Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 2100 - setup question

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    67 Posts 6 Posters 10.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Yes. You can do that and you don't need any separate managed switches to do it. As Steve said the VLANs are all internal to the 2100 so no problem there.

      Steve

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @netboy
        last edited by

        @netboy I'm not very well caffeinated yet, but you only want two networks, correct? So you only need one VLAN. The base-not-configured ports are all one interface out of the box because it's a switch. You're trying to separate two of them.

        Or if you follow Ryan's linked directions to the letter to isolate one port, and plug in a cheap 5 port switch, you'd have 3 ports +4 (1->4 remaining switch) ports.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        N 1 Reply Last reply Reply Quote 0
        • N
          netboy @SteveITS
          last edited by netboy

          @steveits
          Now I am trying to implement my idea and seek help.

          I have changed my default IP for router from 192.168.1.1. to 192.168.0.1.

          Can somebody show me screenshots to achieve the following:

          • Create 2 subnets 192.168.0.XXX & 172.16.0.XXX

          • Assign physical port LAN 1 & 2 to 192.168.0.XXX and assign physical port LAN 3 & 4 to 172.16.0.XXX

          Please note that I do not use VLAN's - The idea is to connect LAN 1 & 2 to unmanaged switches and so is LAN 3 & 4 to another set of unmanaged switches.

          I want to take baby steps as I go so that I can get help from this forum. Thanks

          S 1 Reply Last reply Reply Quote 0
          • N netboy referenced this topic on
          • S
            SteveITS Galactic Empire @netboy
            last edited by

            @netboy LAN is already assigned to 192.168.0.1 so ports 1 and 2 are done.

            If you follow https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/configuring-the-switch-ports.html that will isolate port 4 and you can assign it 172.16.0.1. I would start with that, and worry about port 3 in a second step.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            N 1 Reply Last reply Reply Quote 1
            • N
              netboy @SteveITS
              last edited by netboy

              @steveits Hey steveits, I have created the port 4 as per the url you provided. Now I want this to apply to port 3 as well. Can you kindly let me know how I go about doing this? Do I follow identical process for port 3 as well - I basically want port 3 and 4 on the same subnet 172.16.0.1/24

              N 1 Reply Last reply Reply Quote 0
              • N
                netboy @netboy
                last edited by netboy

                @netboy
                45e7ceaa-16a8-4aed-b2a2-1e94a385e078-image.png

                My guess is based on the screenshot above:

                • edit VLAN group 0 and REMOVE 3

                • edit VLAN group 1 and ADD 3

                Will the above work? The idea is to make 3 & 4 in subnet 172.16.0.1/24

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by stephenw10

                  Yes, do that and also change the PVID on port 3 to 4084 to match port 4.

                  Screenshot from 2022-10-30 13-51-36.png

                  Steve

                  N 1 Reply Last reply Reply Quote 0
                  • N
                    netboy @stephenw10
                    last edited by

                    @stephenw10
                    Thank you.
                    This is how it looks now:

                    3ed92305-c6b6-47c1-8c7b-db60f2f92551-image.png

                    add2a8d0-bf76-4de9-a88d-ace8b1b2efee-image.png

                    Does the above sound OK ?

                    N 1 Reply Last reply Reply Quote 0
                    • N
                      netboy @netboy
                      last edited by

                      @netboy As soon as I did the above my Web GUI is VERY SLOW (I was trying to apply static address to certain MAC addresses). Has the port / switch configuration messed up something?

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Yes, that's correct for the switch config.

                        As long as you have the mvneta1.4084 VLAN interface also configured and assigned it should work as expected.

                        Steve

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          netboy @stephenw10
                          last edited by

                          @stephenw10
                          Get the following message:
                          Hmmm… can't reach this page
                          192.168.0.1
                          took too long to respond

                          1 Reply Last reply Reply Quote 0
                          • N
                            netboy
                            last edited by

                            @netboy 372d22f8-ac5e-41a1-a875-b653c4f7ebfd-image.png

                            This is what I have

                            N 1 Reply Last reply Reply Quote 0
                            • N
                              netboy @netboy
                              last edited by netboy

                              @netboy Definitely something is wrong... the web GUI is very slow......Any suggestions?

                              N 1 Reply Last reply Reply Quote 0
                              • N
                                netboy @netboy
                                last edited by

                                @netboy When I removed the ethernet jack from port 3 the web gui works normal. Is there something I am missing in configuring port 3?

                                R 1 Reply Last reply Reply Quote 0
                                • R
                                  rcoleman-netgate Netgate @netboy
                                  last edited by

                                  @netboy What was plugged into port 3 exactly? And if it was a switch what was THAT plugged in to?

                                  What it sounds like to me, after a quick glance over the thread, is you might have a loop going -- your main network feeding back into the new VLAN... but that's just an educated guess.

                                  Ryan
                                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                  Requesting firmware for your Netgate device? https://go.netgate.com
                                  Switching: Mikrotik, Netgear, Extreme
                                  Wireless: Aruba, Ubiquiti

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Yes, if you had the switch connected to ports 3 and 4.
                                    The switch in the 2100 does not support STP to prevent that.

                                    Steve

                                    N 1 Reply Last reply Reply Quote 0
                                    • N
                                      netboy @stephenw10
                                      last edited by netboy

                                      @stephenw10 What is STP? Yes port 3 and port 4 are connected to "separate" unmanaged switches so that anything connected to the switch has the 172 subnet.

                                      This was my idea right from beginning.

                                      Are you telling me that I cannot connect any switch to port 3 and 4?

                                      Please note that port 3 is disconnected right now and port 4 is connected to a unmanaged switch. This configuration does not choke up web GUI but once I connect port 3 to a switch the web GUI chokes up.

                                      Kindly advice

                                      R 1 Reply Last reply Reply Quote 0
                                      • R
                                        rcoleman-netgate Netgate @netboy
                                        last edited by

                                        @netboy said in Netgate 2100 - setup question:

                                        What is STP?

                                        Spanning Tree Protocol.

                                        If you have a link from one network going into another, it cannot detect that and mitigate the cross-talk.

                                        You can connect a switch to those ports, yes, but I was asking you what the rest of those are connected to -- is it possible that one of those switches is connected to port 1 or 2?

                                        Ryan
                                        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                        Requesting firmware for your Netgate device? https://go.netgate.com
                                        Switching: Mikrotik, Netgear, Extreme
                                        Wireless: Aruba, Ubiquiti

                                        N 1 Reply Last reply Reply Quote 0
                                        • N
                                          netboy @rcoleman-netgate
                                          last edited by

                                          @rcoleman-netgate You are on the money!!! I had daisy chained the switch which was in port 1 and port 3 because my standby router had only one port and was waiting for 2100 to arrive. Newbie mistake!!! Thanks for pointing this out!

                                          I have now removed the daisy chain ethernet cable connecting switches which were in port 3 and port 1.

                                          Web gui works fine.

                                          Thank you for baby sitting me!

                                          R 1 Reply Last reply Reply Quote 1
                                          • R
                                            rcoleman-netgate Netgate @netboy
                                            last edited by

                                            @netboy Yeah, don't do that :) It does bad things -- as you have seen. :)

                                            Ryan
                                            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                            Requesting firmware for your Netgate device? https://go.netgate.com
                                            Switching: Mikrotik, Netgear, Extreme
                                            Wireless: Aruba, Ubiquiti

                                            N 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.