Segmenting a network into VLANs is the single most useful thing a small firewall can do: guests, cameras, servers and staff stop sharing a broadcast domain and you get a chokepoint where policy is enforced. On pfSense CE 2.9 the firewall side is straightforward; most problems come from the switch configuration and from mismatched expectations about which port is tagged and which is not. This guide builds three VLANs on one trunk port: 10 for staff, 20 for servers and 30 for guests.
Table of Contents
Short answer: On pfSense go to Interfaces » Assignments » VLANs, create VLAN tags 10, 20 and 30 on the LAN parent interface, assign each as a new interface, enable it with a static IPv4 address, and turn on DHCP under Services » DHCP Server for each. Then add firewall rules per VLAN interface, because new interfaces have no rules and block everything. On the switch, set the port facing pfSense as a trunk carrying tagged 10, 20 and 30, and set edge ports as untagged access ports in the right VLAN.
Create the VLANs on pfSense
Go to Interfaces » Assignments and open the VLANs tab. Add an entry for each tag with the parent interface set to the physical port that will become the trunk, typically igc1. Keep the description short and meaningful: staff, servers, guests. Back on the Interface Assignments tab, the new devices appear as igc1.10, igc1.20 and igc1.30; click Add for each, then open the resulting OPT interfaces, enable them, rename them to match the descriptions, and set the IPv4 configuration type to Static with addresses such as 10.0.10.1/24, 10.0.20.1/24 and 10.0.30.1/24. Save and apply after each one.
Decide what happens to the untagged LAN on the parent port. Leaving it as the management network on 192.168.1.0/24 is common and gives you a fallback if a VLAN misbehaves. Mixing tagged and untagged traffic on the same parent works on most NICs, but some cheap adapters strip tags in hardware; if VLANs never pass traffic, disable VLAN hardware filtering under System » Advanced » Networking.
DHCP and DNS per VLAN
Under Services » DHCP Server there is now a tab per interface. Enable each, set a range inside the subnet, and point DNS at the interface address so the Unbound resolver on pfSense answers. Under Services » DNS Resolver make sure the new interfaces are selected in the network interfaces list, otherwise clients get a DHCP lease but cannot resolve names.
Firewall rules between VLANs
New interfaces have an empty rule set and pfSense denies by default. Create an alias called rfc1918 covering 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, then on each VLAN tab add rules in this order: allow DNS and NTP to the interface address, block anything to rfc1918 except what the segment needs, and allow everything else to any. For the guest VLAN also block access to the firewall’s own management ports with an explicit rule above the allow. Servers usually need inbound rules on the staff VLAN allowing specific ports to the server subnet. Apply changes and remember the anti-lockout rule only protects LAN, not the VLANs.
Configure the managed switch
Terminology varies by vendor but the model is the same. The port connected to pfSense’s parent interface becomes a trunk, carrying VLANs 10, 20 and 30 tagged, and the management VLAN untagged if you kept one. Edge ports become access ports: a member of exactly one VLAN, untagged, with the PVID set to that VLAN so incoming frames are tagged correctly. Ports feeding access points that broadcast several SSIDs are trunks too, with the AP doing the tagging. On a typical CLI the trunk looks like this:
interface GigabitEthernet1/0/1
switchport mode trunk
switchport trunk allowed vlan 1,10,20,30
switchport trunk native vlan 1
interface GigabitEthernet1/0/5
switchport mode access
switchport access vlan 30
Web-managed switches express the same thing as a VLAN membership grid with T, U and blank cells; read T as tagged and U as untagged, and make sure the PVID column matches the U cell.
Verify and common pitfall
Plug a laptop into an access port in VLAN 30, confirm it receives an address from the 10.0.30.0/24 pool, resolves names and reaches the internet, and then confirm it cannot ping 10.0.20.1 or a staff device. On pfSense, Status » DHCP Leases shows the lease on the right interface and Diagnostics » Packet Capture on igc1.30 shows the tagged frames arriving. From the shell, ifconfig igc1.30 confirms the VLAN device exists and carries the address.
The most common pitfall is a native VLAN mismatch: pfSense expects untagged frames to be the management LAN while the switch has a different PVID on the trunk, so management stops working the moment the trunk is enabled. Change trunk settings from a port that is not the trunk, and keep console access to the switch until everything is confirmed. If you plan to filter DNS on the new segments, Configure pfBlockerNG for DNS and IP blocking picks up from here.
PfSense VLAN at a glance

Official documentation: pfSense documentation, Linux man pages.
Related guides: Install OPNsense 26.7 and set up basic firewall and NAT rules · Install pfSense CE 2.9 step by step with the network installer and ZFS · Troubleshoot MTU, fragmentation and slow VPN throughput.
Frequently asked questions
Does pfSense VLAN configuration work the same on OPNsense?
Largely yes. OPNsense creates VLANs under Interfaces » Devices » VLAN, assigns them the same way and needs per-interface firewall rules just like pfSense; the switch side is identical.
How long does it take to add a VLAN to pfSense?
Creating the tag, assigning the interface, enabling DHCP and writing rules takes about ten minutes per VLAN once the trunk exists. The switch port changes take a similar time.
Can I undo a VLAN change that broke connectivity?
Yes. Diagnostics » Backup & Restore keeps a configuration history, so you can revert to the previous version, or use the console option to reset interface assignments and reach the WebGUI on the untagged LAN.