Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
Problems setting up VLANs
« previous
next »
Print
Pages: [
1
]
Author
Topic: Problems setting up VLANs (Read 4466 times)
Matt_K
Newbie
Posts: 10
Karma: 0
Problems setting up VLANs
«
on:
July 20, 2022, 11:01:34 pm »
I'm trying to segment my network a bit. I'm trying to have 3 VLANs. VLAN 1, Vlan 100, and VLAN 200.
My Switch is a managed TP-Link. One Port 1, which is where the Firewall is connected. I have configured the port for VLAN 1 untagged, VLAN 100 Tagged, VLAN 200 Tagged. I created 2 other ports 7 & 8 to be untagged on VLAN 100 and 200 for testing.
In the firewall I created the 2 new VLANs. Attaching them to the LAN interface. I assigned each interface and gave them a static IP on a new subnet. I created new firewall rules on each interface. Basically allow all ip4. I also added DHCP for each interface.
I can't ping the ip's and the firewall can't ping my computer. I have nothing in the firewall logs from or to that interface ether. Any idea what I'm missing here?
Logged
hescominsoon
Jr. Member
Posts: 87
Karma: 1
CDTT - Certified Duct Tape Technician
Re: Problems setting up VLANs
«
Reply #1 on:
July 21, 2022, 12:37:03 am »
a picture of your interfaces, interface assignments and firewall rules for each interface would be helpful.
Logged
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #2 on:
July 21, 2022, 12:47:28 am »
I can do that.
Logged
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #3 on:
July 21, 2022, 12:56:33 am »
So I spoke too soon. I don't know how to add pic inline.
So I am attaching them. Sorry.
Logged
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #4 on:
July 21, 2022, 12:57:20 am »
and some more.
Logged
lilsense
Hero Member
Posts: 600
Karma: 19
Re: Problems setting up VLANs
«
Reply #5 on:
July 21, 2022, 01:27:16 am »
untagged vlans are unsupported if you are using tagged valns on the same interface.
Logged
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #6 on:
July 21, 2022, 03:55:56 pm »
Can you expand on that please?
I thought I could have, for example.
The native / default VLAN (which is untagged)
Then a tagged VLAN
If I can't do that. What is the proper way to setup OpnSense to have more than one VLAN on the LAN interface?
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Problems setting up VLANs
«
Reply #7 on:
July 21, 2022, 04:06:10 pm »
It is not entirely unsupported but discouraged because things that rely on promiscuous mode like DHCP tend to stumble over mixed tagged and untagged frames in the FreeBSD network stack. The general recommendation is not to use a native VLAN on FreeBSD.
If your switch on the other end insists on running one VLAN untagged/native, set it to one you don't use. I use 1001 for that in all my infrastructure.
Then simply assign LAN to e.g. VLAN 1 (tagged) ... or any other number, of course.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #8 on:
July 21, 2022, 04:40:33 pm »
I think I understand.
So if I want 3 VLANs make all of them including the base LAN tagged. I will try that.
Logged
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #9 on:
July 21, 2022, 04:47:15 pm »
So the base interface LAN doesn't appear to have a way to attach a VLAN ID. Do I just delete the IP address for this interface and give it to a VLAN interface that is attached to the physical interface LAN?
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Problems setting up VLANs
«
Reply #10 on:
July 21, 2022, 06:13:53 pm »
You go to Interfaces > Assignments and assign "LAN" to "VLAN-1" instead of igb0 - done, LAN is now tagged.
Since OS 22.1 you also need to assign the parent igb0 to a dummy interface and enable that. Architectural reasons, I hope they find a more intuitive solution in the future.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Matt_K
Newbie
Posts: 10
Karma: 0
Re: Problems setting up VLANs
«
Reply #11 on:
July 22, 2022, 04:49:53 pm »
Thank you. I'll give it a shot.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
Problems setting up VLANs