Setup VLAN on pfSense virtualized in Proxmox

Поділитися
Вставка
  • Опубліковано 30 вер 2024

КОМЕНТАРІ • 87

  • @DodoDodo-eo2su
    @DodoDodo-eo2su 11 місяців тому +29

    Jesus, I wish every tutorial was so straight on point. No intro, no "hit the subscribe button", no bullshit. Wonderful

    • @Divgitally
      @Divgitally  11 місяців тому

      Thank you for the message! I really appreciate it! I make the guides I want for myself. Also I forget things and have to look at them myself from time to time to remember.

  • @vojtechstoklasa3417
    @vojtechstoklasa3417 8 місяців тому +7

    Finally a video about proxmox vlans which doesn't take 10 years and is straight to point, you helped me to solve issue i had for last 2 days

    • @Divgitally
      @Divgitally  8 місяців тому

      Haha, I'm happy my video was useful, and thank you for the message! There are times for longer, more detailed videos. Then there are other times you just need some quick answer's!

  • @kuacikecil9019
    @kuacikecil9019 5 місяців тому +1

    How to configure vlan on mikrotik virtualized proxmox sir?

    • @Divgitally
      @Divgitally  5 місяців тому

      Hello! The Proxmox side should be similar, but i have not used the Mikrotik router enough to say anything about how to do that, but if you join the Discord server i have in the video description and share some images from the UI I could try to help you!

  • @ricardosalafte
    @ricardosalafte 5 місяців тому +1

    thank you great video , could you please help me , i cant get ping betwen the vlans....

    • @Divgitally
      @Divgitally  5 місяців тому

      Hello! I'm glad it somewhat helped! If you have Discord, you can hop on the server i have and share a screenshot of the rules you have set up so i can more easily see whats up! The invite is in the video description.

  • @sigitkusuma
    @sigitkusuma 7 місяців тому +1

    is it possible to implement only using 1 ether interface on proxmox ?

    • @Divgitally
      @Divgitally  7 місяців тому

      Yes, that is absolutely possible. It can just be a bit more messy. You will still need another router as a gateway.
      Do you have anything special in mind?

  • @JspectraX
    @JspectraX Місяць тому +1

    Would you do the same for OPNsense?

    • @Divgitally
      @Divgitally  Місяць тому

      I have thought about it. I plan on changing from a "physical pfSense router" to a virtual OPNsense router for my lab network. I will be setting up a test network before going ahead with that which I plan on making a guide on. I sadly don't have a time-frame though.

  • @GT-sc5sk
    @GT-sc5sk 21 день тому

    that work well on just one node, what is about HA..migration to another proxomox node maybe will work but you will loose connectivity..that guess can not can be fixed

  • @ronald0122
    @ronald0122 23 дні тому

    can't i juse use vlan aware on the default bridge on the lan port. my goal is to use multiple vlans on my physical switch that is connected to my proxmox host with pfsense installed. my proxmox host has 2 nics (1 for lan + vlans and 1 for wan).

  • @ImTheKaiser
    @ImTheKaiser 10 місяців тому +2

    I just handle the vlans on proxmox so pfsense sees them as actual interfaces.
    This makes it more portable and easier to replicate if hardware changes.
    This also gives me more security if there is other tagged traffic on the trunk, as proxmox won’t even show/pass it to the VM
    Downside is it may require restarting the vm if you are trying to add a new vlan(nic)and unable to hot plug the new interface

    • @Divgitally
      @Divgitally  10 місяців тому

      Cool. Thank you for the tip. It's always nice to have multiple ways of doing things like VLAN'S!

  • @drreality1
    @drreality1 Рік тому +3

    Thanks, why would be the benefit from ovs bridge vs normal bridg?
    Cheers

    • @Divgitally
      @Divgitally  Рік тому +1

      I think it can become a bit messy depending on how you do it with normal bridges. But I cant say that one is better than the other, this is just the way i like to do it.

  • @ethereal5097
    @ethereal5097 Місяць тому +2

    Now, that's how you do a how-to video.
    Thanks!

    • @Divgitally
      @Divgitally  Місяць тому

      I'm glad you like the video! Thank you for the kind words!

  • @bobbybologna3029
    @bobbybologna3029 7 місяців тому +2

    Now THAT is a Tutorial! I know what VLANs are, I know how to set them up on a physical switch, however virtualizing is a different beast and you got RIGHT TO THE POINT! You rock!

    • @Divgitally
      @Divgitally  7 місяців тому

      Thanks! I really appreciate your feedback! The points you hit on is what i try to accomplish and I'm happy that I managed to do that! Thank you for the message!

  • @John-vk1ij
    @John-vk1ij Рік тому +1

    Quick question. Is it possible to not modify the Proxmox VE network settings? I'd like to only create a VLAN20 in pfSense on the existing LAN interface, and leave PVE agnostic of any VLAN going on that interface.

    • @Divgitally
      @Divgitally  Рік тому +1

      Hello. Thank you for the question. If you just want the one VLAN on the interface, it should be fine as long as you enable VLAN on it. It's with multiple VLAN's on the same interface you will run into issues.

  • @louisemothe9204
    @louisemothe9204 Рік тому +2

    Thank you very much for your video which helped me to create secure virtual machines in my network to detect and report Internet scammers. It made my job much easier and I am very grateful.

    • @Divgitally
      @Divgitally  Рік тому +1

      Really happy to hear that the video was useful to you! and good luck in hunting down and reporting scammers!
      It would be really interesting knowing more about how you go about doing that!

  • @jenniferw8963
    @jenniferw8963 Рік тому +1

    Thanks for the video. Just wondering why you went iwth OVS Bridge/IntPort for VLAN support? I see Linux Bridge and Linux VLAN above that. What's the difference between the two?

    • @Divgitally
      @Divgitally  Рік тому

      Hello! Thank you for the message!
      Using OVS was the first way I got it working. You can use Linux VLAN's, but I found that I more easily lost overview. Other than my preference, there should not be any major difference.

  • @jaY-fq7qs
    @jaY-fq7qs 4 місяці тому +1

    Hi , dumb Q. do i need vlan switch here using OVS?

    • @Divgitally
      @Divgitally  4 місяці тому

      Hello there. Not stupid at all! It really depends on what you want to do. If you just want to have multiple VLAN's on Proxmox and share one VLAN out, you do not need anything other than a unmanaged switch. You just need it if you wish to have multiple VLAN's out from Proxmox.

    • @jaY-fq7qs
      @jaY-fq7qs 4 місяці тому +1

      @@Divgitally thnks for your reply. yeah i have proxmox on my intel nuc which has single LAN. and i also have manged switch capable of vlan. if im going to add multiple vm with vlans, i want to try this OVS. would it work? i think this one would be the solution for having a single NIC. Can you please help me out. 😃
      in proxmox single NIC, im running pfsense, i just dont kniw how to integrate coin wifi hotspot on vlan22. and sometimes i just want try out another firewall and vms like opnsense, openwrt, and so on. Thank you!

    • @Divgitally
      @Divgitally  4 місяці тому

      It is absolutely possible to do with one nic, but you will need to set up one VLAN on your switch for WAN and one or more for your LAN side. Then, all VLANS need to be trunked to the port where your Proxmox and pfSense router is connected.
      All VLAN's need to be on the same physical interface you have on Proxmox.
      There are some others I have spoken with on the Discord server I set up that has done the same as you want to do. There is a link to it in the video description if you wish to hop on there. It is just a bit easier to follow up there.
      There are plenty of good routers and firewall's to virtualize and play with! OPNsense is similar to pfSense. OpenWRT is more of a router compared to the two others.

    • @jaY-fq7qs
      @jaY-fq7qs 4 місяці тому

      @@Divgitally Thank you bro! appreciate it ! 🍻

  • @faizansirajuddin
    @faizansirajuddin 6 місяців тому +1

    I installed mikrotik in proxmox and And want to utilizee 1-512 VLANs on a single port. So do I need to create these interfaces one by one 512 times? Or is there any shorter command?

    • @Divgitally
      @Divgitally  6 місяців тому +1

      Hello! There might be a way to do it more quickly, but I don't know it. I can try to take a look later.
      Can I ask you why you need that many VLAN's? I have never seen that many VLAN's in use at one time in a setup.

    • @faizansirajuddin
      @faizansirajuddin 6 місяців тому +1

      @@Divgitally I'm admin at internet provider, so we are segregating our zones by vlan. So we required even more than 512 as our network spans over entire country.

    • @Divgitally
      @Divgitally  6 місяців тому +1

      @@faizansirajuddin​ Cool! That makes sense!
      from what i can see, the command below is used to generate a vlan. An option is to generate all the commands using something like excel for example, then copying them (first to notepad because Excel can be annoying) into the CLI. You might get away with pushing 20 or more commands at a time, but i cant promise that.
      /interface vlan add vlan-id=50 interface=ether2 name=ether2-vlan50
      I don't have any better tips for doing that at the moment best of luck to you and I'm here or Discord if you need me!

    • @faizansirajuddin
      @faizansirajuddin 6 місяців тому +1

      @Divgitally Regards! Another issue I encountered when virtualizing Mikrotik on Proxmox is that it behaves strangely with PPPOE users-users connect occasionally and disconnect others. especially when using vlans to host numerous PPPOE servers. I set up a dhcp server on the same VLAN to confirm that it was operational. However, when switching to PPPoE on the same VLAN, requests occasionally get through and occasionally don't. Using CCR resolved this issue for me.

    • @Divgitally
      @Divgitally  6 місяців тому

      @@faizansirajuddinThank you for sharing! I have personally just used it in a minor setup, but it would really be interesting to learn more about your setup! Can i ask about the spec's on your machine?

  • @KareemAly-e9o
    @KareemAly-e9o 21 день тому

    Thanks for sharing.

  • @keketohmx
    @keketohmx Рік тому +3

    Thank you so much for the info🙏🏻🎉
    In the last step you say it’s possible to take the name of a physical interface that is already in use on a bridge (LAN) and to add the name of the physical interface into the OVS bridge ports.
    When I do this, I lose my pfsense web interface and I can only access pfsense via the console in proxmox. Is there something I might be missing that is causing this? Or is this expected?

    • @Divgitally
      @Divgitally  Рік тому +3

      If you are taking the interface you need for connecting to Proxmox, you will have to add an IP address to the VLAN you wish to connect to Proxmox via.
      I should have done a better job of explaining that, apologies for that!

    • @franzpleurmann2585
      @franzpleurmann2585 Рік тому

      @@Divgitally Can you explain step by step how to do that? Where do I have to add the IP address - in the proxmox network tab (OVS Bridge or OVS IntPort) or in the Pfsense Interfaces Tab (IPv4 Configuration Type)?

    • @Divgitally
      @Divgitally  Рік тому

      @@franzpleurmann2585 Hello! You add it to the OVS intPort on Proxmox. If you look at 4:09 in the video.
      1. Select the vlan you wish to access Proxmox through and edit it.
      2. Add an IP address and network mask in bits from the range you have on that VLAN in the field next to "IPv4/CIDR". An example is 192.168.200.40/24
      3. If you plan on Proxmox reaching out to the internet via this VLAN you will have to empty the Gateway (IPv4) from any other interface and add the router (VLAN) address here for example 192.168.200.1 (No network mask)
      4. Click ok and then apply the configuration
      If you are still running into issues you can jump on the Discord server I have where you can share some pictures so i can more easily help you.

    • @surajmeghoe7962
      @surajmeghoe7962 4 місяці тому

      Im stuck here, my setup is proxmox on 1 pc. On the proxmox I have pfsense and 1 w11 virtual machine. Pfsense can give the virtual machine ip I see, but if I connect my physical LAN INTERFACE OF PFSENSE TO MY SWITCH I CANT GET IP FOR MY VLANS ON MY MANAGED SWITCH. IF I remove the name of the physical interface that has the lan and give it to the ovm, then I cant access pfsense no more. What must I do to have virtually the vlans working and physically.

  • @jenniferw8963
    @jenniferw8963 Рік тому +1

    Thanks for the video. Question; I see you created the OVS Bridge you did not specify a Bridge Port. I see that you have three network interfaces. So which one does it bridge to? I have en01 for WAN traffic (that's the built in 1 gigabit nic) and I have another nic interface (SFP+) used for LAN traffic.

    • @Divgitally
      @Divgitally  Рік тому

      Thanks again!
      I have to look into it to remember my thinking. These videos are partially so I can remind myself when I have to set it up again. If I remember correctly, you should add the physical port as a bridge in the OVS.
      I'll try to remember to look into it later when I am able to.
      My memory is not the best, so please remind me if I am slow!

  • @MyPoincare
    @MyPoincare Рік тому +1

    i am new to network. Very nice video btw, I can follow it without any issue. However, I just wondering. When I remove the bridge connection and use only vlan instead. I lost connection to internet. Is the bridge connection still necessary or I missed to configure vlan to get the internet connection on pfsense setting?

    • @Divgitally
      @Divgitally  Рік тому

      Hello. I'm happy I'm somewhat helpful! You should be able to use only the vlan bridge. What did you lose connection to?
      If you remove the bridge from Proxmox and not the VM. The VM will fail to start because that does not happen automatically.
      If you are able to take some print screen's, you can share them on the discord server I set up. I can more easily help when I can see how it looks.

  • @franzpleurmann2585
    @franzpleurmann2585 Рік тому +2

    I have a mini pc with two nics (wan and lan) and proxmox which virtualizes pfsense. As far as I understand it I would need antother nic to get my managed switch to pick up vlan ids. Can you go into more detail about the way to get the vlans into other switches?

    • @Divgitally
      @Divgitally  Рік тому

      Well it depends on how you set everything up. For lab and learning, I would setup the default vmbr0 as WAN in on pfSense and create another vmbr with the other interface where I could have VLAN's on.
      Passing the VLAN's from pfSense and Proxmox is straight forward, but when it comes to the switches it can be a bit different. Some you will have to setup which port is towards router or other switches and configure the VLAN's while others are more simple.
      What type of switch are you using?

  • @bogy5259
    @bogy5259 10 місяців тому +1

    why cant i just use a normal linux brigde? there i can also give a vlan tag

    • @Divgitally
      @Divgitally  10 місяців тому

      It's a really long time since I was testing different things, but if I recall correctly I ran into some issues with it. That can also be because I did something else wrong.
      I would really like to know about it if you try it with Linux bridge and get it to work!

  • @bogy5259
    @bogy5259 Рік тому +1

    i dont understand why u need the OVS IntPort. Can someone help me?

    • @Divgitally
      @Divgitally  Рік тому

      So I might remember things wrong since i made the video, but there are a few ways of reaching the same goal of using VLAN's in Proxmox. This was the the least messy way I found.
      The reason for the IntPort's is to "configure" the VLAN's on the OVS. you can also add an IP address to the IntPort to allow access to Proxmox from the different VLAN's with different IP addresses
      I am currently using another setup with physical hardware so i can't test if you can completely drop the IntPorts, but that might be the case.

  • @SiwyMisio
    @SiwyMisio Рік тому +1

    Thank you.
    Greetings from Poland.

    • @Divgitally
      @Divgitally  Рік тому

      My pleasure. Good luck with all your vlan'ing!

  • @Dips_M
    @Dips_M Рік тому +2

    Fantastic video thank you! would this also work for creating an isolated test network e.g. a malware analysis environment?

    • @Divgitally
      @Divgitally  Рік тому +1

      I have to say that i am paranoid when it comes to malware, but that is a way to segregate away certain parts of the network. One of the reasons i use this is to keep IOT devices that i don't trust away from the rest of the network.
      I did not go to much into the details around firewall rules but i would also want to make sure that the malware network could access the firewall IP. Also test everything before you let some malware loose!

    • @Dips_M
      @Dips_M Рік тому +1

      @@Divgitally Many thanks for the advice, I too share the same paranoia regarding malware. I have set a malware lab on an old laptop using virtual box, would love to set up on proxmox soon too for convenience. Will make sure to test beforehand as you said.

    • @Divgitally
      @Divgitally  Рік тому +1

      Don't hesitate to ask if you get any questions during setup. I might not have the answer though.
      Malware analysis seems interesting though! I have looked a bit at John Hammond videos where he goes over some malware.

    • @Darkk6969
      @Darkk6969 Рік тому +1

      FYI, most malwares can detect a VM so it won't do anything.

    • @Divgitally
      @Divgitally  Рік тому +1

      @@Darkk6969 Reading your comment made me remember something about malware laying dormant if it could only see one CPU core. They are always developed upon to increase complexity to increase infection rate so that example is old, old news by now.

  • @dotcaodin
    @dotcaodin Рік тому +1

    That's amazing. Don't you have any managed switch in the network?
    I planning to do the same with Sophos XG Home firewall.

    • @Divgitally
      @Divgitally  Рік тому

      Thank you! I have two managed switches that I use actively, one Mikrotik and one Aruba. I did think about showing the VLAN setup on Mikrotik but decided against it to save time.
      I actually ran Sophos XG for a while but personally found pfSense more intuitive, but that was a few years ago. I ran a few services behind it and it worked great.

    • @iothomas
      @iothomas Рік тому

      @@Divgitally yes it was clear saving time was part of the objective, it was like I was watching at 1.5x speed.
      It was very helpful though

    • @Divgitally
      @Divgitally  Рік тому +1

      @@iothomas Glad you found it helpful!
      I'm thinking about making videos in a way where i explain more, but there are so many good people that do it that way so well see.

  • @mandarihno3463
    @mandarihno3463 Рік тому +1

    Great Video

    • @Divgitally
      @Divgitally  Рік тому

      Thank you! I really appreciate people like you taking time to write comments like these!

  • @m14_gamer12
    @m14_gamer12 Рік тому +1

    Can i make vlan on proxmox and pfscense is on standalone device what things i must change or its the same thx.

    • @Divgitally
      @Divgitally  Рік тому

      Hello, as far as i know, you will have to do everything the same except for setting up pfSense on Proxmox. Also remember to check VLAN aware on the network interface in Proxmox.

    • @m14_gamer12
      @m14_gamer12 Рік тому

      @@Divgitally so all step except installing and can i connect it to managed switch and the vlan on pfscense is the same and can i connect another devices to same vlan. And you got another subscriber👍

    • @Divgitally
      @Divgitally  Рік тому

      @@m14_gamer12 That should be correct unless I am missing something. I have usually just run everything on a Proxmox node including the node on the same VLAN but that should be the way if I'm not forgetting something. Hopefully i am correct and i have earned another subscriber!
      Please tell me if I am wrong though. Then i will look into it when i get everything on my network up and running again.

  • @Ayahuaska8
    @Ayahuaska8 Рік тому +1

    Very very interesting information, it will kill some of my life and I would love it!
    Thank you very much!

    • @Divgitally
      @Divgitally  Рік тому +1

      Thank you for the message and good luck VLANing!

    • @Ayahuaska8
      @Ayahuaska8 Рік тому +1

      @@Divgitally I used m0n0 and pfsense in the past and "recently" discovered proxmox and this combination looks amazing and will take part of my life just for fun.
      A guru friend of mine strongly recommended oVirt because of the pain that is ceph with proxmox ... what do you think?
      Thanks the YT algorithm to bring you to me ☺️

    • @Divgitally
      @Divgitally  Рік тому +1

      @@Ayahuaska8 I have yet to get really into ceph, I am trying to learn and understand it fully.
      For type 1 hypervisors, I have used Proxmox, Hyper v and ESXI but I plan to try using both oVirt and Xen.
      So I don't have any clear answer for what I think around that at the moment, but hopefully I can be of more help in the future when I have learned more myself!

  • @javieralhusainy6322
    @javieralhusainy6322 11 місяців тому +1

    how can i do the same with openwrt

    • @Divgitally
      @Divgitally  11 місяців тому +1

      Hello! I am unsure how to do that, but I'll upload a video about it if i get around to trying!

    • @javieralhusainy6322
      @javieralhusainy6322 11 місяців тому +1

      @@Divgitally I've been trying to do it for three days and couldn't get it to work it's probably because I don't know much about networking

    • @Divgitally
      @Divgitally  11 місяців тому

      @@javieralhusainy6322 I am unsure about how OpenWRT handles VLAN's, but it should be the same configuration in Proxmox. You can join the Discord server I have. You can post a few pictures showing your setup and I'll try to look at it!

  • @masszero3521
    @masszero3521 Рік тому +1

    Why people still use pfsense now?
    Make video using proxmox and mikrotik...
    People now uses mikrotik...

    • @Divgitally
      @Divgitally  Рік тому

      Hello, pfSense have a lot of nice features, but I have thought about trying Mikrotik Router OS and want to learn about the cloud hosted router functions.
      I have a Mikrotik switch and really like how functional it is yet easy to use.

    • @Darkk6969
      @Darkk6969 Рік тому +1

      I use both pfsense and MikroTik switches. I have several for my home lab actually. MikroTik is not for everybody as it requires a steep learning curve on networking. It took me a few tries to get VLAN working with pfsense and I've been doing this for a very long time. The thing about VLANs on Mikrotik you use the bridge not the actual port themselves to make use of the hardware offloading.

    • @masszero3521
      @masszero3521 Рік тому

      @@Darkk6969 thats true it needs learning when using Mikrotik been there, now I've been using it with all my networks...