Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Laptop Not Working on Vlan

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    17 Posts 4 Posters 409 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O Offline
      oznet
      last edited by oznet

      Setup IoT vlan and and created a DHCP server for the IoT vlan.

      Then added the mac address of the laptop ethernet port under IoT to a static mapping.

      I never get the assigned Vlan IP on the laptop just the usual DHCP from the Lan interface.

      The IP assigned under IoT is not used on my home network.

      I set up the vlan for 192.168.50.1 and can ping that. This is as far as I can get.

      AndyRHA JKnottJ 2 Replies Last reply Reply Quote 0
      • AndyRHA Offline
        AndyRH @oznet
        last edited by

        @oznet Did you also add the VLAN to your switch if you are using a managed switch? Or is the subnet on a discreet port on the FW?
        Details on the build would be helpful.

        o|||||||o
        8200

        O 1 Reply Last reply Reply Quote 0
        • JKnottJ Offline
          JKnott @oznet
          last edited by

          @oznet

          Some notebooks do not support VLANs. I ran into that problem with a work computer. It depends on the drivers.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • O Offline
            oznet @AndyRH
            last edited by

            @AndyRH I have used port 4 on the 2100 for the laptop just for testing, so I can rule out my switches and access points and get this going first. the 2100 has the latest firmware.

            My Lan network runs IP from 192.168.1.1 for 254 addresses

            My IoT vlan is setup for 192.168.50 for 254 addresses

            The DHCP is setup to use the IoT with a static map using the laptops ethernet mac and assign 192.168.50.2

            AndyRHA 1 Reply Last reply Reply Quote 0
            • AndyRHA Offline
              AndyRH @oznet
              last edited by

              @oznet A picture of how port 4 is configured may shed some light. Did you actually build a VLAN or did you just create a new network and assign it to port 4? Doing the latter should mean the only network seen by the laptop would be the new network. If you did the former then you will need to tell the laptop what VLAN it should be on.
              Simply creating a new network and assigning it to the port is the best way IMO. I have my IPv6 network this way.

              o|||||||o
              8200

              luckman212L O 2 Replies Last reply Reply Quote 0
              • luckman212L Offline
                luckman212 LAYER 8 @AndyRH
                last edited by

                @oznet you didn't say which pfSense version you're using, that might be relevant. There were a few Kea bugs/gotchas (most of which have been fixed in the latest 26.07). E.g. redmine #15493 could cause things like this.

                I agree with AndyRH though that it's probably a VLAN config issue with the quirky Marvell 6000 switch on the 2100. You have to edit about 4 or 5 different screens to properly configure a VLAN on those devices.

                AndyRHA O 2 Replies Last reply Reply Quote 0
                • AndyRHA Offline
                  AndyRH @luckman212
                  last edited by

                  @luckman212 Good point, I forgot about the switch.

                  Getting the config right the first time can be a challenge.

                  o|||||||o
                  8200

                  1 Reply Last reply Reply Quote 0
                  • O Offline
                    oznet @AndyRH
                    last edited by

                    @AndyRH I actually followed this youtube video, and could ping 192.168.50.1 my vlan ip space, I did not create any rules yet, just plugged the laptop into a regular port 4 on the 2100. I am running 26.07.

                    Followed the video step by step

                    https://www.youtube.com/watch?v=rHE6MCL4Gz8

                    AndyRHA 1 Reply Last reply Reply Quote 0
                    • O Offline
                      oznet @luckman212
                      last edited by

                      @luckman212 followed this video seems striaght forward???

                      https://www.youtube.com/watch?v=rHE6MCL4Gz8

                      luckman212L 1 Reply Last reply Reply Quote 0
                      • AndyRHA Offline
                        AndyRH @oznet
                        last edited by

                        @oznet said in Laptop Not Working on Vlan:

                        could ping 192.168.50.1

                        That interface will almost always be pingable from another port because it is virtual and on the FW.

                        Because you are getting a wrong address it is likely the switch is not configured correctly. This is where a screen shot of the config is helpful. Many here can quickly tell you what is wrong if you show the right things.

                        o|||||||o
                        8200

                        1 Reply Last reply Reply Quote 0
                        • luckman212L Offline
                          luckman212 LAYER 8 @oznet
                          last edited by

                          @oznet that looks like a decent video, but a few things are definitely not ideal about it.

                          First, he's doing the demo in a Proxmox VM which is quite a bit different than configuring physical hardware, especially the 2100.

                          Second, and more importantly, it's based on pfSense CE 2.6.0 which is a 4+ year old version… you said you're running 26.07+ so I would definitely suggest trying to follow Netgate's official docs for configuring the special switch/VLANs on the 2100 as it's got critical steps that I'm sure that video is missing (although I admit I didn't watch the whole thing)

                          If you want your port 4 to operate as an independent interface (not a "trunk" port), you should try to set up 802.1q VLAN Mode.

                          O 1 Reply Last reply Reply Quote 0
                          • O Offline
                            oznet @luckman212
                            last edited by

                            @luckman212 1st_shot.png 2nd_shot.png 3rd_shot.png 4th_shot.png

                            luckman212L 1 Reply Last reply Reply Quote 0
                            • luckman212L Offline
                              luckman212 LAYER 8 @oznet
                              last edited by luckman212

                              @oznet Until you've got your main VLAN/DHCP problem worked out, I would not add additional complexity by setting "Deny Unknown Clients" in that restricted only known clients mode - makes this harder to troubleshoot for sure. Send screenshots of your Marvell 6000 switch config (all 3 tabs)

                              O 1 Reply Last reply Reply Quote 0
                              • luckman212L luckman212 referenced this topic
                              • O Offline
                                oznet @luckman212
                                last edited by

                                @luckman212

                                Ok I am still struggling on this vlan thing from the Netgate 2100 out to the IoT devices, I have watched a lot of videos but they dont start from scratch. I have 11 IoT devices I need to place on their own network with access only to the internet and not to my trusted. I have several devices not sure if I need to replace any of the switches or Ap's or what? I am a newbie at this. I am also not sure whether I need to configure one of the physical ports on the Netgate 2100 even? I have attached a diagram of my network at present. I do very much appreciate the help so far but need more help on this. Cheers Markhome_network_diagram_basic_IoT.jpg The circled red areas are the IoT devices to set up

                                luckman212L 1 Reply Last reply Reply Quote 0
                                • luckman212L Offline
                                  luckman212 LAYER 8 @oznet
                                  last edited by

                                  Yes, a couple of cheap Ubiquiti or even Microtik managed switches to replace those unmanaged Netgears is almost impossible to avoid if you want to get this done. As it is now, the unmanaged switches in the garage and other side of the house are going to make it impossible to isolate your security cameras on an IoT VLAN (even if you did manage to properly configure one of the Ethernet ports on the 2100 as a trunk or access port)

                                  I know you're looking for a YouTube video that walks through the setup of VLANs on the 2100. I found 1 in Spanish (but you can just follow along with the screens) and 1 from LTS that covers the 1100 which is almost identical to the 2100 so should be helpful:

                                  • Configurar VLANS en Pfsense Netgate 2100 (19:39) - 2025-06-09
                                  • SG-1100 VLAN Switch Configuration - Lawrence Systems (12:07) - 2019-08-25
                                  O 1 Reply Last reply Reply Quote 1
                                  • O Offline
                                    oznet @luckman212
                                    last edited by

                                    @luckman212 The security cameras will remain on trusted, but perhaps its best to replace the one in the garage and purchase 1 managed netgear rather than replacing 2 switches with another brand.

                                    I believe but correct me if I am wrong but will need to create another ssid for the tp link access points with my vlan tag and plug them into the managed netgear switches? The other unmanaged switch I will keep for my trusted network, does this make sense?

                                    luckman212L 1 Reply Last reply Reply Quote 0
                                    • luckman212L Offline
                                      luckman212 LAYER 8 @oznet
                                      last edited by

                                      You can stay with Netgear if you want, but if you want those circled IoT devices in the garage on your untrusted VLAN, and the cameras on trusted, then yes you definitely need a managed switch over there.

                                      It is possible to have a single SSID assign devices to different VLANs depending on their MAC address, if you use something like RADIUS. But I doubt you'd be setting that up. So yes- you'd create a dedicated SSID for IoT devices as long as your APs support that (TP-Link should be fine)

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                      Privacy Policy · Cookie Policy