Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - danman

#1
I finally made the first part! Which means I got my brain working with PVID and UNTAGGED etc.
AP is fully working now. One switch works... yeah, this part is done.

Thank you @nero355 & viragomann for all the hints/help! That was really helpful =)

On Sunday will be the swap with the openwrt main router and then I've to check the other switches, proxmox and whatnot.
I'll be back ;)
#2
QuoteWhat are you trying to achieve ?!

- Setting the correct Management IP Address for the webGUI of the Switch ?
- Getting the right subnet to specific Clients connected to the Switch ?

Exactly that -> `Setting the correct Management IP Address for the webGUI of the Switch?`

Quote- Router <---> Switch = Always Tagged.
- Switch <---> Switch = Always Tagged.
- Switch <---> Accesspoint = Always Tagged.
- Switch <---> Wired Clients = Untagged.
- Accesspoint <---> Wireless Clients = Tagged VLAN in the SSID Settings and once the Wireless Clients connect they get an Untagged connection.
The AP should be like that but I've to check it properly, the entire openwrt AP device. Like I mentioned, the connection works good on the current openwrt main router but I dont have a IP listed under "Active DHCPv4 Leases" either on the main openwrt device. I'm not focusing on the AP at the moment because it has some firewall still running on that device and such. I just wanted to mentioned that the tagged from opnsense (port 1 - igc1 VLANs) -> switch (port 5 only TAGGED) -> openwrt (wan port TAGGED and untagged) works so far.

QuoteHowever... in some cases... you need to also add one Untagged VLAN in order to have a Management IP Address for Switches and Accesspoints and this subnet comes from a seperate Untagged NIC in the case of OPNsense as I was trying to explain to your earlier on !!
I dont understand. So do you mean other ports on the opnsense device should be used only for different switches/APs?
Quote- Pick any of the available NICs for a new Interface and just leave it Enabled but without any IP Address configuration.
Are you talking particular about that?

QuoteCan we assume that each VLAN Interface has it's own Subnet and active DHCP Server + the right Firewall Rules ?

In other words : You are not trying to spread one Subnet and DHCP Server across multiple VLANs ?
Nah, thats all good. I checked it a few times now. Also all Interfaces are selected under general.

QuoteIf you don't get any DHCP IP Address then there is an error in your configuration => See my previous questions !!
Well, I thought PVID takes care to tell opnsense that this switch would like to go with VLAN 25 but this seems to be not the case so I think the only option is to use a static IP address.

I've also a few proxmox server and other switches etc I'll see how that will work. I think on proxmox for example I had to set up IPv4/CIDR which should take care of that.

Maybe, I was just lucky before that the switches took the right VLAN in the first place :D I'm not so familiar with VLAN, I'm not setting it up every day or even years. Once its done, its done ;)

QuoteLooks like another configuration error! Possibly between the Switch and the Accesspoint ?!
I think I can try a bit more on the AP as I mentioned further up in this post.

QuoteThen you need to fix your OPNsense configuration :P
I think it's more my way of thinking about all that especially the PVID is probably the key issue in my brain here :D
#3
I was just editing my post...

Edit:
I think I probably miss something here.  I just try to understand that:
OPNsense
  • all VLANs are running on Port 1 (igc1)
  • IP set
  • DHCP set

switch on port 5
  • all tagged, nothing untagged on port 5
  • PVID doesn't matter
  • for now only static IP works

openwrt AP
  • all tagged from switch port 4 to WAN port
  • VLANs created
  • WiFi 2.4 for VLAN ID 80 and wifi 5 for VLAN 50 (but it connects to ID 60/80 or whatever)

I just hooked the switch and the openwrt AP device onto my current set up with the main openwrt router. VLAN configs are the exact same for the AP and switch like I try to use with the opnsense router.
That works very good. Thats not helpful :D

EDIT END

QuoteIf you want to connect devices to VLAN 25 you will have to use a different switch port, where you can configure the PVID.
Yeah, that works too. The issue is here how can I tell opnsense that the switch I use to trunk the VLANs to to put this switch in IP range 25 (VLAN ID 25) without static IP and without PVID?

I don't understand why the openwrt AP doesnt connect to right VLAN ID either. It doesnt makes sense. I've to check that again. Something doesnt work here right :D but actually I checked it already but obviously there is something weird going on.
#4
Quote1. By default, the PVID of all ports is 1.
2. 802.1Q VLAN PVID will be restored to 1 when 802.1Q VLAN is disabled.

QuoteThis would tag any incoming packet with VLAN ID 5, which makes no sense for a trunk port.
Not sure why it would be 5 but it doesn't matter.

I need to somehow tell the switch to connect to the specific VLAN ID 25 which would mean, whenever I use a device to trunk VLANs I'll need to set a static IP  for that particular device as well.
Because I've a few devices/VMs I would like to avoid that :D
#5
QuoteIs a MUST because FreeBSD based stuff doesn't seem to like UNTAGGED and TAGGED traffic combined on the same Switch Port according to a lot of users here on the forum !!
I've on that port only VLANs TAGGED to the switch and also now that - "- Pick any of the available NICs for a new Interface and just leave it Enabled but without any IP Address configuration." but that doesnt change anything. Same issue as before.

QuoteMeans you don't want that type of access anywhere else on your network ?
I've created a VLAN management for that but I'm not sure if Im going to use it.I might set things differently. But for now, the port 3 is the physical (no VLAN/untagged) access to the opnsense router.

QuoteI am sure that once you get everything working correctly the DHCP Server will start working for you correctly too :)
I hope so :D

QuoteDisabling the Firewall shoudn't be needed at any point so let's agree to never do that again, OK ? ;)
Haha, yeah its not connected to the Internet. I just want to set things up first. It can be handy to check out any firewall issues. I might reset the switch, might be an issue there.
I watched a video last night that you should suppose to set the VLAN PVID only on untagged ports but how does opnsense know which VLAN to handle the switch with then? And I always changed the PVID to work with OpenWrt and this works fine for years that way.

QuoteWhatever works for you is fine, but just make sure the TAGGED/UNTAGGED configuration for each Switch Port is correct.
Yeah, port 5 gets all VLANs (tagged) and some goes to the port 4/openwrt (tagged) and the other 3 ports are untagged.

Just by writing the last sentence I realised I never checked the untagged ports. Which I did now. Port 1 is running on ID 80 which works. Port 2 ID 20 and Port 3 on 50. All ports are working fine and gets the right DHCP/IP range etc. PVID works on that side, that is good.

So that basically means to me, that I probably should set up on opnsense igc1 port with the right IP range (25)? I'm trying to set the switch on VLAN ID 25 same for the openwrt but it always gets 80 and sometimes 60. If I set a static ip for the switch that would work too but as I mentioned there are coming a few more devices with TAGGED ports and I dont wanna play that game.

Just wondering why openwrt doesnt have the issues with PVID and opnsense has it or I can't find the set up for it or whatever.

So if I can't use PVID 25 for Port 4 & 5 to tell OPNsense in which DHCP/IP range it should put those devices how can I change it on opnsense side and not setting up static IPs?
#6
Hi nero355

I'm going to try it out later on today.

I thought I just leave that information here too.

My set up currently is with a OpenWrt router which has also a few VLANs. So the switches are actually all set up and working for openwrt. The plan is to replace the openwrt router with the opnsense router and another openwrt AP device.
So the VLANs from the current openwrt router stays the same and has been already created on the opnsense router with some extra VLANs.

opnsense
On opnsense I deleted LAN entirely because I use Port 3 (igc2) for management of the opnsense device directly. igc0 is WAN and igc3 is currently used as WAN DHCP to the current openwrt router.

Quote- Pick any of the available NICs for a new Interface and just leave it Enabled but without any IP Address configuration.
This is one peace is missing currently. I'm using cg1 only for VLANs. Also when I set up a static IP on the switch to VLAN ID 25 that works but I dont want to add on every single device a static IP.

QuoteTo keep things simple I will asume you know how to take care of the DHCP/NAT/Firewall Rules stuff and skip that part.
I've created them all but I also disable sometimes the firewall just to check it out. Not sure if that helps or makes things even worth though.

switch
Quote- Port #1
I use port 5 for that. I could change that.

Quote- Port #2
No need for that.

Quote- Port #3
This is currently on Port 4 and it seems to work so far, more or less. Similar issues with the switch though.

Like I mentioned above, I'll give it a shot later on.
Thank you for the reply! Really appreciate it.
#7
26.7 Series / Multiple VLANs - sometimes 60, 80, ...
August 01, 2026, 01:48:57 PM
Hi

I'm new with VLANs on OPNsense.

I created a bunch of VLANS and I'm trying to trunk them to an openwrt AP device - mainly VLAN IDs 50, 55, 60 and 80

It's OPNsense -> TP-LINK TL-SG105E -> OpenWrt
OPNsense:
I've 12 VLANs on port 1 (igc1).
All DHCP set and all interfaces up and running.

Switch:
Should receive 20, 25, 50, 55, 60 and 80.
I've configured port 5 as a VLAN trunk.
The PVID on port 5 is 25 but it gets 60.
It also had 80 some reboots.

OpenWrt:
All set up.
When I connect to wifi I currently connect to VLAN 60 even the VLAN device/ID on that wifi is 55.

So the whole AP idea some kind of works, I can see the device on OPNsense but it's just the wrong VLAN ID.

I'm a bit confused. I'm still trying to figure it out how I can set the main IP for igc1 (switch) which should be 25 and of course that the wifi/AP connects to the right VLAN IDs.

Hope someone has a bit time to help me here. Thanks!
#8
Ok AdGuardHome is solved as well so far. It might needs to be changed again once VLANs are created etc. but the solution here was to change the config file of AdGuardHome

/usr/local/AdGuardHome/AdGuardHome.yaml
dns:
  bind_hosts:
    - 192.168.101.1
I had before every interface 0.0.0.0.
#9
Ok internet works ... kind of.

If you are looking for the same issue, here is just the set up if you use straight unbound:

Firewall -> Rules -> Add

 Description = WireGuard internet access
 Interface = HomeWireGuard
 Action = Pass
 Direction = Both
 Version = IPv4
 Protocol = Any
 Source = Single host or Network (10.10.10.0/24)
 Source Port = Any
 Destination = Any
 Destination Port = Any



I'm using AdGuardHome on OPNsense.

AdGuardHome (port 53) -> Upstream DNS servers 192.168.101.1:5353 (Unbound Port changed to 5353)
I have the following issue that for some reason when AdGuard is involved that my VPN clients request and the following reply includes also the wireguard interface IP. As seen in the following through Unbound everything works fine.

Unbound only:
16:32:01.282074 IP 10.10.10.2.59972 > 192.168.101.1.53: 50781+ [1au] A? google.com. (51)
16:32:01.282137 IP 192.168.101.1.53 > 10.10.10.2.59972: 50781 1/0/1 A 142.250.195.110 (55)

with adguardhome:
16:33:36.498148 IP 10.10.10.2.41034 > 192.168.101.1.53: 58975+ [1au] A? google.com. (51)
16:33:37.045166 IP 10.10.10.1.53 > 10.10.10.2.41034: 58975 1/0/1 A 142.250.195.110 (55)


Why is it not passing it directly as well (192.168.101.1.53 > 10.10.10.2).
#10
Hey

I'm currently setting up OPNsense (v26.7) and WireGuard. The installation of OPNsense is brand new on bare metal.
Currently I'm trying to have at least internet access and access to all LANs.

My network skills are very limited so to lock down LAN again and allow specific LANs/VLANs only etc. will follow after that :)

The connection to wireguard in my home network and extern works without any issues.
The client "AllowedIPs" is set to "0.0.0.0/0, ::/0".

I've no NAT rules yet, only the open port on the WAN interface. And here is where I'm struggling. I created first a "Destination NAT" and chose "Register rule" under "Firewall rule" first which worked too but still no access to the internet or LAN.
I read something about "Source NAT" and to enable "Hybrid Source NAT rule generation".

But it instead of mucking around and enabling and open this and that I would like to ask first to have a proper configuration. The docs are currently for the older versions I assume - https://docs.opnsense.org/manual/how-tos/wireguard-client.html so this doesn't help me at the moment as well.

Anyhow, I hope someone has the time to guide me through my configuration.

Thank you!
Dan
#11
Thanks! I'll take a look at it. Maybe it's easier to swap it than I think.
#12
Hey

Just installed a fresh opnsense device where I'm going to use my own certificates via acme.sh (dns option). The certificates are created on another VM and also published for only the home network.
I'm currently gathering some ideas on how best to automate this, especially for opnsense.

I use just a script for simple linux boxes and run them via crontab every day:
curl -o "/etc/nginx/ssl/cert.key" -z "/etc/nginx/ssl/cert.key" "https://homecerts.local/cert.key" && \
curl -o "/etc/nginx/ssl/cert.cer" -z "/etc/nginx/ssl/cert.cer" "https://homecerts.local/cert.cer" && \
systemctl reload nginx.service

I'm not familiar with opnsense under the hood. I can also use crontab, but how could I import the certificates then?

Thanks!
#13
Has anyone found a solution yet? I just tried again with the latest update 22.1.1_3 but it's still the same problem.
#14
Facing the same issue. Did you get it sorted?