Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    advice on physical layout plans for new PFSsense router setup

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 6 Posters 1.8k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      alexeymohr @stephenw10
      last edited by

      @stephenw10 Yeah I've got two Unifi USW-24-POE switches, a U6-Lite access point, and a U6-LR access point (all managed by a CloudKey Gen2) - the plan is to have all VLANs be available on each of those devices. None is an L3 device.

      My initial plan was to have each NIC on the Protectli pfSense router dedicated to an individual VLAN, but it seems like maybe I'd be better off just aggregating a few of those ports and then trunking all the VLANs at once?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • stephenw10S Online
        stephenw10 Netgate Administrator
        last edited by

        Yup, that's what I would do. Use two ports there to create an LACP LAGG to the first switch and trunk all the VLANs across that.

        Steve

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator @alexeymohr
          last edited by

          @alexeymohr said in advice on physical layout plans for new PFSsense router setup:

          but it seems like maybe I'd be better off just aggregating a few of those ports and then trunking all the VLANs at once?

          You loose control of which physical interface is actually used for traffic - and "depending" you could end up with hairpin traffic over the same physical interface for intervlan traffic.

          I personally prefer more control and like placing vlans on specific physical interfaces so I am sure that intervlan traffic where there is a lot of it not possible to hairpin over the same physical interface.

          If you have the ports not a problem doing this... Only thing lagg/lacp gets you is if 1 of the interfaces fail, cable fails or unplugged etc you don't loose connectivity.. I like control more than redundancy for interface failure..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • MarinSNBM Offline
            MarinSNB
            last edited by

            Does anyone have any links/references to a step-by-step guide on how to achieve this setup using switches for VLANs (with/without LAGG)? Thanks!

            Netgate 6100 Max pfSense+
            โ€”>Unifi Aggregation/24 Pro PoE/24 PoE Enterprise switches
            โ€”> UCK2+
            โ€”> 3x U6E APs

            1 Reply Last reply Reply Quote 0
            • stephenw10S Online
              stephenw10 Netgate Administrator
              last edited by

              There are a bunch of video walk throughs on YouTube. Tom Lawrence's probably the best. For example his LAGG tutorial: https://www.youtube.com/watch?v=VULKulpXBYU

              johnpozJ MarinSNBM 2 Replies Last reply Reply Quote 1
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator @stephenw10
                last edited by

                @stephenw10 dude - bet you beer that is spammer.. Look at his other posts..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                MarinSNBM JKnottJ 2 Replies Last reply Reply Quote 0
                • stephenw10S Online
                  stephenw10 Netgate Administrator
                  last edited by

                  Meh, could be. ๐Ÿ˜‰

                  1 Reply Last reply Reply Quote 0
                  • MarinSNBM Offline
                    MarinSNB @stephenw10
                    last edited by

                    @stephenw10 thank you so much!

                    Netgate 6100 Max pfSense+
                    โ€”>Unifi Aggregation/24 Pro PoE/24 PoE Enterprise switches
                    โ€”> UCK2+
                    โ€”> 3x U6E APs

                    1 Reply Last reply Reply Quote 0
                    • MarinSNBM Offline
                      MarinSNB @johnpoz
                      last edited by

                      @johnpoz Was this intended for me?

                      Netgate 6100 Max pfSense+
                      โ€”>Unifi Aggregation/24 Pro PoE/24 PoE Enterprise switches
                      โ€”> UCK2+
                      โ€”> 3x U6E APs

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ Offline
                        JKnott @johnpoz
                        last edited by

                        @johnpoz said in advice on physical layout plans for new PFSsense router setup:

                        stephenw10 dude - bet you beer that is spammer.. Look at his other posts.

                        Just his question made me wonder if he's serious. Physical layout? Really?

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.