• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Routing vLAN to Internet[SOLVED!!]

Scheduled Pinned Locked Moved Routing and Multi WAN
7 Posts 3 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nappy_d
    last edited by Jan 20, 2016, 2:46 AM Jan 16, 2016, 10:20 PM

    Hi all, I am trying to configure a vLAN(vLAN25) as a guest Internet connection with my UniFi UAP-LR access points.

    What I have working is DHCP on my vLAN25 Interface and what appears to be communication with wireless devices.

    What I am unable to do is route traffic to the internet.

    Can anyone give me a tip to get this working?

    In my research I have configured the following screenshot but so far no success in getting this working.  Access through my vlan1 connected SSID is working 100%.

    TIA…
    ![Screen Shot 2016-01-16 at 5.18.09 PM.png](/public/imported_attachments/1/Screen Shot 2016-01-16 at 5.18.09 PM.png)
    ![Screen Shot 2016-01-16 at 5.18.09 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2016-01-16 at 5.18.09 PM.png_thumb)

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by Jan 16, 2016, 11:52 PM

      WAN net is the subnet of WAN interface address. If you want access Internet host change the destination to "any".
      However, if you want to prevent wife guests from accessing your LANs, add an alias that contains all you internal subnets and in the firewall rule check "not" at destination, select alias and enter this alias below instead.

      1 Reply Last reply Reply Quote 0
      • N
        nappy_d
        last edited by Jan 17, 2016, 4:02 AM

        Thanks for that. I setup the rule as below and still not able to route this vlan to the internet.

        Any further thoughts?

        ![Screen Shot 2016-01-16 at 10.57.12 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2016-01-16 at 10.57.12 PM.png_thumb)
        ![Screen Shot 2016-01-16 at 10.57.12 PM.png](/public/imported_attachments/1/Screen Shot 2016-01-16 at 10.57.12 PM.png)

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by Jan 17, 2016, 10:54 AM

          Now you allow only TCP protocol. For DNS there is also UDP necessary. So change it at least to TCP/UDP, if you want allow no further.

          And in Firewall > NAT > Outbound check if you guest wifi has been added to the rules.

          1 Reply Last reply Reply Quote 0
          • N
            nappy_d
            last edited by Jan 17, 2016, 5:22 PM

            Thanks…some interesting and strange issues are occurring with this subinterface.  When I configured this vLAN:

            • Internet browsing slowly decays to the point that even my default Wifi vLAN stops working.
            • I delete the sub-interface all settings and reboot then all started to work again.

            My system used is at follows...any thoughts?

            • Lenovo Think Center M55

            • Second NIC for LAN TP-Link PCI-E 1GigE

            • Version 2.2.6-RELEASE (i386)

            • built on Mon Dec 21 14:50:36 CST 2015

            • FreeBSD 10.1-RELEASE-p25

            • CPU Type Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz

            • 2 CPUs: 1 package(s) x 2 core(s)

            • 40GB SSD

            1 Reply Last reply Reply Quote 0
            • N
              nappy_d
              last edited by Jan 20, 2016, 2:45 AM

              OK I solved this issue. It turns out that by me changing the sub interfaces name from OPT1 to as an example GuestWiFi, it was somehow causing issues within pfSense.

              Maybe it is somewhere deep in the manual but as long as I leave the default subinterface names as it is created, everything works well and tagging and routing occurs.

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Jan 20, 2016, 1:50 PM

                I have all my opt interfaces renamed.. that has nothing to do with your problem..  Unless maybe your trying to call 2 the same name?

                Some are physical nics, others are vlans on physical nics - see attached.

                interfacenames.png
                interfacenames.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received