Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN plus VLANs: device gets IP from the wrong DHCP-server

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    18 Posts 2 Posters 190 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sgw @patient0
      last edited by

      @patient0 said in LAN plus VLANs: device gets IP from the wrong DHCP-server:

      And there is not much point in allowing all VLAN on Switch2p21 if it can't do VLANs.

      correct. turned that off now. For sure this doesn't explain the DHCP issue.

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        sgw @sgw
        last edited by

        corrected a mistake:

        eno1 .. Switch2port13 .. is member of vmbr0 on the PVE

        it only transports tagged VLANs .. so it can't transport the untagged DHCP traffic from LAN2 also

        My try would be: connect PC as DHCP-client to switch1p20 (that's where the problems were reported first), let it get an address. Yesterday it pulled an IP in LAN2.

        Then remove the connection between Switch2 and Switch3, retry.

        We can only do that when we have announced some maintenance window (next week).

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          sgw @sgw
          last edited by

          Just as a thought:

          I don't have these 2 boxes ticked on the pfSense interfaces:

          https://docs.netgate.com/pfsense/en/latest/interfaces/configure.html#reserved-networks

          And the firewall rules have this "allow * from/to everywhere" for LAN and LAN2.

          PCs should reach servers etc / but we don't want these DHCP-packages.

          Should I block port 67/68 on LAN2 interface?

          patient0P 1 Reply Last reply Reply Quote 0
          • patient0P Offline
            patient0 @sgw
            last edited by

            @sgw said in LAN plus VLANs: device gets IP from the wrong DHCP-server:

            I don't have these 2 boxes ticked on the pfSense interfaces:
            https://docs.netgate.com/pfsense/en/latest/interfaces/configure.html#reserved-networks

            No, as mentioned on the page it is usually used on WAN interfaces to block RFC1918 traffic.

            Should I block port 67/68 on LAN2 interface?

            I don't see why that would be necessary. If you read DHCP discovery you see that the client sends a DHCPDISCOVER to 255.255.255.255 which is limited to the broadcast domain (LAN1).
            I think it's best if you use Wireshark to sniff the traffic that you see on a port with PVID1 to check what DHCP traffic you see.

            Btw, I assume you have set that port on the switch to PVID1 and no VLANs allowed?

            S 2 Replies Last reply Reply Quote 0
            • S Offline
              sgw @patient0
              last edited by

              @patient0 said in LAN plus VLANs: device gets IP from the wrong DHCP-server:

              Btw, I assume you have set that port on the switch to PVID1 and no VLANs allowed?

              pls detail which port is meant here, thx

              patient0P S 2 Replies Last reply Reply Quote 0
              • patient0P Offline
                patient0 @sgw
                last edited by

                @sgw I was referring to the port you put the client on which should get a LAN1 IP.

                1 Reply Last reply Reply Quote 0
                • S Offline
                  sgw @sgw
                  last edited by sgw

                  You talk about the access port for the PC? Yes, its PVID is 1 = LAN1 native. VLANs are allowed there per default, I assumed this wouldn't hurt as the PC should not talk tagged. But we will test that.

                  patient0P 1 Reply Last reply Reply Quote 0
                  • S Offline
                    sgw @patient0
                    last edited by

                    @patient0 said in LAN plus VLANs: device gets IP from the wrong DHCP-server:

                    I don't see why that would be necessary. If you read DHCP discovery you see that the client sends a DHCPDISCOVER to 255.255.255.255 which is limited to the broadcast domain (LAN1).
                    I think it's best if you use Wireshark to sniff the traffic that you see on a port with PVID1 to check what DHCP traffic you see.

                    Good to hear that my fw-rules aren't wrong in that way ... I run pfSenses with dozens of VLANs and interfaces in other sites and never had such an issue so far.

                    1 Reply Last reply Reply Quote 0
                    • patient0P Offline
                      patient0 @sgw
                      last edited by

                      @sgw said in LAN plus VLANs: device gets IP from the wrong DHCP-server:

                      I assumed this wouldn't hurt as the PC should not talk tagged. But we will test that.

                      It shouldn't, you're right. But to narrow it down it would help.

                      I do use a Unifi Switch and have clients on ports configured like yours (native VLAN 1 and allow all VLAN) and it works as expected.

                      S 1 Reply Last reply Reply Quote 0
                      • S Offline
                        sgw @patient0
                        last edited by sgw

                        @patient0 I don't know about that PC. But it's very unlikely that it's configured to understand VLAN 150. This VLAN comes from me and exists only on my systems (pfSense, switches, PVE).

                        But sure, I will take away the VLANs from that port at first.

                        thanks so far

                        I wrote an issue on the german Proxmox-forum as well, to check my bridging setup on the PVE.

                        I link it here, maybe somebody is interested as well:
                        link

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.