Assistance setting up basic PFsense with VLans
-
Hello, I am in the process of moving away from a Meraki MX60 Meraki switch and Meraki WIFI AP. Cisco/Meraki equipment is nice but it comes at a cost and a time limit for renewal. I have another year before my time runs out but wanted to get a head start. Also I liked the functions of PFsense like AV and WAN caching and well…I like to learn and the web GUI’s of Meraki is just too easy.
Anyway my issue is that I setup an HP dl360 g4 server as my PF box. This is only a test at this point but I want to make sure I have a working environment before I replace my equipment. I loaded the software and went about configuring. I am able to do a simple configuration, 1 WAN, 1 LAN connection however soon as I bring in VLANs everything breaks.Still only two physical NIC connections and for the moment the WAN NIC plugs into my current network’s LAN. I can’t seem to get DHCP to assign addresses and I cant talk to the PF via its lan interface on any of the VLAN. I have gone over both my switch config as well as PF and nothing stands out. any suggestions or area’s I should look into? For switches I have Zyxel GS1900 and its interface is fairly straight forward so I don’t believe I have it configured wrong. But ill include screen shots of both.
Any assistance would be greatly appreciated!
-
Do some research on VLANs and what the terms tagged and untagged mean.
I have no idea what VLAN 1 on bge0 will do. In general, VLAN X on bge0 means traffic tagged with VLAN X. I am pretty sure you cannot tag VLAN 1 (the default untagged VLAN) so I don't know what that will do.
If you want to mix tagged and untagged traffic, assign, simply, bge0 for the untagged traffic and VLAN X on bge0 for tagged.
If your switch supports a "management VLAN" you might want to change it to a tagged VLAN and get off VLAN 1/Untagged entirely. It might only accept management connections on VLAN 1.
-
Ill give that a shot, removing vlan 1 and making it just a pass though port. I thought the PVID on the switch defaulted to vlan 1.