Hello,
My / the problem is, that I do not manage to get a decent vlan separation and routing inside TrueNas.
Different traffic streams should be separated by VLAN's. For that reason, the NAS is connected with vlan-tagged trunks to my switches.
The NAS has two interfaces:
- the first nic (em0) one vlan being the management vlan for emergency access
- the second nic (mlxen0) has a combination of vlan's related to multiple purposes and also has the management vlan
The management VLAN should be tied to the TrueNas GUI and the other VLANS are related to TrueNas storage, VM's and Jails.
To make that work in the GUI we have:
a) the global network configuration
b) interfaces of type interface, vlan, bridge and lagg
Below my comments on the related settings / screens
Global network configuration
I feel very unconformable there:
- It seems to be the configuration page of the TrueNAS GUI (and partly the network layer). However all kind of strange things IMHO
* It should be related to a particular VLAN (in case you use VLAN's), ..... but it is not
* there are a default gateways, nameservers and domains, things which IMHO should be related to VLAN's and not to something global !!!
To have a global Default gateway is even dramatic, traffic should never be allowed to leave a VLAN !
VLAN set-up
- very wired things as well.
* a vlan is assigned to an interface (thats OK)
* a vlan is tagged or not (that is missing, just as PIVD)
* and VLAN addresses are definitely not related to an interface !!
* you should give vlan's a unique name being vlanxx, where it sounds logical that xx equals the vlanno, however .... problem is you have two links carrying the same vlan
Bridge set-up
- tja what is a bridge here, I think it is best compared with an internal unmanaged switch
- and again IP-address do not belong to an bridge
- and what if you tie two interfaces together using a bridge ...... then the IP-numbers should probably ..... be assigned to the bridge ... since you can not assign then to all related ^VLAN-ports/interfaces^
Trying to access the GUI
As written above I am trying to connect the GUI via the traffic trunk and for emergency purposes via the management interface port/trunk as well. Lots of problems there as well:
Scenario-1
VLAN-1 has IP-addresses defined and VLAN-2 as well. The Default gateway is related to VLAN-2
- that does not work for VLAN1 since the traffic is routed back via VLAN-1
Scenario-2
VLAN-1 is on interface-1 (vlan-1a) and on interface-2 (vlan-1b) as well, so I decide to define a bridge (bridge1)
- I assigned vlan-1a and vlan1b to that bridge
- and assigned an IP-address to the bridge
- after that I can assign the bridge IP to the GUI
However ...... I could not access the GUI via that IP at all !!
As example, at the moment I can only use the traffic-vlan (which have the default route) to reach the GUI. Not what I want and not secure.
To summarize:
- the GUI is IMHO very weird
- a couple of things do not work at all (hopefully I am wrong)
Louis
My / the problem is, that I do not manage to get a decent vlan separation and routing inside TrueNas.
Different traffic streams should be separated by VLAN's. For that reason, the NAS is connected with vlan-tagged trunks to my switches.
The NAS has two interfaces:
- the first nic (em0) one vlan being the management vlan for emergency access
- the second nic (mlxen0) has a combination of vlan's related to multiple purposes and also has the management vlan
The management VLAN should be tied to the TrueNas GUI and the other VLANS are related to TrueNas storage, VM's and Jails.
To make that work in the GUI we have:
a) the global network configuration
b) interfaces of type interface, vlan, bridge and lagg
Below my comments on the related settings / screens
Global network configuration
I feel very unconformable there:
- It seems to be the configuration page of the TrueNAS GUI (and partly the network layer). However all kind of strange things IMHO
* It should be related to a particular VLAN (in case you use VLAN's), ..... but it is not
* there are a default gateways, nameservers and domains, things which IMHO should be related to VLAN's and not to something global !!!
To have a global Default gateway is even dramatic, traffic should never be allowed to leave a VLAN !
VLAN set-up
- very wired things as well.
* a vlan is assigned to an interface (thats OK)
* a vlan is tagged or not (that is missing, just as PIVD)
* and VLAN addresses are definitely not related to an interface !!
* you should give vlan's a unique name being vlanxx, where it sounds logical that xx equals the vlanno, however .... problem is you have two links carrying the same vlan
Bridge set-up
- tja what is a bridge here, I think it is best compared with an internal unmanaged switch
- and again IP-address do not belong to an bridge
- and what if you tie two interfaces together using a bridge ...... then the IP-numbers should probably ..... be assigned to the bridge ... since you can not assign then to all related ^VLAN-ports/interfaces^
Trying to access the GUI
As written above I am trying to connect the GUI via the traffic trunk and for emergency purposes via the management interface port/trunk as well. Lots of problems there as well:
Scenario-1
VLAN-1 has IP-addresses defined and VLAN-2 as well. The Default gateway is related to VLAN-2
- that does not work for VLAN1 since the traffic is routed back via VLAN-1
Scenario-2
VLAN-1 is on interface-1 (vlan-1a) and on interface-2 (vlan-1b) as well, so I decide to define a bridge (bridge1)
- I assigned vlan-1a and vlan1b to that bridge
- and assigned an IP-address to the bridge
- after that I can assign the bridge IP to the GUI
However ...... I could not access the GUI via that IP at all !!
As example, at the moment I can only use the traffic-vlan (which have the default route) to reach the GUI. Not what I want and not secure.
To summarize:
- the GUI is IMHO very weird
- a couple of things do not work at all (hopefully I am wrong)
Louis