Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense 1.2.3 and multiple SSID WLAN utilizing VLANs

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 1 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jrmitchell83
      last edited by

      Hi,

      I'm driving myself crazy trying to setup a configuration as follows:

      Internet -> pfSense 1.2.3 -> Netgear GS724TPS Smart Switch -> Netgear Access point (WNAP320) running 1 untagged and 1 tagged SSID/VLAN.

      My goal is to have the untagged SSID run against the "core" network while the tagged SSID/VLAN would be for guests so they cannot access my internal network.

      Working backwards, I setup the following:
      1. primary SSID on VLAN 1 untagged and the the secondary (guest) SSID on VLAN20.
      2. Created VLAN20 on the switch and set VLAN20 as "tagged" on the switch.
      3. Created VLAN20 in pfSense and setup DHCP on this VLAN for 192.168.55.1 (General Internal is set to 192.168.1.1).
      4. Associated with the guest SSID, and I'm receiving an IP in the 192.168.55.1 network but I'm not able to access the internet.

      I think I'm close here but must have a step missing?

      One more question I have is….I do not want this guest VLAN to be able to speak to my 192.168.1.1 network. Is it possible for someone to associate to the guest SSID and manually set an IP in the 192.168.1.1 network and gain access? Do both of the SSIDs need to by tagged for "better" security or is my config OK? Any suggestions to my approach would be great!

      Is there an example of this in the forums somewhere? I searched but didn't get a perfect hit

      1 Reply Last reply Reply Quote 0
      • J
        jrmitchell83
        last edited by

        Did I put this in the wrong forum? :)

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.