Wednesday, September 29, 2021

Flat to Vlan question Pfsense and SG500x

Hey all,

I am trying to move away from a flat network to vlans but ran into some issues the first time I tried this.

Current network is one flat 192.168.x.x address space. There is a LAN interface connected to my L3 switch. I added new vlans on the switch, created a new_LAN interface on pfsense and assigned a vlaned interface from the switch to the pfsense router. New vlans are 10.10.x.x/24 with a /30 address for that vlan interface to the new_LAN interface on the pfsense. Thanks to a fellow Redditor for pointing out my switch could not do a routed interface

I am able to talk between the new vlans but no Internet access. Also how do the old and new networks to talk? I assumed I needed to add some rules at the firewall level which I did. But all of the traffic is going out the default route on the switch which is the old 192.168.x.x network which is a problem for the new vlans.

I’ve looked this up a bit and there was a thread about creating policies on the switch that specify which route a vlan should take. Is that my only option at this point?



No comments:

Post a Comment