Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Need help setting up new fresh install of pfsense with lagg and 5 vlans

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 5 Posters 1.0k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hermanmunster
      last edited by

      Been trying for weeks to go from a flat network to vlans but cannot seem to get it working. I cant tell if its my switch or firewall.

      Firewall- protectli 4 port
      ManagedSwitch- tplink tl sg1016 de

      Firewall:
      I have lagg0 setup on igb2,3
      5 vlans 10-50 setup with lagg0 as parent interface
      Dhcp setup for vlans individual subnets

      Switch:
      Have default vlan1 on ports 1,2 with pvid 1(undeletable default vlan)
      Ports 3,4 LAGG connected to firewall lagg ports pvid1
      Ports 5,6 untagged pvid10
      Ports7,8 untagged pvid20
      Ports9,10 untagged pvid30
      Ports11,12 untagged pvid40
      Ports 13-16 untagged pvid50

      On all of the ports I have tried tagging 1 (the port that goes to lan) or the lag ports and cant seem to be able to ping from my pc plugged into switch port 2 on lan to a pc plugged into port 9 on the switch.
      I am sure I am missing something on pfsense in the firewall or something else.
      So far with all the tinkering and referencing several half decade old posts and videos I am thoroughly confused. And everyone seems to do firewall rules in same but different ways.

      Any direction is welcome as its been weeks and I cant seem to get any traction and might just be chasing my tail

      patient0P johnpozJ stephenw10S 3 Replies Last reply Reply Quote 0
      • patient0P Online
        patient0 @hermanmunster
        last edited by

        @hermanmunster said in Need help setting up new fresh install of pfsense with lagg and 5 vlans:

        Ports 3,4 LAGG connected to firewall lagg ports pvid1

        For the VLAN tagged traffic to be allowed on LAGG Ports 3 & 4 all the VLAN IDs have to be add as tagged. E.g.

        VID 10: untagged ports 5 & 6, tagged 3 & 4
        ... and similar for the other VLAN. Have you done that? LAN (vid 1) should work on ports 1 & 2 AFAIK see. Can you post screenshots of the switch configuration for one VLAN (all tabs, like PVID and 802.1q). Having said that: what VLAN mode have you set, port based or 802.1q?

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator @hermanmunster
          last edited by johnpoz

          @hermanmunster said in Need help setting up new fresh install of pfsense with lagg and 5 vlans:

          (undeletable default vlan)

          If you can not delete default vlan your going to have a bad day.. How can you put say port 5 into vlan X if you can not remove vlan 1? You can't have a port with more than 1 untagged vlan.

          there were many a thread a few years back where these tplink switches had this issue where you could not remove vlan 1. I thought they fixed that with firmware?

          What I would suggest is you make sure you can delete vlan 1 if you put a port in vlan X.. If you can not - throw the switch away its useless.

          As to working with lag ports.. I would suggest you get your vlans working with only 1 physical port before you attempt to add connections into the lagg/lacp/portchannel/etherchannel setup etc..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

          dennypageD 1 Reply Last reply Reply Quote 1
          • stephenw10S Online
            stephenw10 Netgate Administrator @hermanmunster
            last edited by

            @hermanmunster said in Need help setting up new fresh install of pfsense with lagg and 5 vlans:

            ManagedSwitch- tplink tl sg1016 de

            That's from TP-Link's range of 'do-not-want' swicthes! 😉

            But in all seriousness those switches have known firmware bugs that can trip you up. Including not being able to remove the default vlan.

            You can still use it though as long as you either don't use anything untagged or don't care about broadcasts to the default vlan leaving all ports. I have that switch. Oh also it doesn't pass packet fragments which is... interesting. Mine is the 1.0 hw.

            H 1 Reply Last reply Reply Quote 0
            • H Offline
              hermanmunster @stephenw10
              last edited by

              @stephenw10 yes haha I posted and then figured that out finally but didnt delete my post. The fix is I ordered a linksys managed switch hopefully those arent bad?

              1 Reply Last reply Reply Quote 0
              • stephenw10S Online
                stephenw10 Netgate Administrator
                last edited by

                I have no experience with them but they're probably fine.

                You can use the tp-link switch with vlans and it will work fine with the known caveats. You certainly should be able to ping between VLANs fine.

                Did you have all the VLANs tagged on the ports in the LAGG?

                1 Reply Last reply Reply Quote 0
                • dennypageD Offline
                  dennypage @johnpoz
                  last edited by

                  @johnpoz said in Need help setting up new fresh install of pfsense with lagg and 5 vlans:

                  As to working with lag ports.. I would suggest you get your vlans working with only 1 physical port before you attempt to add connections into the lagg/lacp/portchannel/etherchannel setup etc..

                  This is very wise advice…

                  1 Reply Last reply Reply Quote 2
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                  Privacy Policy · Cookie Policy