- Joined
- Nov 22, 2017
- Messages
- 310
So here is what I am trying to do: there are three vlans coming into freenas (10, 50, 60) and there are two jails running, one on vlan 10 (where the web gui also runs) and the other on vlan 60; vlan 50 is mostly unused aside from also being what the bmc is on. This is mostly working; I added the the vlans under networking, added static routes for physical lan and the two vlans in use and set vlan 10 to dhcp (static assignment) and the others to static ips. The jails each have different bridges specified and the apropreate vlan for the vnet default interface, they are also each set to use dhcp which is statically assigned.
I can ping all of the freenas's addresses from my computer (which is on vlan 10) and the jail on vlan 10, but not the one on vlan 60 (there are firewall rules that should allow this), and when I ssh in I cannot ping my computer from the jail on vlan 60. Also I cannot connect to the web management interface on the jail running on vlan 60.
For the firewall I am running pfsense and at the moment each network has a rule passing traffic to the other.
I am hoping someone might be able to tell me how I can make this work or what other info might be useful in diagnosing the problem.
I can ping all of the freenas's addresses from my computer (which is on vlan 10) and the jail on vlan 10, but not the one on vlan 60 (there are firewall rules that should allow this), and when I ssh in I cannot ping my computer from the jail on vlan 60. Also I cannot connect to the web management interface on the jail running on vlan 60.
For the firewall I am running pfsense and at the moment each network has a rule passing traffic to the other.
I am hoping someone might be able to tell me how I can make this work or what other info might be useful in diagnosing the problem.
Code:
$ ifconfig -a igb0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=6403bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,VLAN_HWTSO,RXCSUM_IPV6,TXCSUM_IPV6> ether d0:50:99:c1:3d:03 hwaddr d0:50:99:c1:3d:03 inet 192.168.4.115 netmask 0xffffff00 broadcast 192.168.4.255 nd6 options=9<PERFORMNUD,IFDISABLED> media: Ethernet autoselect (1000baseT <full-duplex>) status: active igb1: flags=8c02<BROADCAST,OACTIVE,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=6403bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,VLAN_HWTSO,RXCSUM_IPV6,TXCSUM_IPV6> ether d0:50:99:c1:3d:04 hwaddr d0:50:99:c1:3d:04 nd6 options=9<PERFORMNUD,IFDISABLED> media: Ethernet autoselect (1000baseT <full-duplex>) status: active lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=600003<RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6> inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x3 inet 127.0.0.1 netmask 0xff000000 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> groups: lo vlan11: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=200001<RXCSUM,RXCSUM_IPV6> ether d0:50:99:c1:3d:03 inet 192.168.60.115 netmask 0xffffff00 broadcast 192.168.60.255 nd6 options=9<PERFORMNUD,IFDISABLED> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 60 vlanpcp: 0 parent interface: igb0 groups: vlan vlan10: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=200001<RXCSUM,RXCSUM_IPV6> ether d0:50:99:c1:3d:03 inet 192.168.9.115 netmask 0xffffff00 broadcast 192.168.9.255 nd6 options=9<PERFORMNUD,IFDISABLED> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 10 vlanpcp: 0 parent interface: igb0 groups: vlan vlan12: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=600303<RXCSUM,TXCSUM,TSO4,TSO6,RXCSUM_IPV6,TXCSUM_IPV6> ether d0:50:99:c1:3d:03 inet 192.168.50.115 netmask 0xffffff00 broadcast 192.168.50.255 nd6 options=9<PERFORMNUD,IFDISABLED> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 50 vlanpcp: 0 parent interface: igb0 groups: vlan bridge0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 02:6f:4f:03:36:00 nd6 options=1<PERFORMNUD> groups: bridge id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15 maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200 root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0 member: vnet0:1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP> ifmaxaddr 0 port 8 priority 128 path cost 2000 member: vlan10 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP> ifmaxaddr 0 port 5 priority 128 path cost 20000 vnet0:1: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: associated with jail: plex as nic: epair0b options=8<VLAN_MTU> ether b2:13:dd:98:4a:80 hwaddr 02:ba:d0:00:08:0a nd6 options=1<PERFORMNUD> media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>) status: active groups: epair bridge11: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 02:6f:4f:03:36:0b nd6 options=1<PERFORMNUD> groups: bridge id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15 maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200 root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0 member: vnet0:2 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP> ifmaxaddr 0 port 10 priority 128 path cost 2000 member: vlan11 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP> ifmaxaddr 0 port 4 priority 128 path cost 20000 vnet0:2: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: associated with jail: transmission as nic: epair0b options=8<VLAN_MTU> ether 4a:3a:78:77:16:83 hwaddr 02:ba:d0:00:0a:0a nd6 options=1<PERFORMNUD> media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>) status: active groups: epair