• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

network guru - need help determining routing/access problem

amrogers3

Gawd
2FA
Joined
Nov 7, 2010
Messages
664
I have 3 VLANs 101, 102, 103. I have a device on 101 and cannot access it from either 102 or 103.

However, if I move the device to 102 or 103 I can access it.

My interface rules are wide open. I reset the state table and also reset to default config and then set up VLANs and firewall rules. Any ideas what could be causing this behavior?

Picture24-1.png

Picture22-1.png

Picture23-1.png


Please help! Been troubleshooting for days and can't figure this out.
 
What is doing the routing betwixt the vlans?

Perhaps VLAN 101 is the management vlan (thus on all the ports?)
 
What is doing the routing betwixt the vlans?

Perhaps VLAN 101 is the management vlan (thus on all the ports?)

Ahh, I wish it was that! VLAN104 is the manangement VLAN. I am using a 3Com Switch 3CDSG8.

I can move the device to 102 and the laptop to 101 and it works. I am baffled as to what is the problem with accessing the device on 101.

Cannot ping, can not connect to device when is is connected on VLAN101. If I move it to VLAN102 and move the laptop to VLAN101 I can ping and connect to laptop all day long.
 
Last edited:
Is there by chance some default VLAN settings that are being applied in 101 that are not applied in 102/103.

Like QoS based things and / or VOIP traffic on VLAN101 that may be causing issues?

Not familiar enough with that switch to offer more than basic shots in the dark to jar some thoughts along. I know that on Netgears VLAN1 is management by default, but I don't know if that would apply here either.
 
Is there by chance some default VLAN settings that are being applied in 101 that are not applied in 102/103.

Like QoS based things and / or VOIP traffic on VLAN101 that may be causing issues?

Not familiar enough with that switch to offer more than basic shots in the dark to jar some thoughts along. I know that on Netgears VLAN1 is management by default, but I don't know if that would apply here either.

Thanks for reply. I set up VLAN104 as management. No VOIP restrictions on 101 although I can check tomorrow if there is QoS restrictions.

Also, while the device is in VLAN101 I can ping it using the diagnostic utility from the pfSense box via the LAN, VLAN101, VLAN102, and VLAN103 interfaces. I cannot ping the device from a laptop on 102 or 103 though.
 
What is doing the routing betwixt the vlans?

This. You only have L2 switch from what i can see. No router = no connectivity. VLANs are like separate physical lans, so you need router to connect them.
 
pfSense is the router. It is successfully routing between devices on all VLANs. The problem is VLAN101. When I attached the device to VLAN101, I can't access it from the other VLANs.

If I move my laptop to 101 and the device to 102, it works. I am trying to figure out why 101 is the problem. It is not connected to a management port and the rules on all 3 VLANs are configured the same.

What gives?
 
Can you ping your gateways? So device on vlan103 ping vlan101 gw, and vice versa...

Also, make sure your windows firewall is off? maybe it has one of the networks set to 'public' or whatever in the network manager.
 
Can you ping your gateways? So device on vlan103 ping vlan101 gw, and vice versa...

Also, make sure your windows firewall is off? maybe it has one of the networks set to 'public' or whatever in the network manager.

yes sir, can ping all gateway. Have a laptop on 102 and can successfully ping 101. Can't ping the device on 101 though.
 
Cannot ping, can not connect to device when is is connected on VLAN101. If I move it to VLAN102 and move the laptop to VLAN101 I can ping and connect to laptop all day long.

So clearly it's not a problem with the VLAN but the device.

Does the "device" have any unwanted static routes for 192.168.101.1/29 network?

What is this "device" BTW?
 
So clearly it's not a problem with the VLAN but the device.

Does the "device" have any unwanted static routes for 192.168.101.1/29 network?

What is this "device" BTW?

Yeah man, that is what I though. The device is a synology DS211J.

I can move the DS211 from 101 to 102 and move my laptop to 103 and can ping it and access the DS211 with no problem. So pfSense is routing fine and I can ping it on another VLAN with no problem. No static route have been set.

I cant figure out why I can no longer access the DS211 when I move it to VLAN101.
 
So by accessing it I assume you mean CIFS or windows file sharing, which would sound like the pfsense is filtering those packets. But you also can't ping it, but can ping the laptop when it's on 101 which at least tells us the pfsense isn't filtering icmp on that VLAN. I suppose you could try to connect to the c$ share on the laptop while it's on 101, but my guess is you'll be able to see it.

I also assume you've looked at the firewall log on the pfsense to see if it's dropping any packets while you have that device on 101?

Odd problem. I assume the NAS device is running some linux derivative. Can you get a shell on it and type route?
 
Are you certain you are changing the ip address and gateway for the synology to reflect the proper vlan when you move it?
 
I also assume you've looked at the firewall log on the pfsense to see if it's dropping any packets while you have that device on 101?

Odd problem. I assume the NAS device is running some linux derivative. Can you get a shell on it and type route?

I agree, it's very odd. I can SSH into the DS211 and get a shell. I tried pinging the laptop on 102 from DS211 on 101 but I get unreachable. I've looked at the firewall and I don't see any packets related to either source or destination address.

Are you certain you are changing the ip address and gateway for the synology to reflect the proper vlan when you move it?

Yep, I check and recheck every time.
 
How can I make sure the pfsense is routing correctly? I reverted to pfsense 1.2.3 and set up 3 VLANS on interface em0. Now no VLANs seem to be able to communicate with each other. I'm thinking there is configuration step I am missing somewhere.
 
How can I make sure the pfsense is routing correctly? I reverted to pfsense 1.2.3 and set up 3 VLANS on interface em0. Now no VLANs seem to be able to communicate with each other. I'm thinking there is configuration step I am missing somewhere.

So you are running a router on a stick?

The single switch port the router is plugged into is trunked and carries each of the 3 vlans?
 
take a look at the routing tableon the NAS, anything funny? I think you mentioned that you verified the gateway address is correct on the NAs on vlan 101. Is there a setting on the NAs to disable ICMP echo response? can you telnet/ssh to the device while on the same subnet? on a different subnet?
 
Thanks for the replies. I appreciate the help trying to figure this out.

So you are running a router on a stick?
The single switch port the router is plugged into is trunked and carries each of the 3 vlans?

Yes I am running a router on a stick. The switch is set up as follows (note: at the time I took screenshot I only had pfsense and my laptop plugged into switch):
pfSense plugged into port 8 on switch.

take a look at the routing tableon the NAS, anything funny? I think you mentioned that you verified the gateway address is correct on the NAs on vlan 101. Is there a setting on the NAs to disable ICMP echo response? can you telnet/ssh to the device while on the same subnet? on a different subnet?

I haven't looked at routing table on NAS, however I have not set up any static routes on it. From my tests, the NAS does not block ICMP. I can ping it if I am on the same VLAN as the NAS. Also, if I am on same subnet I can SSH to NAS. If I change laptop to different VLAN, can no longer ping or access.
 
Last edited:
To rule out if it is a 2.0 issue, I installed 1.2.3. Now, for some reason none of the VLANs can communicate with each other. Is there a config option I am missing on older version of pfsense to enable inter VLAN communication?

I have the rules on the VLANs wide open.
 
I'd loose the etherchannel/lacp and just stick with 802.1q tags until I got it working. Also I think lacp was added pfsense 2.0 though I could be wrong as don't/would never use it.
 
Looks like I finally found the issue. The problem lies with a virtual interface utilized by VMware Fusion.

Picture41.png


The virtual interface was using the IP address 192.168.101.1 which was the same IP address of the VLAN101 interface. Once I disabled the interface with "ifconfig vmnet1 down" I was able to ping to and from VLAN101. All seems to be "working" at the moment. Crazy how you can overlook the obvious sometimes.
 
Back
Top