1
General Discussion / VLAN setup DHCP works, but cannot ping gateway
« on: March 03, 2024, 12:09:15 pm »
Hello, I've recently decided to dabble with VLANs with no prior knowledge of how it works, so this is a learning experience for me. I've set it up similarly to what most tutorials I've found have done (ex. https://www.wundertech.net/how-to-set-up-a-vlan-in-opnsense/) and have created a VLAN with an ID of 30, I haven't changed the setup for the default LAN and those packets are not tagged with any VLAN ID.
My setup is pretty simple for now, and if (or when) I get VLANs to work I'd like to expand it, but right now it's:
OPNSense box -> [ managed switch port 8 (tagged VLAN 30) -> managed switch port 5 (untagged VLAN 30) ] -> Computer
Connecting a computer using this scheme, the computer gets designated an IP from the VLAN range, but whenever I try to ping anything on the network it just times out (this includes the gateway and any other devices I connect to the managed switch). I've checked the rules and have added a rule similar to the default "allow LAN to any rule". Looking at the live view I cannot see any blocked requests with a source or destination ip of the VLAN.
I'm not sure what the next step in debugging the issue would be, would it be possible to send a request out and see where it fails?
My setup is pretty simple for now, and if (or when) I get VLANs to work I'd like to expand it, but right now it's:
OPNSense box -> [ managed switch port 8 (tagged VLAN 30) -> managed switch port 5 (untagged VLAN 30) ] -> Computer
Connecting a computer using this scheme, the computer gets designated an IP from the VLAN range, but whenever I try to ping anything on the network it just times out (this includes the gateway and any other devices I connect to the managed switch). I've checked the rules and have added a rule similar to the default "allow LAN to any rule". Looking at the live view I cannot see any blocked requests with a source or destination ip of the VLAN.
I'm not sure what the next step in debugging the issue would be, would it be possible to send a request out and see where it fails?