pfSense VLAN Trunk and Firewall Rules Configuration - 夜莺博客

pfSense VLAN Trunk and Firewall Rules Configuration

pfSense on a single trunk link can serve dozens of networks without extra NICs: create 802.1Q VLAN interfaces on the parent physical interface, assign each one, and control traffic between them with firewall rules on the pfSense interfaces rather than ACLs on the switch. The failure modes are just as compact — a VLAN created on the wrong parent, or a switch trunk that does not carry the VLAN, produces an interface that never comes up and gives no obvious clue why. Here is the full sequence with the checks at each step.

1. Create the VLAN Interfaces

Interfaces -> Assignments -> VLANs -> Add
  Parent interface:  igb1            (the trunk port to the switch)
  VLAN tag:          10
  VLAN priority:     0
  Description:       LAN_USERS

Repeat for each VLAN (20 = SERVERS, 30 = IOT, 99 = MGMT)

Interfaces -> Assignments
  Assign each new VLAN as an interface: assign -> rename -> enable

pfSense creates a virtual interface named igb1.10. If the parent interface does not appear in the VLAN parent list, the driver does not support 802.1Q on that NIC — rare on Intel, common on some USB and consumer Realtek adapters.

2. Switch Side: Make It a Real Trunk

configure terminal
interface GigabitEthernet0/1
 switchport mode trunk
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 999
 switchport trunk allowed vlan 10,20,30,99
 no shutdown
end

Do not include the VLAN that pfSense uses for its own management access only if you are sure you have out-of-band access — a mistyped allowed list on the trunk is how people lock themselves out of the firewall. Set the native VLAN to an unused ID and keep it consistent on both ends; a native VLAN mismatch creates a duplicate-broadcast leak between VLAN 1 on the switch and the untagged traffic on pfSense.

3. Assign Addresses and DHCP Per VLAN

Interfaces -> LAN_USERS
  IPv4 Configuration Type: Static IPv4
  IPv4 Address: 10.10.10.1 / 24
  Block private networks: disabled for internal VLANs

Services -> DHCP Server -> LAN_USERS
  Range:      10.10.10.100 - 10.10.10.200
  Gateway:    10.10.10.1
  DNS:        10.10.10.1
  Domain:     corp.example.com

Status -> Interfaces   # each VLAN must show "up" with the expected MAC and media
Diagnostics -> Ping    # source the ping from each VLAN interface

4. Firewall Rules Decide the Policy

Firewall -> Rules -> LAN_USERS
  # allow DNS and DHCP to the firewall itself
  Action: Pass  Protocol: TCP/UDP  Destination port: 53  Destination: LAN_USERS net
  Action: Pass  Protocol: UDP      Destination port: 67  Destination: LAN_USERS net

  # allow only what users need
  Action: Pass  Protocol: TCP      Destination: 10.10.20.0/24  Port: 443
  Action: Pass  Protocol: ANY      Destination: any            Port: any   (internet)

Firewall -> Rules -> SERVERS
  Action: Pass  Protocol: TCP      Source: LAN_USERS net  Destination: 10.10.20.10  Port: 3306
  # everything else is implicitly blocked - no explicit deny needed

Rules are evaluated top-down, first match wins, and pfSense already blocks everything that is not explicitly passed. Inter-VLAN routing happens by default as soon as both networks have gateway addresses, so access control must live in these rule sets — an empty rules tab is an open network.

5. When the VLAN Interface Will Not Come Up

  • No carrier: the switch port is not a trunk, or the specific VLAN is not in the allowed list.
  • Link up, no traffic: interface not enabled in Interfaces → Assignments, or the address is on the wrong subnet.
  • Trunk works for one VLAN only: a native VLAN mismatch, or a second switch in the path pruning the tag.
  • DHCP silent: firewall rule for UDP 67 missing on the VLAN interface, or the DHCP service is not enabled for that interface.
  • Asymmetric behaviour: the client's default gateway points at the switch's SVI instead of the pfSense interface — pick one routing point per VLAN and document it.

Related reading: IPsec VTI versus policy-based VPN with GRE and WireGuard site-to-site VPN configuration.

原文链接:https://pfsense-docs.netlify.app/interfaces/vlan-trunking