Laptop Not Working on Vlan
-
Setup IoT vlan and and created a DHCP server for the IoT vlan.
Then added the mac address of the laptop ethernet port under IoT to a static mapping.
I never get the assigned Vlan IP on the laptop just the usual DHCP from the Lan interface.
The IP assigned under IoT is not used on my home network.
I set up the vlan for 192.168.50.1 and can ping that. This is as far as I can get.
-
@oznet Did you also add the VLAN to your switch if you are using a managed switch? Or is the subnet on a discreet port on the FW?
Details on the build would be helpful. -
Some notebooks do not support VLANs. I ran into that problem with a work computer. It depends on the drivers.
-
@AndyRH I have used port 4 on the 2100 for the laptop just for testing, so I can rule out my switches and access points and get this going first. the 2100 has the latest firmware.
My Lan network runs IP from 192.168.1.1 for 254 addresses
My IoT vlan is setup for 192.168.50 for 254 addresses
The DHCP is setup to use the IoT with a static map using the laptops ethernet mac and assign 192.168.50.2
-
@oznet A picture of how port 4 is configured may shed some light. Did you actually build a VLAN or did you just create a new network and assign it to port 4? Doing the latter should mean the only network seen by the laptop would be the new network. If you did the former then you will need to tell the laptop what VLAN it should be on.
Simply creating a new network and assigning it to the port is the best way IMO. I have my IPv6 network this way. -
@oznet you didn't say which pfSense version you're using, that might be relevant. There were a few Kea bugs/gotchas (most of which have been fixed in the latest 26.07). E.g. redmine #15493 could cause things like this.
I agree with AndyRH though that it's probably a VLAN config issue with the quirky Marvell 6000 switch on the 2100. You have to edit about 4 or 5 different screens to properly configure a VLAN on those devices.
-
@luckman212 Good point, I forgot about the switch.
Getting the config right the first time can be a challenge.
-
@AndyRH I actually followed this youtube video, and could ping 192.168.50.1 my vlan ip space, I did not create any rules yet, just plugged the laptop into a regular port 4 on the 2100. I am running 26.07.
Followed the video step by step
https://www.youtube.com/watch?v=rHE6MCL4Gz8
-
@luckman212 followed this video seems striaght forward???
https://www.youtube.com/watch?v=rHE6MCL4Gz8
-
@oznet said in Laptop Not Working on Vlan:
could ping 192.168.50.1
That interface will almost always be pingable from another port because it is virtual and on the FW.
Because you are getting a wrong address it is likely the switch is not configured correctly. This is where a screen shot of the config is helpful. Many here can quickly tell you what is wrong if you show the right things.
-
@oznet that looks like a decent video, but a few things are definitely not ideal about it.
First, he's doing the demo in a Proxmox VM which is quite a bit different than configuring physical hardware, especially the 2100.
Second, and more importantly, it's based on pfSense CE 2.6.0 which is a 4+ year old version… you said you're running 26.07+ so I would definitely suggest trying to follow Netgate's official docs for configuring the special switch/VLANs on the 2100 as it's got critical steps that I'm sure that video is missing (although I admit I didn't watch the whole thing)
If you want your port 4 to operate as an independent interface (not a "trunk" port), you should try to set up 802.1q VLAN Mode.
-
-
@oznet Until you've got your main VLAN/DHCP problem worked out, I would not add additional complexity by setting "Deny Unknown Clients" in that restricted only known clients mode - makes this harder to troubleshoot for sure. Send screenshots of your Marvell 6000 switch config (all 3 tabs)
-
L luckman212 referenced this topic
-
Ok I am still struggling on this vlan thing from the Netgate 2100 out to the IoT devices, I have watched a lot of videos but they dont start from scratch. I have 11 IoT devices I need to place on their own network with access only to the internet and not to my trusted. I have several devices not sure if I need to replace any of the switches or Ap's or what? I am a newbie at this. I am also not sure whether I need to configure one of the physical ports on the Netgate 2100 even? I have attached a diagram of my network at present. I do very much appreciate the help so far but need more help on this. Cheers Mark
The circled red areas are the IoT devices to set up -
Yes, a couple of cheap Ubiquiti or even Microtik managed switches to replace those unmanaged Netgears is almost impossible to avoid if you want to get this done. As it is now, the unmanaged switches in the garage and other side of the house are going to make it impossible to isolate your security cameras on an IoT VLAN (even if you did manage to properly configure one of the Ethernet ports on the 2100 as a trunk or access port)
I know you're looking for a YouTube video that walks through the setup of VLANs on the 2100. I found 1 in Spanish (but you can just follow along with the screens) and 1 from LTS that covers the 1100 which is almost identical to the 2100 so should be helpful:
- Configurar VLANS en Pfsense Netgate 2100 (19:39) - 2025-06-09
- SG-1100 VLAN Switch Configuration - Lawrence Systems (12:07) - 2019-08-25
-
@luckman212 The security cameras will remain on trusted, but perhaps its best to replace the one in the garage and purchase 1 managed netgear rather than replacing 2 switches with another brand.
I believe but correct me if I am wrong but will need to create another ssid for the tp link access points with my vlan tag and plug them into the managed netgear switches? The other unmanaged switch I will keep for my trusted network, does this make sense?
-
You can stay with Netgear if you want, but if you want those circled IoT devices in the garage on your untrusted VLAN, and the cameras on trusted, then yes you definitely need a managed switch over there.
It is possible to have a single SSID assign devices to different VLANs depending on their MAC address, if you use something like RADIUS. But I doubt you'd be setting that up. So yes- you'd create a dedicated SSID for IoT devices as long as your APs support that (TP-Link should be fine)
Privacy Policy · Cookie Policy
