Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    7100 1u vlan addition question

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    25 Posts 3 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rcoleman-netgate Netgate @hescominsoon
      last edited by rcoleman-netgate

      @hescominsoon You can remove the VLANs from the ports and thus kill the switch, but I would not break the LAGG.

      You need VLANs to pass (tagged) on 9 and 10 to get the ports to talk back to the pfSense software. If you want to add a NIC to the 7100 and not use the LAGG0 that would give you the very function you want.

      Or I would suggest you look at the 4100, 6100 or 8200 instead of using a 7100 for your needs.

      You can drop all the VLANs if you wish as well and limit them to a single port through the VLANs tab on Interfaces->Switches. But be careful how you proceed as if that is your primary connection interface changes here can result in loss of access to the GUI and you will need to use the CLI to roll back config changes.

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      1 Reply Last reply Reply Quote 1
      • H
        hescominsoon
        last edited by

        unfortunately i already purchased the 7100 and cannot return it.

        R 1 Reply Last reply Reply Quote 0
        • R
          rcoleman-netgate Netgate @hescominsoon
          last edited by

          @hescominsoon Tell me what you want to do... Default config on the 7100 is...

          WAN on ETH1

          LAN on ETH2-8

          https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100-1u/configuring-the-switch-ports.html

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          1 Reply Last reply Reply Quote 0
          • H
            hescominsoon
            last edited by

            This post is deleted!
            R 1 Reply Last reply Reply Quote 0
            • R
              rcoleman-netgate Netgate @hescominsoon
              last edited by

              @hescominsoon said in 7100 1u vlan addition question:

              all i want to do is put vlans 10 and 20 on the internal interface...

              Interfaces->Assignments ... VLAN tab

              Add VLANs to LAGG0.
              That's covered here: https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100-1u/configuring-the-switch-ports.html#id1

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              1 Reply Last reply Reply Quote 1
              • H
                hescominsoon
                last edited by

                let's just get vlans 10 and 20 to work on the internal interface...if it spans multiple physical ports i'l not worry a bout it

                R 1 Reply Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @hescominsoon
                  last edited by

                  @hescominsoon said in 7100 1u vlan addition question:

                  if it spans multiple physical ports i'l not worry a bout it

                  Until you do the SWITCH VLAN part of the config the VLANs won't do much of anything on LAGG0.

                  You have to tell the switch hardware (which is not part of the pfSense base software) to assign the VLANs to something, too

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  1 Reply Last reply Reply Quote 1
                  • H
                    hescominsoon
                    last edited by

                    This post is deleted!
                    R 1 Reply Last reply Reply Quote 0
                    • R
                      rcoleman-netgate Netgate @hescominsoon
                      last edited by rcoleman-netgate

                      @hescominsoon said in 7100 1u vlan addition question:

                      is it safe to assume the 4100, 6100, and 8200 do not have this "feature"?

                      They do not have switches built-in, correct.

                      It is well documented that the following models have built-in switches:
                      1100, 2100, 3100*, 7100*

                      The following devices do use all discrete ports:
                      5100*, 4100, 6100, 8200

                      * denotes models are no longer sold by Netgate.

                      I recommend you contact sales@netgate.com for assistance in picking the best firewall for your needs.

                      Isolating the two VLANs on ports on the 7100 and not using anything else is a trivial setting and will not deter from the throughput or performance of a 7100. But you can also add a NIC to your 7100 with the addition of a PCI Riser Card for $46 from our store. I have these in both of my own personal 7100s for future PCIe expansion. The ports that you get from there are discrete. As are the IX0 and IX1 ports on the front of your 7100.

                      Ryan
                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                      Requesting firmware for your Netgate device? https://go.netgate.com
                      Switching: Mikrotik, Netgear, Extreme
                      Wireless: Aruba, Ubiquiti

                      H 1 Reply Last reply Reply Quote 1
                      • H
                        hescominsoon @rcoleman-netgate
                        last edited by

                        @rcoleman-netgate i am actually very familiar with sizing them I've just been living in the 15xx and abovve..:) i'll just make sure i do not use the swithced appliances.

                        one more thing...i am putting this firewall into a unifi network. with the internal untagged traffic being on vlan 4xx on the 7100 will i need to set the management lan(which wll be on 192.168.1.1/24) on the same 4xxx vlan or can i remove the base vlan from the intern lan port and have it pass untagged traffic and stack the 10 and 20 vlans on it?

                        R 1 Reply Last reply Reply Quote 0
                        • R
                          rcoleman-netgate Netgate @hescominsoon
                          last edited by

                          @hescominsoon said in 7100 1u vlan addition question:

                          can i remove the base vlan from the intern lan port and have it pass untagged traffic and stack the 10 and 20 vlans on it?

                          The VLANs are untagged on those ports (look at the VLANs tagging page) 8ccd0498-eb84-49d5-ba8c-a696fa7d31a4-image.png
                          so they will pass untagged traffic on 4091 and 4090 respectively.

                          To add 10 and 20 to a port just add the VLAN for those tagged on its port and 9 and 10 and that's completed.

                          Ryan
                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                          Requesting firmware for your Netgate device? https://go.netgate.com
                          Switching: Mikrotik, Netgear, Extreme
                          Wireless: Aruba, Ubiquiti

                          H 1 Reply Last reply Reply Quote 0
                          • H
                            hescominsoon @rcoleman-netgate
                            last edited by

                            @rcoleman-netgate and this seems to be where we are miscommunicating. i want vlans 10 and 20 to be on the same physical interface as lan(192.168.1.1/24)....how can i do this?

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              rcoleman-netgate Netgate @hescominsoon
                              last edited by

                              @hescominsoon The documentation is quite well written with how to do that, in addition to the link I made about isolating a port, you can do that but choose, instead, to TAG the port traffic and skip the PVID step.

                              Ryan
                              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                              Requesting firmware for your Netgate device? https://go.netgate.com
                              Switching: Mikrotik, Netgear, Extreme
                              Wireless: Aruba, Ubiquiti

                              H 1 Reply Last reply Reply Quote 0
                              • H
                                hescominsoon @rcoleman-netgate
                                last edited by

                                @rcoleman-netgate said in 7100 1u vlan addition question:

                                @hescominsoon The documentation is quite well written with how to do that, in addition to the link I made about isolating a port, you can do that but choose, instead, to TAG the port traffic and skip the PVID step.

                                i think have it...added 10 and 20 t0 9t and then added the vlans from lagg0 into the assignments...

                                H 1 Reply Last reply Reply Quote 0
                                • H
                                  hescominsoon @hescominsoon
                                  last edited by

                                  @hescominsoon said in 7100 1u vlan addition question:

                                  @rcoleman-netgate said in 7100 1u vlan addition question:

                                  @hescominsoon The documentation is quite well written with how to do that, in addition to the link I made about isolating a port, you can do that but choose, instead, to TAG the port traffic and skip the PVID step.

                                  i think have it...added 10 and 20 t0 9t and then added the vlans from lagg0 into the assignments...

                                  7100 switch.png 7100assignments.png

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    hescominsoon
                                    last edited by

                                    so will this config give me access to the 10 and 20 on eth2?

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      rcoleman-netgate Netgate @hescominsoon
                                      last edited by

                                      @hescominsoon Not at all.

                                      You need to tag ports 2, 9 and 10 on VLANs 10 and 20 to get it on port 2.

                                      See all my VLANs tagged on 2, 9 and 10.
                                      49a9c38f-459a-4ffe-9da8-c45ce10c0694-image.png

                                      Ryan
                                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                      Requesting firmware for your Netgate device? https://go.netgate.com
                                      Switching: Mikrotik, Netgear, Extreme
                                      Wireless: Aruba, Ubiquiti

                                      H 1 Reply Last reply Reply Quote 0
                                      • H
                                        hescominsoon @rcoleman-netgate
                                        last edited by

                                        @rcoleman-netgate 7100 switch vlan2.png

                                        1 Reply Last reply Reply Quote 2
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          Yup, that looks good. You will see tagged packets from valn 10 and 20 on Eth2 and internally on lagg0.

                                          H 1 Reply Last reply Reply Quote 1
                                          • H
                                            hescominsoon @stephenw10
                                            last edited by

                                            @stephenw10 thanks for the tips..it's appreciated..:) Once i you pointed out the switch wasn't part of pfsense it made more "sense"..:)

                                            R 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.