Setup VLAN on pfSense virtualized in Proxmox

Поделиться
HTML-код
  • Опубликовано: 4 дек 2024

Комментарии • 87

  • @DodoDodo-eo2su
    @DodoDodo-eo2su Год назад +31

    Jesus, I wish every tutorial was so straight on point. No intro, no "hit the subscribe button", no bullshit. Wonderful

    • @Divgitally
      @Divgitally  Год назад

      Thank you for the message! I really appreciate it! I make the guides I want for myself. Also I forget things and have to look at them myself from time to time to remember.

  • @vojtechstoklasa3417
    @vojtechstoklasa3417 10 месяцев назад +10

    Finally a video about proxmox vlans which doesn't take 10 years and is straight to point, you helped me to solve issue i had for last 2 days

    • @Divgitally
      @Divgitally  10 месяцев назад

      Haha, I'm happy my video was useful, and thank you for the message! There are times for longer, more detailed videos. Then there are other times you just need some quick answer's!

  • @samsh0-q3a
    @samsh0-q3a 10 месяцев назад +2

    Now THAT is a Tutorial! I know what VLANs are, I know how to set them up on a physical switch, however virtualizing is a different beast and you got RIGHT TO THE POINT! You rock!

    • @Divgitally
      @Divgitally  10 месяцев назад

      Thanks! I really appreciate your feedback! The points you hit on is what i try to accomplish and I'm happy that I managed to do that! Thank you for the message!

  • @ethereal5097
    @ethereal5097 3 месяца назад +2

    Now, that's how you do a how-to video.
    Thanks!

    • @Divgitally
      @Divgitally  3 месяца назад

      I'm glad you like the video! Thank you for the kind words!

  • @louisemothe9204
    @louisemothe9204 Год назад +2

    Thank you very much for your video which helped me to create secure virtual machines in my network to detect and report Internet scammers. It made my job much easier and I am very grateful.

    • @Divgitally
      @Divgitally  Год назад +1

      Really happy to hear that the video was useful to you! and good luck in hunting down and reporting scammers!
      It would be really interesting knowing more about how you go about doing that!

  • @SiwyMisio
    @SiwyMisio 2 года назад +1

    Thank you.
    Greetings from Poland.

    • @Divgitally
      @Divgitally  2 года назад

      My pleasure. Good luck with all your vlan'ing!

  • @Ayahuaska8
    @Ayahuaska8 2 года назад +1

    Very very interesting information, it will kill some of my life and I would love it!
    Thank you very much!

    • @Divgitally
      @Divgitally  2 года назад +1

      Thank you for the message and good luck VLANing!

    • @Ayahuaska8
      @Ayahuaska8 2 года назад +1

      @@Divgitally I used m0n0 and pfsense in the past and "recently" discovered proxmox and this combination looks amazing and will take part of my life just for fun.
      A guru friend of mine strongly recommended oVirt because of the pain that is ceph with proxmox ... what do you think?
      Thanks the YT algorithm to bring you to me ☺️

    • @Divgitally
      @Divgitally  2 года назад +1

      @@Ayahuaska8 I have yet to get really into ceph, I am trying to learn and understand it fully.
      For type 1 hypervisors, I have used Proxmox, Hyper v and ESXI but I plan to try using both oVirt and Xen.
      So I don't have any clear answer for what I think around that at the moment, but hopefully I can be of more help in the future when I have learned more myself!

  • @KareemAly-e9o
    @KareemAly-e9o 2 месяца назад

    Thanks for sharing.

  • @ImTheKaiser
    @ImTheKaiser Год назад +2

    I just handle the vlans on proxmox so pfsense sees them as actual interfaces.
    This makes it more portable and easier to replicate if hardware changes.
    This also gives me more security if there is other tagged traffic on the trunk, as proxmox won’t even show/pass it to the VM
    Downside is it may require restarting the vm if you are trying to add a new vlan(nic)and unable to hot plug the new interface

    • @Divgitally
      @Divgitally  Год назад

      Cool. Thank you for the tip. It's always nice to have multiple ways of doing things like VLAN'S!

  • @mandarihno3463
    @mandarihno3463 Год назад +1

    Great Video

    • @Divgitally
      @Divgitally  Год назад

      Thank you! I really appreciate people like you taking time to write comments like these!

  • @jenniferw8963
    @jenniferw8963 Год назад +1

    Thanks for the video. Just wondering why you went iwth OVS Bridge/IntPort for VLAN support? I see Linux Bridge and Linux VLAN above that. What's the difference between the two?

    • @Divgitally
      @Divgitally  Год назад

      Hello! Thank you for the message!
      Using OVS was the first way I got it working. You can use Linux VLAN's, but I found that I more easily lost overview. Other than my preference, there should not be any major difference.

  • @MyPoincare
    @MyPoincare Год назад +2

    i am new to network. Very nice video btw, I can follow it without any issue. However, I just wondering. When I remove the bridge connection and use only vlan instead. I lost connection to internet. Is the bridge connection still necessary or I missed to configure vlan to get the internet connection on pfsense setting?

    • @Divgitally
      @Divgitally  Год назад

      Hello. I'm happy I'm somewhat helpful! You should be able to use only the vlan bridge. What did you lose connection to?
      If you remove the bridge from Proxmox and not the VM. The VM will fail to start because that does not happen automatically.
      If you are able to take some print screen's, you can share them on the discord server I set up. I can more easily help when I can see how it looks.

  • @drreality1
    @drreality1 2 года назад +3

    Thanks, why would be the benefit from ovs bridge vs normal bridg?
    Cheers

    • @Divgitally
      @Divgitally  2 года назад +1

      I think it can become a bit messy depending on how you do it with normal bridges. But I cant say that one is better than the other, this is just the way i like to do it.

  • @jenniferw8963
    @jenniferw8963 Год назад +1

    Thanks for the video. Question; I see you created the OVS Bridge you did not specify a Bridge Port. I see that you have three network interfaces. So which one does it bridge to? I have en01 for WAN traffic (that's the built in 1 gigabit nic) and I have another nic interface (SFP+) used for LAN traffic.

    • @Divgitally
      @Divgitally  Год назад

      Thanks again!
      I have to look into it to remember my thinking. These videos are partially so I can remind myself when I have to set it up again. If I remember correctly, you should add the physical port as a bridge in the OVS.
      I'll try to remember to look into it later when I am able to.
      My memory is not the best, so please remind me if I am slow!

  • @GT-sc5sk
    @GT-sc5sk 2 месяца назад

    that work well on just one node, what is about HA..migration to another proxomox node maybe will work but you will loose connectivity..that guess can not can be fixed

  • @keketohmx
    @keketohmx Год назад +3

    Thank you so much for the info🙏🏻🎉
    In the last step you say it’s possible to take the name of a physical interface that is already in use on a bridge (LAN) and to add the name of the physical interface into the OVS bridge ports.
    When I do this, I lose my pfsense web interface and I can only access pfsense via the console in proxmox. Is there something I might be missing that is causing this? Or is this expected?

    • @Divgitally
      @Divgitally  Год назад +3

      If you are taking the interface you need for connecting to Proxmox, you will have to add an IP address to the VLAN you wish to connect to Proxmox via.
      I should have done a better job of explaining that, apologies for that!

    • @franzpleurmann2585
      @franzpleurmann2585 Год назад

      @@Divgitally Can you explain step by step how to do that? Where do I have to add the IP address - in the proxmox network tab (OVS Bridge or OVS IntPort) or in the Pfsense Interfaces Tab (IPv4 Configuration Type)?

    • @Divgitally
      @Divgitally  Год назад

      @@franzpleurmann2585 Hello! You add it to the OVS intPort on Proxmox. If you look at 4:09 in the video.
      1. Select the vlan you wish to access Proxmox through and edit it.
      2. Add an IP address and network mask in bits from the range you have on that VLAN in the field next to "IPv4/CIDR". An example is 192.168.200.40/24
      3. If you plan on Proxmox reaching out to the internet via this VLAN you will have to empty the Gateway (IPv4) from any other interface and add the router (VLAN) address here for example 192.168.200.1 (No network mask)
      4. Click ok and then apply the configuration
      If you are still running into issues you can jump on the Discord server I have where you can share some pictures so i can more easily help you.

    • @surajmeghoe7962
      @surajmeghoe7962 7 месяцев назад

      Im stuck here, my setup is proxmox on 1 pc. On the proxmox I have pfsense and 1 w11 virtual machine. Pfsense can give the virtual machine ip I see, but if I connect my physical LAN INTERFACE OF PFSENSE TO MY SWITCH I CANT GET IP FOR MY VLANS ON MY MANAGED SWITCH. IF I remove the name of the physical interface that has the lan and give it to the ovm, then I cant access pfsense no more. What must I do to have virtually the vlans working and physically.

  • @Dips_M
    @Dips_M 2 года назад +2

    Fantastic video thank you! would this also work for creating an isolated test network e.g. a malware analysis environment?

    • @Divgitally
      @Divgitally  2 года назад +1

      I have to say that i am paranoid when it comes to malware, but that is a way to segregate away certain parts of the network. One of the reasons i use this is to keep IOT devices that i don't trust away from the rest of the network.
      I did not go to much into the details around firewall rules but i would also want to make sure that the malware network could access the firewall IP. Also test everything before you let some malware loose!

    • @Dips_M
      @Dips_M 2 года назад +1

      @@Divgitally Many thanks for the advice, I too share the same paranoia regarding malware. I have set a malware lab on an old laptop using virtual box, would love to set up on proxmox soon too for convenience. Will make sure to test beforehand as you said.

    • @Divgitally
      @Divgitally  2 года назад +1

      Don't hesitate to ask if you get any questions during setup. I might not have the answer though.
      Malware analysis seems interesting though! I have looked a bit at John Hammond videos where he goes over some malware.

    • @Darkk6969
      @Darkk6969 2 года назад +1

      FYI, most malwares can detect a VM so it won't do anything.

    • @Divgitally
      @Divgitally  2 года назад +1

      @@Darkk6969 Reading your comment made me remember something about malware laying dormant if it could only see one CPU core. They are always developed upon to increase complexity to increase infection rate so that example is old, old news by now.

  • @franzpleurmann2585
    @franzpleurmann2585 Год назад +2

    I have a mini pc with two nics (wan and lan) and proxmox which virtualizes pfsense. As far as I understand it I would need antother nic to get my managed switch to pick up vlan ids. Can you go into more detail about the way to get the vlans into other switches?

    • @Divgitally
      @Divgitally  Год назад

      Well it depends on how you set everything up. For lab and learning, I would setup the default vmbr0 as WAN in on pfSense and create another vmbr with the other interface where I could have VLAN's on.
      Passing the VLAN's from pfSense and Proxmox is straight forward, but when it comes to the switches it can be a bit different. Some you will have to setup which port is towards router or other switches and configure the VLAN's while others are more simple.
      What type of switch are you using?

  • @John-vk1ij
    @John-vk1ij Год назад +1

    Quick question. Is it possible to not modify the Proxmox VE network settings? I'd like to only create a VLAN20 in pfSense on the existing LAN interface, and leave PVE agnostic of any VLAN going on that interface.

    • @Divgitally
      @Divgitally  Год назад +1

      Hello. Thank you for the question. If you just want the one VLAN on the interface, it should be fine as long as you enable VLAN on it. It's with multiple VLAN's on the same interface you will run into issues.

  • @dotcaodin
    @dotcaodin 2 года назад +1

    That's amazing. Don't you have any managed switch in the network?
    I planning to do the same with Sophos XG Home firewall.

    • @Divgitally
      @Divgitally  2 года назад

      Thank you! I have two managed switches that I use actively, one Mikrotik and one Aruba. I did think about showing the VLAN setup on Mikrotik but decided against it to save time.
      I actually ran Sophos XG for a while but personally found pfSense more intuitive, but that was a few years ago. I ran a few services behind it and it worked great.

    • @iothomas
      @iothomas 2 года назад

      @@Divgitally yes it was clear saving time was part of the objective, it was like I was watching at 1.5x speed.
      It was very helpful though

    • @Divgitally
      @Divgitally  2 года назад +1

      @@iothomas Glad you found it helpful!
      I'm thinking about making videos in a way where i explain more, but there are so many good people that do it that way so well see.

  • @sigitkusuma
    @sigitkusuma 9 месяцев назад +1

    is it possible to implement only using 1 ether interface on proxmox ?

    • @Divgitally
      @Divgitally  9 месяцев назад

      Yes, that is absolutely possible. It can just be a bit more messy. You will still need another router as a gateway.
      Do you have anything special in mind?

  • @ronald0122
    @ronald0122 2 месяца назад

    can't i juse use vlan aware on the default bridge on the lan port. my goal is to use multiple vlans on my physical switch that is connected to my proxmox host with pfsense installed. my proxmox host has 2 nics (1 for lan + vlans and 1 for wan).

  • @kuacikecil9019
    @kuacikecil9019 7 месяцев назад +1

    How to configure vlan on mikrotik virtualized proxmox sir?

    • @Divgitally
      @Divgitally  7 месяцев назад

      Hello! The Proxmox side should be similar, but i have not used the Mikrotik router enough to say anything about how to do that, but if you join the Discord server i have in the video description and share some images from the UI I could try to help you!

  • @jaY-fq7qs
    @jaY-fq7qs 7 месяцев назад +1

    Hi , dumb Q. do i need vlan switch here using OVS?

    • @Divgitally
      @Divgitally  7 месяцев назад

      Hello there. Not stupid at all! It really depends on what you want to do. If you just want to have multiple VLAN's on Proxmox and share one VLAN out, you do not need anything other than a unmanaged switch. You just need it if you wish to have multiple VLAN's out from Proxmox.

    • @jaY-fq7qs
      @jaY-fq7qs 7 месяцев назад +1

      @@Divgitally thnks for your reply. yeah i have proxmox on my intel nuc which has single LAN. and i also have manged switch capable of vlan. if im going to add multiple vm with vlans, i want to try this OVS. would it work? i think this one would be the solution for having a single NIC. Can you please help me out. 😃
      in proxmox single NIC, im running pfsense, i just dont kniw how to integrate coin wifi hotspot on vlan22. and sometimes i just want try out another firewall and vms like opnsense, openwrt, and so on. Thank you!

    • @Divgitally
      @Divgitally  7 месяцев назад

      It is absolutely possible to do with one nic, but you will need to set up one VLAN on your switch for WAN and one or more for your LAN side. Then, all VLANS need to be trunked to the port where your Proxmox and pfSense router is connected.
      All VLAN's need to be on the same physical interface you have on Proxmox.
      There are some others I have spoken with on the Discord server I set up that has done the same as you want to do. There is a link to it in the video description if you wish to hop on there. It is just a bit easier to follow up there.
      There are plenty of good routers and firewall's to virtualize and play with! OPNsense is similar to pfSense. OpenWRT is more of a router compared to the two others.

    • @jaY-fq7qs
      @jaY-fq7qs 7 месяцев назад

      @@Divgitally Thank you bro! appreciate it ! 🍻

  • @JspectraX
    @JspectraX 3 месяца назад +1

    Would you do the same for OPNsense?

    • @Divgitally
      @Divgitally  3 месяца назад

      I have thought about it. I plan on changing from a "physical pfSense router" to a virtual OPNsense router for my lab network. I will be setting up a test network before going ahead with that which I plan on making a guide on. I sadly don't have a time-frame though.

  • @bogy5259
    @bogy5259 Год назад +1

    i dont understand why u need the OVS IntPort. Can someone help me?

    • @Divgitally
      @Divgitally  Год назад

      So I might remember things wrong since i made the video, but there are a few ways of reaching the same goal of using VLAN's in Proxmox. This was the the least messy way I found.
      The reason for the IntPort's is to "configure" the VLAN's on the OVS. you can also add an IP address to the IntPort to allow access to Proxmox from the different VLAN's with different IP addresses
      I am currently using another setup with physical hardware so i can't test if you can completely drop the IntPorts, but that might be the case.

  • @bogy5259
    @bogy5259 Год назад +1

    why cant i just use a normal linux brigde? there i can also give a vlan tag

    • @Divgitally
      @Divgitally  Год назад

      It's a really long time since I was testing different things, but if I recall correctly I ran into some issues with it. That can also be because I did something else wrong.
      I would really like to know about it if you try it with Linux bridge and get it to work!

  • @m14_gamer12
    @m14_gamer12 Год назад +1

    Can i make vlan on proxmox and pfscense is on standalone device what things i must change or its the same thx.

    • @Divgitally
      @Divgitally  Год назад

      Hello, as far as i know, you will have to do everything the same except for setting up pfSense on Proxmox. Also remember to check VLAN aware on the network interface in Proxmox.

    • @m14_gamer12
      @m14_gamer12 Год назад

      @@Divgitally so all step except installing and can i connect it to managed switch and the vlan on pfscense is the same and can i connect another devices to same vlan. And you got another subscriber👍

    • @Divgitally
      @Divgitally  Год назад

      @@m14_gamer12 That should be correct unless I am missing something. I have usually just run everything on a Proxmox node including the node on the same VLAN but that should be the way if I'm not forgetting something. Hopefully i am correct and i have earned another subscriber!
      Please tell me if I am wrong though. Then i will look into it when i get everything on my network up and running again.

  • @ricardosalafte
    @ricardosalafte 7 месяцев назад +1

    thank you great video , could you please help me , i cant get ping betwen the vlans....

    • @Divgitally
      @Divgitally  7 месяцев назад

      Hello! I'm glad it somewhat helped! If you have Discord, you can hop on the server i have and share a screenshot of the rules you have set up so i can more easily see whats up! The invite is in the video description.

  • @javieralhusainy6322
    @javieralhusainy6322 Год назад +1

    how can i do the same with openwrt

    • @Divgitally
      @Divgitally  Год назад +1

      Hello! I am unsure how to do that, but I'll upload a video about it if i get around to trying!

    • @javieralhusainy6322
      @javieralhusainy6322 Год назад +1

      @@Divgitally I've been trying to do it for three days and couldn't get it to work it's probably because I don't know much about networking

    • @Divgitally
      @Divgitally  Год назад

      @@javieralhusainy6322 I am unsure about how OpenWRT handles VLAN's, but it should be the same configuration in Proxmox. You can join the Discord server I have. You can post a few pictures showing your setup and I'll try to look at it!

  • @faizansirajuddin
    @faizansirajuddin 8 месяцев назад +1

    I installed mikrotik in proxmox and And want to utilizee 1-512 VLANs on a single port. So do I need to create these interfaces one by one 512 times? Or is there any shorter command?

    • @Divgitally
      @Divgitally  8 месяцев назад +1

      Hello! There might be a way to do it more quickly, but I don't know it. I can try to take a look later.
      Can I ask you why you need that many VLAN's? I have never seen that many VLAN's in use at one time in a setup.

    • @faizansirajuddin
      @faizansirajuddin 8 месяцев назад +1

      @@Divgitally I'm admin at internet provider, so we are segregating our zones by vlan. So we required even more than 512 as our network spans over entire country.

    • @Divgitally
      @Divgitally  8 месяцев назад +1

      @@faizansirajuddin​ Cool! That makes sense!
      from what i can see, the command below is used to generate a vlan. An option is to generate all the commands using something like excel for example, then copying them (first to notepad because Excel can be annoying) into the CLI. You might get away with pushing 20 or more commands at a time, but i cant promise that.
      /interface vlan add vlan-id=50 interface=ether2 name=ether2-vlan50
      I don't have any better tips for doing that at the moment best of luck to you and I'm here or Discord if you need me!

    • @faizansirajuddin
      @faizansirajuddin 8 месяцев назад +1

      @Divgitally Regards! Another issue I encountered when virtualizing Mikrotik on Proxmox is that it behaves strangely with PPPOE users-users connect occasionally and disconnect others. especially when using vlans to host numerous PPPOE servers. I set up a dhcp server on the same VLAN to confirm that it was operational. However, when switching to PPPoE on the same VLAN, requests occasionally get through and occasionally don't. Using CCR resolved this issue for me.

    • @Divgitally
      @Divgitally  8 месяцев назад

      @@faizansirajuddinThank you for sharing! I have personally just used it in a minor setup, but it would really be interesting to learn more about your setup! Can i ask about the spec's on your machine?

  • @masszero3521
    @masszero3521 2 года назад +1

    Why people still use pfsense now?
    Make video using proxmox and mikrotik...
    People now uses mikrotik...

    • @Divgitally
      @Divgitally  2 года назад

      Hello, pfSense have a lot of nice features, but I have thought about trying Mikrotik Router OS and want to learn about the cloud hosted router functions.
      I have a Mikrotik switch and really like how functional it is yet easy to use.

    • @Darkk6969
      @Darkk6969 2 года назад +1

      I use both pfsense and MikroTik switches. I have several for my home lab actually. MikroTik is not for everybody as it requires a steep learning curve on networking. It took me a few tries to get VLAN working with pfsense and I've been doing this for a very long time. The thing about VLANs on Mikrotik you use the bridge not the actual port themselves to make use of the hardware offloading.

    • @masszero3521
      @masszero3521 2 года назад

      @@Darkk6969 thats true it needs learning when using Mikrotik been there, now I've been using it with all my networks...