Skip to content
DnsLister Forum

Where domain hunters compare notes

Help with my basic network

Solved

TLDR: A newbie (me) spend 22 hours of a weekend trying to transform his network from a flat network through a consumer grade WiFi Router, to a proper segregated network with a pfSense router/firewall mini PC and his WiFi router transformed VLAN aware WiFi Access Point through OpenWRT. Of that time, 19 hours were trying to figure out why he could connect to the AP, but had no internet.

Solution: I don't know if I am such a newbie that I did not know to look for that, or that it was suppose to configure itself, but the problem was in pfSense, in Services -> DNS Resolver -> Access List. It was empty. So, the laptop connected to the LAN port had internet access, but the devices connecting to the AP got every DNS request denied.

I leave this here crossing my fingers it saves someone else those 19 hours. Thanks for the responses.

Below is the body of the original post.

Original Post

Hey, I am relatively new to homelabing, and the first thing I want to do is set up networking. I have spent over twenty hours this weekend trying to set this up, but I am still stuck. I apologize if I do not use some terms properly, as I said, I am a newbie.

Below I detail what I have and what I have done, and the problem I have. I appreciate any help, and let me know if there is any other info I can post that help you understand the problem.

My previous set up

Before now I have always had a flat network, that for years have been as follows

  • Crappy Linksys WiFi router provided (read: sold at ridiculous markup) from my ISP, where I am locked out from the Web GUI.
  • A D-Link Eagel Pro AI AX3200 (R32) WiFi router connected directly to the ISP router, that is the one where everything at home is connected to (as I understand, that means I am double NATed).
  • A second D-Link router, same model, as a wireless extender to my home office where the signal of the first is weak. It is not wired, it connects to the first router wirelessly (my house is old, not ethernet wired, I need to fix that).

My goal

Having a properly isolated network with multiple VLANs, having a box working as a pfSense router / firewall, with a first R32 running OpenWRT as a VLAN aware WiFi AP, and a second R32, also with OpenWRT as an extender in my home office for the first one.

My proposed VLANs

VLAN Use When? WiFi?
trusted Household personal devices. ASAP Yes
homelab Household services ASAP No
guest Transient devices Soon Yes
playground Learning / Experimenting / Testing Later No
IoT TVs, printer, IoT devices Soon Yes
work Employer provided Equipment Soon Yes
DMZ DMZ Later No
management Network infrastructure Soon No

The equipment

Besides the two R32s, I got a Qotom branded mini PC with these specs:

Category Specification
CPU Intel i5-8260u
RAM 16 GB DDR4 SODIM
Storage 128 GB NVMe M.2 PCIe 3
Networking 8 ports
LAN 1 – 2 10 G SFP
LAN 3 – 8 i226v 2.5 G RJ45

Currently running pfSense CE 2.7.2, and I have successfully mapped the RJ45 ports to their MACs and interfaces (I don't have yet SFP adapters for ports 1 and 2).

Also I have flashed already one of the R32 with OpenWRT 24.10.5

Desired distribution of ports on pfSense box

Port Device VLAN(s)
3 ISP WAN
4 R32 trusted, work, IoT, guest
5 NAS homelab
6 Proxmox server homelab
7 Testing box playground, DMZ
8 Management port management

What I have done

As I don't want to bring down the network, right now I working like this:

text ISP | Linksys | R32 with D-Link Firmware | pfSense box | R32 with OpenWRT

On pfSense box

  1. Installed pfSense 2.7.2
  2. Assigned port 3 to WAN and port 8 to LAN
  3. Ran Wizard Setup, only changed time zone and unchecked the blockage of private networks on WAN (I am double NATed at this moment).
  4. Created the VLANs that require WiFi access, these are trusted, guest, IoT and work.
  5. Created a trunk interface on port 4 for these VLANs.
  6. Created the interfaces for those VLANs.
  7. Configured the DHCP services for those VLANs.
  8. Created very permissive "all to all pass" firewall rules for the VLANs (I will tight this up when I have a working network).

Results: Wired connection on port 8 gets IP lease from pfSense, can access without issues the web and the Web GUI.

On OpenWRT R32

  1. I flashed the firmware
  2. Disabled DHCP on lan interface
  3. On Networ -> Interfaces -> Devices -> br-lan -> Configure -> Bridge VLAN filtering added untagged management in two ports LAN ports (one to pfSense box and the other to a laptop connected through cable), and tagged for the four VLANs that are included in the trunk.
  4. Assigned interfaces to each VLAN created.
  5. On Network -> Wireless I created the SSID for trusted to test.

Results

  1. I can connect to the OpenWRT Web GUI from the laptop (wired)
  2. I can connect my phone to that SSID.
  3. The phone gets an IP in the appropriate range.
  4. The phone cannot access OpenWRT Web GUI.
  5. The phone can access pfSense Web GUI.
  6. The phone can access the D-Link Web GUI from the R32 that is behind the pfSense box.
  7. Neither the phone nor the laptop connected to the OpenWRT R32 can connect to the internet.

All I want is to be able to connect to the open internet wirelessly from the OpenWRT box, but I am really stuck. I tried help from Gemini, but it led to being locked out from the OpenWRT box and having to reflash it. I tried help from ChatGPT, but it is going on deep rabbit holes and my Sunday is almost over, without getting even my network working (I had the hope to configure also the NAS and at least one or two services on Proxmox).

Any ideas?

Source: r/homelab · by /u/djimenez81

Leave a Reply

Your email address will not be published. Required fields are marked *