I'll continue testing without the external VPN and if anything changes, I'll post here.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: meyergru on August 08, 2026, 09:00:10 AMQuote from: tonys on August 08, 2026, 04:19:52 AMHopefully this settles your debate over combining tagged and untagged traffic, LOL.
See you again when this goes horribly wrong and you do not even remember what you did to make that possible. We never said it was not feasible, but depending on what you do, there can be lots of problems. This may be influenced by your NIC hardware on OpnSense, and is especially true for Unifi switches, which have all kinds of problems with VLANs. If you want a taste of it, look here.
The current switch software releases of some switch models have a problem separating untagged and tagged LANs during switch startup. Depending on the startup order of your machines, they can get IPv4 from any of your VLANs (since all of them are presented untagged). With 802.1x enabled, you may see all IPv6 prefixes at once on untagged ports.
But, as Patrick often says: You do you, LOL. The advice given in here is free - and you are also free to take it or leave it.
Quote from: dseven on August 07, 2026, 09:13:34 AMHave you reboot (opnsense) since eliminating the bridge? There may be some artifact from it lurking somewhere.
Otherwise try this tcpdump to see "what's happening on the wire":tcpdump -nnvvei igc0 '(ether host aa:bb:cc:dd:ee:ff and port 67) or (vlan and ether host aa:bb:cc:dd:ee:ff and port 67)'
Substitute the MAC address of a Guest or IoT device (in two places), and make it (re)connect.
Quote from: dseven on August 06, 2026, 09:50:21 AMAt the start, you had a bridge. Is that bridge now completely gone? Updated ifconfig output might be helpful.
Otherwise I'd tend to suspect that your WiFi is misconfigured...
Quote from: dseven on August 02, 2026, 10:32:17 AMWhat is the purpose of the bridge? What are the member ports?
What are the parent interfaces for the VLAN interfaces?
Mixing bridges and VLAN tagging can be tricky...
Quote from: dseven on August 02, 2026, 10:32:17 AMWhat is the purpose of the bridge? What are the member ports?
What are the parent interfaces for the VLAN interfaces?
Mixing bridges and VLAN tagging can be tricky...
Quote from: Patrick M. Hausen on August 02, 2026, 09:14:19 PMCan you post the output of "ifconfig -a", please? Redact external IP addresses. Private ones are not a security concern, but if you like, change them, too. I am after a full view of VLAN parent devices and bridge memberships.
Kind regards,
Patrick
Quote from: viragomann on August 02, 2026, 09:38:58 AMThe devices might get their IPs from the DHCP on OPNsense. That they get IPs assigned from the wrong subnet indicates, that they are able to communicate with the DHCP on the other subnet.
If you think, your OPNsense configuration is correct, check the subnet separation outside.
How did you do this? Which device is connected to port 1?
Quote from: EricPerl on March 28, 2025, 07:13:30 PMI would remove that "Internet -> WAN (Firewall)" rule on the spot.
It ALLOWS any Internet host that is NOT in your alias to access any port on your public WAN IP!
An allow rule is not blocking anything in any case!!!
An Allow rule with a source (not inverted) only allows hosts matching the criteria.
An allow rule with an inverted (!) source allows all EXCEPT hosts matching the criteria.
More on the rest later.