                      Phone connected right away.

                                      Thanks to you and @Gblenn for your help and assistance.

                                      G 1 Reply Last reply Reply Quote 0
                                      • G
                                        Gblenn @NGUSER6947
                                        last edited by

                                        @NGUSER6947 Great that it works now, but really strange that KEA would be the culprit. I think you had some issues with KEA all along, which you didn't notice until you were testing with something requiring a new IP. I would try changing back to KEA to see if it still works, which I'm guessing it will...

                                        N 1 Reply Last reply Reply Quote 0
                                        • N
                                          NGUSER6947 @Gblenn
                                          last edited by

                                          @Gblenn yeah I may try that at some point. Since ISC is marked "Deprecated" I would think that KEA would be pretty well sorted out by now.

                                          G 1 Reply Last reply Reply Quote 0
                                          • G
                                            Gblenn @NGUSER6947
                                            last edited by

                                            @NGUSER6947 Yes but things seem to pop up, at least in discussions. I had it crash a few months back and it didn't want to restart due to a lock file lingering, so changed back. But I also have it running on another instance on CE where it's been working fine...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.