Unifi + pfSense weirdness. ARP, DHCP

Afternoon all. I manage roughly 60+ pfSense and Unifi setups of various sizes and complexities. Some sites are years old, some sparkling fresh. All now exhibit the same behaviors.

By now all of them are fully up to date with pfSense+ or 2.7.2 with the Unifi Equipment linked up and managed with a hosted 8.6.9 Controller.

The weirdness: As I’ve updated the unifi controller the pfsense devices at all of the sites no longer appear in the client list of devices, their macs report as offline, they do not appear on the port list on port management for their respective rj-45 plugs, nor does DHCP Guarding work. Clients are not issued ips.

If I try to hunt for the firewall by mac it does show up as offline. Meaning the controller used to see it.

As mentioned above everything “appears” to be setup correctly, the networks all still route. VLANS are VLANing. I do have all the VLANS assigned to the default LAN device. igb1, em1, ix1 so the vlan would be igb1.14 or ign1.2000
etc etc depending on the age of the firewall device. Older sites where I had the VLANS on OPT2 or OPT3 might not have exhibited this issue, I’ll have to lab this up and see if that’s still the case.

With DHCP guarding enabled, Unifi APs would get an ip, but some client devices do not. Especially on none default vlans.

I haven’t found anything enlightening in the firewalls, or capturing traffic. The DHCP request would come in, go out, and not get to the client.

As far as the pfsense firewall disappearing from Unifi’s list of devices, baffled by that. I do see several arp requests come in now and then asking who has the gateway ip.

At this point I’m starting to run out of ideas.

Thoughts?

I have never really had a need to look for my pfsense firewalls in the UniFi client list but after reading this post I did and they are not showing online. No idea why, but since everything is working I don’t plan to spend much time on figure out why UniFi’s discovery tool does not list it.

Agreed, it’s working, but why is it working? And why did it change from older versions? These are the things that keep me up at night. :smiley:

It’s a lose end that makes me think something else is amiss. Today I see one setup that has roughly 200 some odd clients active each day is experiencing what feels like a related issue. The Clients on one VLAN just stop working, they get an ip but can’t get to the internet past the firewall.

Still early in diagnosing this problem as it’s very sporatic.

It’s almost as if this particular “guest” VLAN can’t resolve it’s own gateway which is also it’s DHCP server.

Anyway, will see what I see and figure out if it’s related.

I’m glad to hear I’m not the only one seeing that the pfsense device is “gone” from network discovery. Going to assume that’s the case for everyone else on similar versions