OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of chr »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - chr

Pages: [1]
1
21.1 Legacy Series / Guest VLAN and DHCP - another one
« on: May 12, 2021, 02:02:45 am »
I'm simply trying to set up a simple VLAN for a guest PC. Something is not right and would appreciate some guidance.

Opnsense:
1. Create VLAN 30 - GUEST
2. Interface GUEST - vlan 30 on LAN network port (in my case re1). Enabled device with static IP 192.168.30.1/24
3. DHCPv4:[GUEST] with an IP range 192.168.30.100 - 192.168.30.200
4. Created a firewall rule for GUEST:
IPv4 *   GUEST net   *   *   *   *   *   Default allow GUEST to any rule
and there are 3 automatically created rules to allow access to DHCP server

On the switch (Aruba 1930)
1. Create VLAN 30
1. Port 1 on the switch is a trunk to opnsense - VLAN 30 included/tagged
2. Port 15 on the switch is for a guest PC - VLAN 30 included/untagged
3. Interface 15 on the switch is set to Port VLAN ID 30
4. Since routing happens on opnsense I've not enabled routing on the switch and no DHCP relay

On the guest PC I keep getting the self-assigned IP address 169...

I suspect it can be
1. the firewall rule
2. some additional config on the switch (I've seen some posts depending on the type of switch requires a static route for the VLAN)

And yes, I did try to disable IPS (that I only use for WLAN anyway) and sensei is only protecting LAN.

Thoughts? I'm just not sure where to look next. My guess at the moment is that it is related to FW rule (I'm new to opnsense). I figured since it is a VLAN there' just an in-rule.   

BTW - I can ping 192.168.1.30 from a PC that is connected to the switch connected to another port - basically from the LAN to the VLAN 30 interface on opnsense. If I set a static IP on the guest PC I don't get any traffic. I don't see any action for GUEST interface in the live firewall log.









2
General Discussion / Migrating to opnsense
« on: March 04, 2021, 11:52:33 pm »
I'm in the process migrating over to opnsense. My plan is to have 2 separate networks OPT1 for my nvr  and LAN for the main network and DHCP server.  I tried to capture this in a diagram - attached.

Before the cut over I just want to learn a little bit more about opnsense. The actual migration is just to connect the modem, enable the WAN interface on the opnsense FW, make LAN the 192.168.1.1 default GW and then turn the wifi router into an access point.

Everything is up and running with the latest version. Seems to be working fine except I'm not able to reach the NVR on the second network. I thought I would just be able to add a fw rule to allow LAN access to OPT1?  As an example if I'm on the PC 192.168.1.118 I want to access the NVR 192.168.2.3 over ssh or http.

Am I missing something obvious? Do I need to add a route etc? Or is this just not a good scenario and I should just set it up the way it is intended. My understanding was that within the network behind the WAN interface I should just need the fw rules to OPT1 to allow LAN in. And the GW for OPT1 is auto.

I hope this make sense. Appreciate any help or advice.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2