Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN Routing To pfSense - Need Help Please

    Scheduled Pinned Locked Moved Routing and Multi WAN
    12 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      Miscue
      last edited by

      Hey All,

      I'm pretty sure this an interface routing issue that I'm having with my Cisco SG 300, however I want to run it by a more seasoned crowd.  The issue I'm having is that I can't get any of my VLAN traffic out my Cisco SG 300 out to pfSense and then to the internet.  I can however sit on a port that has VLAN1 associated with it and set my IP address to 172.16.15.166 (pfSense is 172.16.15.1) and all connectivity works just fine.  So again, I think it's a VLAN issue of sorts.

      I would like to do all of my inter-VLAN routing within the Cisco SG 300 (which currently works).  Would like all other traffic to go out to pfSense for routing.  I know VLAN1 is a no-no, just using it for testing and will change it in the future.

      Any help would be greatly appreciated.  I've attached a few screenshots of my current setup.

      Cheers,
      Miscue

      ![Screen Shot 2015-07-26 at 4.44.38 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.38 PM.png)
      ![Screen Shot 2015-07-26 at 4.44.38 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.38 PM.png_thumb)
      ![Screen Shot 2015-07-26 at 4.44.48 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.48 PM.png)
      ![Screen Shot 2015-07-26 at 4.44.48 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.44.48 PM.png_thumb)
      ![Screen Shot 2015-07-26 at 4.45.01 PM.png](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.45.01 PM.png)
      ![Screen Shot 2015-07-26 at 4.45.01 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-26 at 4.45.01 PM.png_thumb)

      1 Reply Last reply Reply Quote 0
      • M Offline
        Miscue
        last edited by

        Added a couple screenshots of my setup in pfSense as well.  Pretty much a stock setup from the install.

        pfSense_carvalho_local_-_Status__Dashboard.png
        pfSense_carvalho_local_-_Status__Dashboard.png_thumb
        pfSense_carvalho_local_-_System__Gateways.png
        pfSense_carvalho_local_-_System__Gateways.png_thumb

        1 Reply Last reply Reply Quote 0
        • M Offline
          Miscue
          last edited by

          One more update.  Added a gateway and a route so that I could to my VLANS.  Still can't get out to the internet from them.

          Cheers,
          Miscue.

          pfSense_carvalho_local_-_System__Static_Routes.png
          pfSense_carvalho_local_-_System__Static_Routes.png_thumb
          pfSense_carvalho_local_-_System__Gateways.png
          pfSense_carvalho_local_-_System__Gateways.png_thumb

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Put a host on 172.16.20.0/24 on GE9 (Or any other access port on VLAN 20.)

            Can it ping 172.16.20.1?

            Can it ping 172.16.15.2?

            Can it ping 172.16.15.1?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • M Offline
              Miscue
              last edited by

              @Derelict:

              Put a host on 172.16.20.0/24 on GE9 (Or any other access port on VLAN 20.)

              Can it ping 172.16.20.1? Yes

              Can it ping 172.16.15.2? Yes

              Can it ping 172.16.15.1? No

              Hi Dereict.  Thanks for helping out.  My answers are above.  It's odd that I  can get to 172.16.15.2 (Cisco SG300) but not 172.16.15.1 (pfSense).  I also confirmed it's just not blocking ICMP as I cannot get to the pfSense webGUI on 172.16.15.1.

              I can also ping all the other hosts on 172.16.20.x and other VLANS on the SG 300 (172.16.30.x)

              Cheers,
              Miscue

              1 Reply Last reply Reply Quote 0
              • M Offline
                Miscue
                last edited by

                After answering the above question.  Should my Interface LAN IP addressing be set to the following to allow for the other subnets?

                172.16.15.1/16?

                Would changing the IP address allow for the routing of the other subnets?  172.16.15.x, 172.16.20.x, 172.16.30.x?

                Screen shot attached of what I currently have in place.

                ![Screen Shot 2015-07-27 at 7.49.26 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 7.49.26 AM.png)
                ![Screen Shot 2015-07-27 at 7.49.26 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 7.49.26 AM.png_thumb)

                1 Reply Last reply Reply Quote 0
                • M Offline
                  Miscue
                  last edited by

                  After logged into my older router (Asus Wifi/Router) the LAN IP was set to 172.16.15.1 with a netmask of 255.255.255.0, so I don't think that's the issue.

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    Miscue
                    last edited by

                    Another quick update:  I can get to pfSense from my VLAN20 subnet (172.16.20.x).  However, I still can not get to the internet from those subnets.

                    Added an Any-to-Any firewall rule for testing purposes.  Same results though.

                    Cheers,
                    Brad

                    ![Screen Shot 2015-07-27 at 8.37.50 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 8.37.50 AM.png)
                    ![Screen Shot 2015-07-27 at 8.37.50 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 8.37.50 AM.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      doktornotor Banned
                      last edited by

                      @Miscue:

                      Added an Any-to-Any firewall rule for testing purposes.  Same results though.

                      That rule does not allow DNS (UDP), does not allow ping (ICMP)… Not sure how you are testing.

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        Miscue
                        last edited by

                        Yeah good call.  Saw that.  It was the issue.  Added all protocols and it fixed the issue.

                        Now I'm getting odd RDP random disconnects.

                        1 Reply Last reply Reply Quote 0
                        • M Offline
                          Miscue
                          last edited by

                          Fixed the above with the attached screenshot.

                          ![Screen Shot 2015-07-27 at 9.30.58 AM.png](/public/imported_attachments/1/Screen Shot 2015-07-27 at 9.30.58 AM.png)
                          ![Screen Shot 2015-07-27 at 9.30.58 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-07-27 at 9.30.58 AM.png_thumb)

                          1 Reply Last reply Reply Quote 0
                          • M Offline
                            Miscue
                            last edited by

                            Thanks for everyones help.  Much appreciated.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.