Jump to content

PfSense VLAN for Guest Network

jacob_samd

In reference this video, 

https://www.youtube.com/watch?v=DL4vMLgBrYI&t=722s

 

Has anyone had success making this work. I can get my devices to connect for a short period from time to time but most of the time it will not dish out an ip address. Any suggestions? I run PfSense on a box and then have everything through unmanaged switches to my devices and unifi Access Points I have tried using a managed switch with vlan capabilities but I want to be able to broadcast a home and guest network off the same access points to cover my entire house without having seperate AP's for guest network. 

Thanks,

Link to comment
Share on other sites

Link to post
Share on other sites

Do those Unify APs support multiple SSIDs at once?

 

Also, you set up a separate VLAN with its own IP range in pfsense?

 

and on the APs, you have that separate SSID VLAN tagged to match the separate VLAN in pfsense?

HEDT: i9 10980XE @ 4.9 gHz, 64GB @ 3600mHz CL14 G.Skill Trident-Z DDR4, 2x Nvidia Titan RTX NVLink SLI, Corsair AX1600i, Samsung 960 Pro 2TB OS/apps, Samsung 850 EVO 4TB media, LG 38GL950G-B monitor, Drop CTRL keyboard, Decus Respec mouse

Laptop: Razer Blade Pro 2019 9750H model, 32GB @ 3200mHz CL18 G.Skill Ripjaws DDR4, 2x Samsung 960 Pro 1TB RAID0, repasted with Thermal Grizzly Kryonaut
Gaming Rig: i9 9900ks @ 5.2ghz, 32GB @ 4000mHz CL17 G.Skill Trident-Z DDR4, EVGA RTX 2080 Ti Kingpin, Corsair HX1200, Samsung 970 EVO Plus 2TB, Asus PG348Q monitor, Corsair K70 LUX RGB keyboard, Corsair Ironclaw mouse
HTPC: i7 7700 (delidded + LM), 16GB @ 2666mHz CL15 Corsair Vengeance LPX DDR4, MSI Geforce GTX 1070 Gaming X, Corsair SFX 600, Samsung 850 Pro 512gb, Samsung Q55R TV, Filco Majestouch Convertible 2 TKL keyboard, Logitech G403 wireless mouse

Link to comment
Share on other sites

Link to post
Share on other sites

I think so, yes, and yes. I’ll have to check that out. I believe I have the same as the ones in the video.

 

***Edit

I have the same as the ones in the video...

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, jacob_samd said:

I think so, yes, and yes. I’ll have to check that out. I believe I have the same as the ones in the video.

 

***Edit

I have the same as the ones in the video...

if I'm understanding the video correctly, it sounds like as long as you have the guest interface configured correctly in pfSense and the guest wifi assigned to the appropriate VLAN on the unify AP it should work.

 

I've just been getting my own pfsense + separate guest wifi set up over the weekend but I went with a managed switch and separate cheap wireless N wifi router/ap for the guest just for more granular control and ease of configuration. Trying to compare oranges to apples here, with my setup, on the managed switch I have all the ports except the one for the guest wifi as untagged for VLAN 1 and that port is not part of the group, then for VLAN 2 I have that port untagged and the port going to pfsense tagged. 

On pfsense the interface for VLAN 2 (guest wifi), firewall rules are basically the same as LAN except that I explicitly block anything from LAN 2 interface to LAN so that the guest network can't talk to my main network. The reverse is allowed though so that I can easily manage that guest wifi AP from my main network if need be.

 

Taking that into consideration with what you're doing - since the AP  you have can assign VLAN IDs, I would expect that given a functional interface config on fpsense and the VLAN assigned for your guest wifi AP on the AP itself, it should all work. Have you tried rebooting pfsense? I had to do that last night to get the DHCP assignment working correctly for VLAN 2.

HEDT: i9 10980XE @ 4.9 gHz, 64GB @ 3600mHz CL14 G.Skill Trident-Z DDR4, 2x Nvidia Titan RTX NVLink SLI, Corsair AX1600i, Samsung 960 Pro 2TB OS/apps, Samsung 850 EVO 4TB media, LG 38GL950G-B monitor, Drop CTRL keyboard, Decus Respec mouse

Laptop: Razer Blade Pro 2019 9750H model, 32GB @ 3200mHz CL18 G.Skill Ripjaws DDR4, 2x Samsung 960 Pro 1TB RAID0, repasted with Thermal Grizzly Kryonaut
Gaming Rig: i9 9900ks @ 5.2ghz, 32GB @ 4000mHz CL17 G.Skill Trident-Z DDR4, EVGA RTX 2080 Ti Kingpin, Corsair HX1200, Samsung 970 EVO Plus 2TB, Asus PG348Q monitor, Corsair K70 LUX RGB keyboard, Corsair Ironclaw mouse
HTPC: i7 7700 (delidded + LM), 16GB @ 2666mHz CL15 Corsair Vengeance LPX DDR4, MSI Geforce GTX 1070 Gaming X, Corsair SFX 600, Samsung 850 Pro 512gb, Samsung Q55R TV, Filco Majestouch Convertible 2 TKL keyboard, Logitech G403 wireless mouse

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Kalm_Traveler1 said:

if I'm understanding the video correctly, it sounds like as long as you have the guest interface configured correctly in pfSense and the guest wifi assigned to the appropriate VLAN on the unify AP it should work.

 

I've just been getting my own pfsense + separate guest wifi set up over the weekend but I went with a managed switch and separate cheap wireless N wifi router/ap for the guest just for more granular control and ease of configuration. Trying to compare oranges to apples here, with my setup, on the managed switch I have all the ports except the one for the guest wifi as untagged for VLAN 1 and that port is not part of the group, then for VLAN 2 I have that port untagged and the port going to pfsense tagged. 

On pfsense the interface for VLAN 2 (guest wifi), firewall rules are basically the same as LAN except that I explicitly block anything from LAN 2 interface to LAN so that the guest network can't talk to my main network. The reverse is allowed though so that I can easily manage that guest wifi AP from my main network if need be.

 

Taking that into consideration with what you're doing - since the AP  you have can assign VLAN IDs, I would expect that given a functional interface config on fpsense and the VLAN assigned for your guest wifi AP on the AP itself, it should all work. Have you tried rebooting pfsense? I had to do that last night to get the DHCP assignment working correctly for VLAN 2.

The thing I do not understand is how he got it to work. I have a seperate VLAN in PfSense for the wireless network and from time to time it will work. But randomly it will stop and just not work at all. It is showing the network wirelessly and it accepts users but will not give out an ip address. It is just weird. I may have to go the route of getting a cheap ap for guest network only...

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, jacob_samd said:

The thing I do not understand is how he got it to work. I have a seperate VLAN in PfSense for the wireless network and from time to time it will work. But randomly it will stop and just not work at all. It is showing the network wirelessly and it accepts users but will not give out an ip address. It is just weird. I may have to go the route of getting a cheap ap for guest network only...

That's sort of why I ended up saying screw it and getting a managed switch + cheap N wifi router for my setup. 

 

I'm not very confident in my networking skills even after getting a CompTIA certification last year, but had no real trouble setting mine up this way. The only thing that I messed up was the VLAN config for ports on that managed switch... took me a few hours to figure out that if I want to be able to hit the guest wifi AP from my main VLAN I needed to set the 'shared' port as untagged on VLAN 1, and tagged on VLAN 2.

HEDT: i9 10980XE @ 4.9 gHz, 64GB @ 3600mHz CL14 G.Skill Trident-Z DDR4, 2x Nvidia Titan RTX NVLink SLI, Corsair AX1600i, Samsung 960 Pro 2TB OS/apps, Samsung 850 EVO 4TB media, LG 38GL950G-B monitor, Drop CTRL keyboard, Decus Respec mouse

Laptop: Razer Blade Pro 2019 9750H model, 32GB @ 3200mHz CL18 G.Skill Ripjaws DDR4, 2x Samsung 960 Pro 1TB RAID0, repasted with Thermal Grizzly Kryonaut
Gaming Rig: i9 9900ks @ 5.2ghz, 32GB @ 4000mHz CL17 G.Skill Trident-Z DDR4, EVGA RTX 2080 Ti Kingpin, Corsair HX1200, Samsung 970 EVO Plus 2TB, Asus PG348Q monitor, Corsair K70 LUX RGB keyboard, Corsair Ironclaw mouse
HTPC: i7 7700 (delidded + LM), 16GB @ 2666mHz CL15 Corsair Vengeance LPX DDR4, MSI Geforce GTX 1070 Gaming X, Corsair SFX 600, Samsung 850 Pro 512gb, Samsung Q55R TV, Filco Majestouch Convertible 2 TKL keyboard, Logitech G403 wireless mouse

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/16/2019 at 7:45 PM, Kalm_Traveler1 said:

That's sort of why I ended up saying screw it and getting a managed switch + cheap N wifi router for my setup. 

 

I'm not very confident in my networking skills even after getting a CompTIA certification last year, but had no real trouble setting mine up this way. The only thing that I messed up was the VLAN config for ports on that managed switch... took me a few hours to figure out that if I want to be able to hit the guest wifi AP from my main VLAN I needed to set the 'shared' port as untagged on VLAN 1, and tagged on VLAN 2.

So, I think I got it figured out. My PfSense box is in the basement. The network goes out to an 8 port switch..it was unmanaged. I thought about trying to connect the AP directly to me ethernet out port and when I did that my guest network started working. So i put a managed switch downstairs and was messing around with ports on it and realized my guest network was working and the managed switch had no settings touched on it. With a managed switch there and no settings my access points are working flawlessly in all areas so far...mind you I only got this to work about an hour ago. I will probably make a video on it and explain it better but for now I think this is going to work. My guess is the unmanaged switches just had no idea about my Vlans even though the managed switch did not have to be told about my PfSense Vlan.

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, jacob_samd said:

So, I think I got it figured out. My PfSense box is in the basement. The network goes out to an 8 port switch..it was unmanaged. I thought about trying to connect the AP directly to me ethernet out port and when I did that my guest network started working. So i put a managed switch downstairs and was messing around with ports on it and realized my guest network was working and the managed switch had no settings touched on it. With a managed switch there and no settings my access points are working flawlessly in all areas so far...mind you I only got this to work about an hour ago. I will probably make a video on it and explain it better but for now I think this is going to work. My guess is the unmanaged switches just had no idea about my Vlans even though the managed switch did not have to be told about my PfSense Vlan.

sounds reasonable. I don't think any unmanaged (dumb) switch can read VLAN tags so they essentially don't exist on those switches

HEDT: i9 10980XE @ 4.9 gHz, 64GB @ 3600mHz CL14 G.Skill Trident-Z DDR4, 2x Nvidia Titan RTX NVLink SLI, Corsair AX1600i, Samsung 960 Pro 2TB OS/apps, Samsung 850 EVO 4TB media, LG 38GL950G-B monitor, Drop CTRL keyboard, Decus Respec mouse

Laptop: Razer Blade Pro 2019 9750H model, 32GB @ 3200mHz CL18 G.Skill Ripjaws DDR4, 2x Samsung 960 Pro 1TB RAID0, repasted with Thermal Grizzly Kryonaut
Gaming Rig: i9 9900ks @ 5.2ghz, 32GB @ 4000mHz CL17 G.Skill Trident-Z DDR4, EVGA RTX 2080 Ti Kingpin, Corsair HX1200, Samsung 970 EVO Plus 2TB, Asus PG348Q monitor, Corsair K70 LUX RGB keyboard, Corsair Ironclaw mouse
HTPC: i7 7700 (delidded + LM), 16GB @ 2666mHz CL15 Corsair Vengeance LPX DDR4, MSI Geforce GTX 1070 Gaming X, Corsair SFX 600, Samsung 850 Pro 512gb, Samsung Q55R TV, Filco Majestouch Convertible 2 TKL keyboard, Logitech G403 wireless mouse

Link to comment
Share on other sites

Link to post
Share on other sites

18 hours ago, Kalm_Traveler1 said:

sounds reasonable. I don't think any unmanaged (dumb) switch can read VLAN tags so they essentially don't exist on those switches

They can't read them but AFAIK they should still pass the traffic without touching the tags.  Probably just got unlucky with a model that doesn't.

Router:  Intel N100 (pfSense) WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz)
WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz) Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~800Mbit down, 115Mbit up)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Alex Atkin UK said:

They can't read them but AFAIK they should still pass the traffic without touching the tags.  Probably just got unlucky with a model that doesn't.

Well to be fair I bought some netgear ones for cheap on black friday a few years back. I think I paid about $5 a piece...lol

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, Alex Atkin UK said:

They can't read them but AFAIK they should still pass the traffic without touching the tags.  Probably just got unlucky with a model that doesn't.

ah maybe I misunderstood - I thought he was saying that the guest network was not separated (working as intended) which I as attributing to the dumb switch since it will send all traffic across itself without any segregation from VLANs.

HEDT: i9 10980XE @ 4.9 gHz, 64GB @ 3600mHz CL14 G.Skill Trident-Z DDR4, 2x Nvidia Titan RTX NVLink SLI, Corsair AX1600i, Samsung 960 Pro 2TB OS/apps, Samsung 850 EVO 4TB media, LG 38GL950G-B monitor, Drop CTRL keyboard, Decus Respec mouse

Laptop: Razer Blade Pro 2019 9750H model, 32GB @ 3200mHz CL18 G.Skill Ripjaws DDR4, 2x Samsung 960 Pro 1TB RAID0, repasted with Thermal Grizzly Kryonaut
Gaming Rig: i9 9900ks @ 5.2ghz, 32GB @ 4000mHz CL17 G.Skill Trident-Z DDR4, EVGA RTX 2080 Ti Kingpin, Corsair HX1200, Samsung 970 EVO Plus 2TB, Asus PG348Q monitor, Corsair K70 LUX RGB keyboard, Corsair Ironclaw mouse
HTPC: i7 7700 (delidded + LM), 16GB @ 2666mHz CL15 Corsair Vengeance LPX DDR4, MSI Geforce GTX 1070 Gaming X, Corsair SFX 600, Samsung 850 Pro 512gb, Samsung Q55R TV, Filco Majestouch Convertible 2 TKL keyboard, Logitech G403 wireless mouse

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×