Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Moving pfsense->OPNSense with Unifi VLANs
« previous
next »
Print
Pages: [
1
]
Author
Topic: Moving pfsense->OPNSense with Unifi VLANs (Read 6388 times)
BigSnicker
Newbie
Posts: 9
Karma: 2
Moving pfsense->OPNSense with Unifi VLANs
«
on:
January 07, 2020, 09:47:47 pm »
This may be a stupid question, but for the life of me I can't figure out how to solve this in the OPNSense world.
So I had a pfsense router that used 802.11 tagged VLANs to route traffic across different SSIDs.
I've migrated this to OPNSense and have it *almost* entirely working, except that
I can't seem to get the VLAN tagged traffic routed.
I have rules defined that should all all traffic to be routed everywhere, and it's working fine for untagged traffic coming from the Unifi AP.
So, for example,
Working
WAN <-> OPNSense <-> Uniifi AP (but untagged traffic)
Not working
WAN <-> OPNSense <-> Unifii AP SSID indicated with tagged VLAN
Strangely, all of the devices on VLANs are able to get correct IP addresses allocated from the VLAN subnet address range from the OPNSense DHCP server, but they even can't ping their own subnet gateway, much less get routed to the internet.
I think pfsense got around this by having a section where you had to tag traffic as "0,2t", but I don't know how to do this in OPNSense.
Any suggestions appreciated.
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #1 on:
January 07, 2020, 10:04:26 pm »
Using VLANs here with no problems at all. I'm using EA225 TP link WAPs but the principle is the same, the WAP tags each SSID with the VLAN ID and onto the trunk.
I suspect it might be an issue with the firewall rules as dhcp is working. Here are my orimary VLAN rules, this VLAN is allowed to talk to the other VLANs, however they cannot talk to it but they can connect to the internet. I've expanded the auto rules so you can see them too.
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
BigSnicker
Newbie
Posts: 9
Karma: 2
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #2 on:
January 07, 2020, 10:40:22 pm »
Yes, it seems like the failure should be at the Firewall rules level, but I think I've ruled that out.
As I'm doing my first ever OPNSense set-up and am just trying to get connectivity established, my Firewall rules are wide open for everyone except WAN.
Using your network example, it would be:
QPVLAN IPv4 * *
QPVLAN IPv6 * *
Basically, it's 'any to any' for all protocols.
So is there anything about VLAN tagging that prevents it from reaching layer 3 rules??
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #3 on:
January 07, 2020, 11:29:51 pm »
Not that I'm aware, as I said my system is working fine.
Rather odd that you cannot ping the gateway of the VLAN if you are sat on it.
Ignoring the wifi, if you connect a PC to the VLAN can that connect and if so what's coming up in ipconfig?
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
BigSnicker
Newbie
Posts: 9
Karma: 2
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #4 on:
January 08, 2020, 08:02:01 am »
Well, it was suddenly fixed after I did a lot of fiddling... if I figure out what did it, I'll report back, but I basically did the following:
1. Disabled hardware handing of VPNs
2. Opened up firewall rules to change everything from NETWORKNAME net *, to , * *
3. Replaced automatic NAT with hybrid NAT and adding manual NAT rules for all subnets to WAN
I'll eventually undo most of those and see if it breaks again.
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #5 on:
January 08, 2020, 09:11:46 am »
OK, well welcome to Opnsense. Lots of us here have come from the the darkside.
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #6 on:
January 08, 2020, 10:03:35 am »
i have also a opnsense, with 2 switches and 2 ap's from ubiquity. I installed my own controller. Everything works fine, even with the vlan's.
I left nat as-is (not hybrid), but copied the default rules from lan-interface to the vlans. Most important rule at the end of each vlan (depends on how paranoid you are) for me was the outgoing rule on each interface, from vlan-network to any (Blocked rules apply before).
Important is, that networks in opnsense are configured in the unifi-controller the same way.
Logged
BigSnicker
Newbie
Posts: 9
Karma: 2
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #7 on:
January 09, 2020, 06:44:43 pm »
I think I discovered the problem.
I had "enable Static ARP" on, which I interpreted as "Sure, I'd like to also use Static ARP in the future".
But it seems that that means
only
static ARP, and so none of my traffic was going anywhere.
Everything going MUCH more smoothly now, and in fact I found the overall configuration process was more intuitive than pfsense.
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: Moving pfsense->OPNSense with Unifi VLANs
«
Reply #8 on:
January 10, 2020, 12:50:44 pm »
It is a friendlier option full stop. Jumped ship must be three years ago now and never regretted it. Opnsense has come a long way in those three years.
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Moving pfsense->OPNSense with Unifi VLANs