Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Vlan traffic not working

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    2 Posts 1 Posters 180 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      beavis
      last edited by

      I am trying to setup new vlan for DMZ. I have read this forum and pfsense documents, but some how I cannot get this right. All trafic is OK but not new vlan 70.

      I can ping all ip address assigned to pfsense interfaces from LAN and all host in LAN but cannot ping any host in vlan70. I have tried to set ESX port group to 70 and 4095, I have tried Zyxel switch port 7 (DMZ interface connection) vlan settings tag and untag.
      When I change ESX port group vlan from 70 to 4095 then hosts in vlan70 gets ip from network 10.10.10.0 and not from 10.10.70.0.

      Here is my setup:
      Pfsense 2.7.2 running as VM on ESXi 8. It has 4 physical NIC's
      ESX has 4 Vswitch and 5 port groups, LAN and DMZ port group has vlan 4095
      Physical connections WAN(vmx0) to Ubiquiti cloudGW, LAN(vmx1) and DMZ(vmx3) on same swith and kamera(vmx2) on different switch.

      ESX
      f420ece0-6bc5-40ca-8b9c-8dbeba094ff1-image.png

      Zyxel GS1200 switch
      e2541ac1-4974-432d-8fea-917c61c7827f-image.png

      Pfsense interfaces
      570582de-dd0c-431e-847b-23aec0d79aa0-image.png

      WAN has address 172.16.1.200 and gateway from Ubiquiti
      LAN has 10.10.10.200/24 no gateway
      Kamera has 10.10.30.200/24 no gateway
      DMZ has no ip
      vlantesti has ip 10.10.50.200/24 no gateway
      DMZvlan has 10.10.70.200/24 no gateway

      Pfsense vlan
      8a8b6f41-8471-4900-a775-fd5df1bc45cc-image.png

      FW rules
      305386f2-271d-4035-babd-c6c0a8348767-image.png

      8159a18d-b185-4df7-a6da-a9efa3f5b18d-image.png

      What is wrong in here?

      1 Reply Last reply Reply Quote 0
      • B
        beavis
        last edited by

        I lost my mind with this vlan and made it simple. Removed vlan70 from pfsense and assigned for that parent interface ip in subnet 10.10.70.
        Interface is uplink for DMZ vswitch and port group in exs. So I will put all DMZ vm's in that port group.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.