Discussion:
[pfSense] no internet access on vlan
J. Echter
2014-02-28 06:32:00 UTC
Permalink
Hi,

i have 3 vlan's on my LAN interface.

2 of them working nicely.

With the third i got trouble.

I can access local network devices, but i cannot access internet.

traceroute stops at 192.168.4.1 (vlan3 if address).

default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).

Firewall logs don't show anything.

pfSense 2.1 also was rebooted.

What could be wrong with my setup?

regards

Juergen
Ryan Coleman
2014-02-28 06:33:46 UTC
Permalink
When I set mine up they were pretty straight-forward, I didn’t have to do much inside of pfSense to get it going.

So my thought is this: Is your switch configured correctly for VLAN3?
Post by J. Echter
Hi,
i have 3 vlan's on my LAN interface.
2 of them working nicely.
With the third i got trouble.
I can access local network devices, but i cannot access internet.
traceroute stops at 192.168.4.1 (vlan3 if address).
default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).
Firewall logs don't show anything.
pfSense 2.1 also was rebooted.
What could be wrong with my setup?
regards
Juergen
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
J. Echter
2014-02-28 06:36:05 UTC
Permalink
yep, i think so. all the needed ports have the right tags, also vlan 2
also used on the same ports, just works.

switch operates in layer 2 mode.
Post by Ryan Coleman
When I set mine up they were pretty straight-forward, I didn’t have to do much inside of pfSense to get it going.
So my thought is this: Is your switch configured correctly for VLAN3?
Post by J. Echter
Hi,
i have 3 vlan's on my LAN interface.
2 of them working nicely.
With the third i got trouble.
I can access local network devices, but i cannot access internet.
traceroute stops at 192.168.4.1 (vlan3 if address).
default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).
Firewall logs don't show anything.
pfSense 2.1 also was rebooted.
What could be wrong with my setup?
regards
Juergen
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
Ryan Coleman
2014-02-28 06:38:09 UTC
Permalink
I’ll have to see if I can get into my remote site tomorrow that I have set up with three VLANs (a bar with three SSIDs).

If I have anything - and you don’t find a solution before then (could be Saturday when I’ll be on site) - I’ll get back to you.
Post by J. Echter
yep, i think so. all the needed ports have the right tags, also vlan 2
also used on the same ports, just works.
switch operates in layer 2 mode.
Post by Ryan Coleman
When I set mine up they were pretty straight-forward, I didn’t have to do much inside of pfSense to get it going.
So my thought is this: Is your switch configured correctly for VLAN3?
Post by J. Echter
Hi,
i have 3 vlan's on my LAN interface.
2 of them working nicely.
With the third i got trouble.
I can access local network devices, but i cannot access internet.
traceroute stops at 192.168.4.1 (vlan3 if address).
default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).
Firewall logs don't show anything.
pfSense 2.1 also was rebooted.
What could be wrong with my setup?
regards
Juergen
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
J. Echter
2014-02-28 06:37:03 UTC
Permalink
btw, dhcp runs on pfsense and all the devices are in the right ip range
for vlan3
Post by Ryan Coleman
When I set mine up they were pretty straight-forward, I didn’t have to do much inside of pfSense to get it going.
So my thought is this: Is your switch configured correctly for VLAN3?
Post by J. Echter
Hi,
i have 3 vlan's on my LAN interface.
2 of them working nicely.
With the third i got trouble.
I can access local network devices, but i cannot access internet.
traceroute stops at 192.168.4.1 (vlan3 if address).
default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).
Firewall logs don't show anything.
pfSense 2.1 also was rebooted.
What could be wrong with my setup?
regards
Juergen
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
J. Echter
2014-02-28 09:09:23 UTC
Permalink
unbelievable, but i've overseen the following:

php: rc.initial.setlanip: The command '/sbin/ifconfig 'lagg0_vlan3' inet
delete' returned exit code '1', the output was 'ifconfig: ioctl
(SIOCDIFADDR): Can't assign requested address'
Post by J. Echter
Hi,
i have 3 vlan's on my LAN interface.
2 of them working nicely.
With the third i got trouble.
I can access local network devices, but i cannot access internet.
traceroute stops at 192.168.4.1 (vlan3 if address).
default allow everything to any rule is added, dns forwarder listens on
that ip (dns resolution works).
Firewall logs don't show anything.
pfSense 2.1 also was rebooted.
What could be wrong with my setup?
regards
Juergen
_______________________________________________
List mailing list
http://lists.pfsense.org/mailman/listinfo/list
--
Mit freundlichen Grüssen

Jürgen Echter
Logo

ECHTER Küchen & Elektro GmbH
Augsburger Str. 49

*86529* Schrobenhausen

*Tel:* 08252 / 8976 - 0
*Fax:* 08252 / 8976 - 10
*e-mail:* ***@echter-kuechen-elektro.de
<mailto:***@echter-kuechen-elektro.de>
*web:* www.echter-kuechen-elektro.de <http://www.echter-kuechen-elektro.de>
*Reg.-Gericht: *Ingolstadt Nr. HR B 101907

*Ust.-Id. Nr.:* DE234419866
*
Steuernummer:* 124/125/51166
*
Geschäftsführer:* Thomas Echter
Continue reading on narkive:
Loading...