Pfsense VLAN tagging

I have spent way to many hours trouble shooting this issue. Running around with a chicken with its head cut off.

I was consolidating my switches yesterday and I decided I was going to LACP from FW to Core Switch and Core to a POE switch. So the flow goes FW>CORE>POE. I removed a POE switch that did not really need to be in my rack.

This is when the issue started and caused me to go down tons of paths to try and figure out what was the root cause of the network outage. I lost all communication between my all of my network devices. Super long story short after ripping out all switch and replacing them with new, changing the NIC’s in the FW I could not get traffic to pass over any trunks. At this point I abandon the LACP connections and went back to just 10gb between all. Still could not get any connections on my VLAN’s. That is when I decided to abandon router on stick and trunks. This was the only way I could restore service.

Going through the Logs of Pfsense all of my VLAN traffic was being blocked, if it was on a shared interface. I even created wide open rules to test with and still the traffic was being blocked. I created new NAT’s and the traffic was still being blocked.

I guess after this long rant I really just want to know if anyone else has fallen into this issue with Pfsense.

The 10gb NIC’s I’m using are HP NC552SFP and they are approved by pfsense. Odd thing is I had this running for a year no issue until I removed a switch. There were no loops in my network, so I have no clue why my traffic is now being blocked.

I had a similar issue when I decided to use LACP. I forgot to change the Parent Interface under Interfaces > Assignments > VLANs to point to lagg0. After fixing that, traffic started flowing again.

1 Like

I wish that was the issue. But I pointed all VLAN’s to lagg0 and turned them all on. It was still having the issue where any traffic on the link with VLAN’s were being blocked by the firewall. If I move them to a link with only a single subnet it works fine and traffic is not blocked.