From owner-freebsd-questions@FreeBSD.ORG Fri Jul 23 11:47:40 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4C1E716A4CE for ; Fri, 23 Jul 2004 11:47:40 +0000 (GMT) Received: from mproxy.gmail.com (rproxy.gmail.com [64.233.170.194]) by mx1.FreeBSD.org (Postfix) with SMTP id E953C43D1F for ; Fri, 23 Jul 2004 11:47:39 +0000 (GMT) (envelope-from emilholt@gmail.com) Received: by mproxy.gmail.com with SMTP id 78so8792rnl for ; Fri, 23 Jul 2004 04:47:39 -0700 (PDT) Received: by 10.38.89.74 with SMTP id m74mr180201rnb; Fri, 23 Jul 2004 04:47:39 -0700 (PDT) Message-ID: Date: Fri, 23 Jul 2004 13:47:39 +0200 From: emil To: freebsd-questions@freebsd.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: 801.Q VLAN questions X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Jul 2004 11:47:40 -0000 Hello, I'm currently in the middle of setting up a couple of Cisco Aironet 1100 802.11b/g access points. I've configured the APs so that they tag ethernet frames depending on what SSID is being used by the WLAN users. (One public and one private SSID). Behind the APs I've set up a FreeBSD 5.2.1p9 box with pf (/usr/ports/security/pf) installed. The FBSD machine currently has 3 intel (fxp) ethernet interfaces: fxp0, management interface. fxp1 interface connected to a small dumb switch which the APs are hooked up to, currently no IP adress configured. fxp2 interface connected to the "net", currently no IP adress configured. Then I also have 2 vlan interfaces with the respective VLAN ID's set, they use fxp1 as their parent interface. What I want to do is to bridge fxp1 and fxp2 and then have pf filter the traffic on the vlans. However, the FBSD machine seems to completely ignore the 802.1Q tags, and not separate the traffic coming to fxp1. So does the hive mind have any ideas of what to do? TIA