VLAN Routing To pfSense - Need Help Please

  • Hey All,

    I'm pretty sure this an interface routing issue that I'm having with my Cisco SG 300, however I want to run it by a more seasoned crowd.  The issue I'm having is that I can't get any of my VLAN traffic out my Cisco SG 300 out to pfSense and then to the internet.  I can however sit on a port that has VLAN1 associated with it and set my IP address to (pfSense is and all connectivity works just fine.  So again, I think it's a VLAN issue of sorts.

    I would like to do all of my inter-VLAN routing within the Cisco SG 300 (which currently works).  Would like all other traffic to go out to pfSense for routing.  I know VLAN1 is a no-no, just using it for testing and will change it in the future.

    Any help would be greatly appreciated.  I've attached a few screenshots of my current setup.


    ![Screen Shot 2015-07-26 at 4.44.38 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.38 PM.png)
    ![Screen Shot 2015-07-26 at 4.44.38 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.38 PM.png_thumb)
    ![Screen Shot 2015-07-26 at 4.44.48 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.48 PM.png)
    ![Screen Shot 2015-07-26 at 4.44.48 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.48 PM.png_thumb)
    ![Screen Shot 2015-07-26 at 4.45.01 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.45.01 PM.png)
    ![Screen Shot 2015-07-26 at 4.45.01 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.45.01 PM.png_thumb)

  • Added a couple screenshots of my setup in pfSense as well.  Pretty much a stock setup from the install.

  • One more update.  Added a gateway and a route so that I could to my VLANS.  Still can't get out to the internet from them.


  • LAYER 8 Netgate

    Put a host on on GE9 (Or any other access port on VLAN 20.)

    Can it ping

    Can it ping

    Can it ping

  • @Derelict:

    Put a host on on GE9 (Or any other access port on VLAN 20.)

    Can it ping Yes

    Can it ping Yes

    Can it ping No

    Hi Dereict.  Thanks for helping out.  My answers are above.  It's odd that I  can get to (Cisco SG300) but not (pfSense).  I also confirmed it's just not blocking ICMP as I cannot get to the pfSense webGUI on

    I can also ping all the other hosts on 172.16.20.x and other VLANS on the SG 300 (172.16.30.x)


  • After answering the above question.  Should my Interface LAN IP addressing be set to the following to allow for the other subnets?

    Would changing the IP address allow for the routing of the other subnets?  172.16.15.x, 172.16.20.x, 172.16.30.x?

    Screen shot attached of what I currently have in place.

    ![Screen Shot 2015-07-27 at 7.49.26 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 7.49.26 AM.png)
    ![Screen Shot 2015-07-27 at 7.49.26 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 7.49.26 AM.png_thumb)

  • After logged into my older router (Asus Wifi/Router) the LAN IP was set to with a netmask of, so I don't think that's the issue.

  • Another quick update:  I can get to pfSense from my VLAN20 subnet (172.16.20.x).  However, I still can not get to the internet from those subnets.

    Added an Any-to-Any firewall rule for testing purposes.  Same results though.


    ![Screen Shot 2015-07-27 at 8.37.50 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 8.37.50 AM.png)
    ![Screen Shot 2015-07-27 at 8.37.50 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 8.37.50 AM.png_thumb)

  • Banned


    Added an Any-to-Any firewall rule for testing purposes.  Same results though.

    That rule does not allow DNS (UDP), does not allow ping (ICMP)… Not sure how you are testing.

  • Yeah good call.  Saw that.  It was the issue.  Added all protocols and it fixed the issue.

    Now I'm getting odd RDP random disconnects.

  • Fixed the above with the attached screenshot.

    ![Screen Shot 2015-07-27 at 9.30.58 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 9.30.58 AM.png)
    ![Screen Shot 2015-07-27 at 9.30.58 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 9.30.58 AM.png_thumb)

  • Thanks for everyones help.  Much appreciated.

Log in to reply