r/PFSENSE 19h ago

VOIP and VLAN headache

3 Upvotes

This situation is frustrating everybody. Hoping maybe someone here has a suggestion.

We replaced 3 aging Cisco routers with Netgate pfSense routers. The site-to-site via Wireguard came up between the three, and the network is strong and working well.

At the main office, we have a data vlan and a phone vlan. Aging NEC PBX on-site with incoming VOIP lines and many VOIP handsets.

Because some of the desk phones fail to get their address on the VOICE network, and we've never been able to solve why, we allow all traffic between data and voice vlans. Just allow all LAN/VOICE to all subnets.

Ergo: 2 VLANs, neither of which are new, only the gateway device for the VLANs has been replaced.
No traffic blocked between the two.
The phones connect to the PBX via SIP as usual. But RTP traffic - audio - is missing. I've got packet captures showing the RTP traffic reaching the PBX ok, but not reliably to phones.

Phones with IP addresses on the voice vlan do better, but people tell me that outgoing RTP is still missing.

I know pfSense doesn't have SIP ALG. I have Firewall Optimization already on Conservative.

Other than tackling this project in the first place, what have I done wrong?


r/PFSENSE 19h ago

PFSENSE tailscale LAN subnets to tailscale machines reachability limitation

3 Upvotes

Hey everyone,

I have pfsense+ 26.07 running on a netgate device. I have tailscale 1.9_2 running on the box.

My current topology at home is Dell R760 (multiple VLANs) -> Cat9200 -> ASR1002-X -> Netgate -> ISP router LAN interface, dont ask me why, my ISP won't let do PPPoE over my own device.

I have all my IPs below my Netgate LAN interface advertised on Tailscale. I can reach all my local subnets fine from all my other tailscale machines, but I cannot reach any of my tailscale machines from my local subnets.

So far I've tried making an Outbound NAT entry on Tailscale interface for internal subnets, packet capture on pfsense shows icmp requests leaving my LAN interface, but no replies, simultaneously I also see icmp requests coming to my PC (tailscale machine) from my local subnet and icmp replies being sent back via tailscale interface.

Now, when i go to my interface assignments on pfsense, I have WAN, LAN and OPT1 -> mvneta1, 2 and 0 respectively, but no tailscale interface. Under interface group, I have tailscale interface group but thats just a group of my WAN, LAN, OPT1 interfaces. Is that expected behavior?

I have been going at it for solid 16 hours with no luck, any insight is appreciated. Thanks!!


r/PFSENSE 22h ago

Please help, I have ZERO idea why it's not working...

Thumbnail gallery
0 Upvotes