• Cloning MAC Address

    4
    0 Votes
    4 Posts
    2k Views
    GrimsonG
    https://forum.netgate.com/topic/139859/sg-1100-running-real-vlans/8 the SG-1100 is essentially a router-on-stick in one case. You can't simply change the MAC of just the WAN port, as this is a switch port. You can assign the parent interface mvneta0 and then change it's MAC, which will affect all ports and create a conflict with the original device if it's still connected. So either get rid of the original device, put it on a different L2 if possible, register the SG-1100 MAC with your provider or return the SG-1100 and get a device with more dedicated interfaces. It really pays to research the hardware before you buy it.
  • VLAN Routing Issue

    8
    0 Votes
    8 Posts
    831 Views
    ?
    @johnpoz How should I go about troubleshooting duplicate packets? I read the following link, as well as the link about Asymmetric Routing, but not sure if it applies. https://docs.netgate.com/pfsense/en/latest/firewall/troubleshooting-blocked-log-entries-for-legitimate-connection-packets.html
  • Add NIC as extra LAN-port?

    Moved
    3
    0 Votes
    3 Posts
    516 Views
    T
    @derelict said in Add NIC as extra LAN-port?: Get a switch. Leave igb3 available for use as a router port. If you insist on doing that look at bridging igb1 and igb3 into a bridge and use the bridge for LAN. I got a 5-port switch today which is in LAN but it's full, and I want to buy a Ubiquiti PoE switch 8-60W (about $100) but I only need 1 port so therefore it's not really negotiable to buy one just for I need one extra port lol So I thought if it's easy to use it as a LAN-port in the meantime...
  • Connect 4 physical ports to the same switch

    Moved
    9
    0 Votes
    9 Posts
    1k Views
    DerelictD
    If you want all 4 ports to go to the same switch on 4 different broadcast domains then just connect all 4 ports to 4 untagged switch ports on 4 separate switch VLANS. Pretty much nobody would do that because VLANs are much more flexible but if that's what you want, knock yourself out.
  • Moving device to new VLAN setup not working

    17
    0 Votes
    17 Posts
    2k Views
    K
    @johnpoz said in Moving device to new VLAN setup not working: you don't have any vlan 2 setup on your switch from what you posted You're right I don't have any vlan 2 setup now but from my readings for best practice if a vlan is created e.g.for port 3 for NAS then any other connection e.g. port 2 wlan interface 192.168.2.XXX should also have a vlan setup made. Correctly if I'm wrong. If i want the NAS device to go outside the network (e.g. internet) how will this work if it no longer has a wifi connection since the wifi router in on subnet 192.168.2.2 Do I have to NAT the NAS device to the wifi router? You have to create rules on those to allow what you want. I have a all open rule setup on the NAS interface but still was't able to ping the device using pfsense box under diagnostics however the gateway 192.168.30.1 succeeded. It may be my NAS device (wd mycloud ext2 ultra) giving me the problem. DHCP leases is displaying an ip for the device but it is showing it as offline. The unit itself is showing 3 blue lights indicating all is online.
  • Build router with pfSense

    2
    0 Votes
    2 Posts
    487 Views
    JKnottJ
    @njanja said in Build router with pfSense: What is the purpose of buying a network card with multiple ports.On almost every forum they recommend to me Use VLANs Link aggregation, to increase available bandwidth. You might also want physically separate networks.
  • 1WAN & 2 LAN on SG-1100?

    4
    0 Votes
    4 Posts
    523 Views
    DerelictD
    Not really. It works fine. The default configuration is DHCP WAN and 192.168.1.1/24 on LAN. All you have to do is edit Interfaces > OPT1, enable it, and number it with something other than what is on any other interface (like 192.168.2.1/24), add firewall rules to OPT1 to pass the traffic you want to allow, and enable a DHCP server on OPT1.
  • IGMP Not working

    1
    0 Votes
    1 Posts
    303 Views
    No one has replied
  • Sanity Check - VLAN or Subnets to seperate a single WiFi computer

    8
    0 Votes
    8 Posts
    908 Views
    J
    Thanks for the advice. I found some of it before I read your message but your message was right to the point. I had to read your message a few times to understand, the third rule was kicking my butt because I didn't include the DNS in the first rule. While this type of stuff is probably easy for many people, my goodness it's a lot to think about and keep track of. I mean, I do understand it but dang! So it looks like I have a VLAN that is isolated from everything except the printer. I will still use that 8 port switch as I desire to run some VM's on my ESXi machine on a separate VLAN and I need the switch that handles VTAGS to go between the pfSense computer and ESXi computer, so there was a benefit to having purchased it.
  • [RESOLVED] rate of data transfer between different vlans is extremely low

    4
    0 Votes
    4 Posts
    1k Views
    ivanildolbI
    [RESOLVED] The problem was in Traffic Shaper .. When I prioritized the traffic on the network using the wizard, I reported the speed of the WAN link, in this case, 20 mbps. So, as I checked, pfsense limited the network bandwidth to 20 mb (2.5 MB), including LAN and WAN. As this information is not made explicit in pfsense, I only notice when I deleted Traffic Shaper and set it up again. The solution I found was to report the maximum capacity of the circuit (1 Gb) to use the entire internal network bandwidth. Otherwise, the entire network is limited to the speed of the WAN link. I had done this configuration for a long time, but since the network was not segmented, the internal traffic was not through pfsense, so when I created vlans, pfsense limited the band ..
  • Post Installation , LAN not working

    1
    0 Votes
    1 Posts
    203 Views
    No one has replied
  • New to networking; can't get traffic over VLAN

    7
    0 Votes
    7 Posts
    856 Views
    DerelictD
    Yes. The rules are the same whether they are on em3 or em3.2
  • Interfaces for LAN vs VLAN

    6
    0 Votes
    6 Posts
    667 Views
    johnpozJ
    its a good obfuscation then - looks like actual screen shot! Better to mention you obfuscated or use documented example networks and mention that ;) 192.0.2/24 198.51.100/24 203.0.113/24 2001:DB8::/32 Just saying ;) You would be surprised at some of the stuff you see around here people doing for real ;) Or just block out part of the actual address so its clear is obfuscation..
  • make pfsense box a 10GbE switch

    21
    0 Votes
    21 Posts
    4k Views
    johnpozJ
    Oh I see he was put on a time out ;) I would of made it longer.. Maybe he can go demand info on how to do something that makes no sense on facebook or reddit.. But with such a demanding attitude he won't get much help over there either..
  • pfSense SSH connection between 2 different LAN's dropping after 1 minute

    4
    0 Votes
    4 Posts
    575 Views
    chippey5C
    Solved It was a layer 8 issue - between the chair and the monitor. Static routing on LAN2 was incorrect. Reconfigured the static route (as per the settings in my previous reply) and connections are not dropping anymore.
  • Routing out to Internet through pfSense HW

    routing dns resolver rules internet
    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    Using LAN is OK as long as you understand that you almost certainly shouldn't put anything but other routers with full infrastructure routing knowledge on LAN.
  • Convert Current Network to VLANs

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    If you tell pfSense to tag on VLAN 5, and the switch port connected to that has tagged VLAN 5, then your workstation needs to be connected to an untagged VLAN 5 port on the switch to have layer 2 connectivity to pfSense. That's the whole point.
  • LAGG (LACP) - UniFi Switch (16XG)

    lagg lacp unifi
    43
    0 Votes
    43 Posts
    17k Views
    DerelictD
    OK then the MAC address should be spoofed. The MAC address on the LAGG should also be the spoofed MAC. That is exactly what would be expected.
  • Access for one host to VLAN

    6
    0 Votes
    6 Posts
    720 Views
    DerelictD
    Please post your rule set not a summary of what you think is there. You left out a lot of key information.
  • 7100-1U - Switch ports LAGG problem

    switch lagg bug
    3
    0 Votes
    3 Posts
    1k Views
    RicoR
    @Asamat: Your 'this Bug' URL is this thread here. -Rico
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.