Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Five lan ports and nine vlans.

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rcoleman-netgate Netgate @stampeder
      last edited by

      @stampeder said in Five lan ports and nine vlans.:

      I can tag several vlans in the netgear switches, I'm just not sure how to handle these when I get to the Netgate router.

      The same way -- if the port the Netgate connects to is tagged then they need to be tagged on pfSense as well.

      https://docs.netgate.com/pfsense/en/latest/vlan/index.html

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      S 1 Reply Last reply Reply Quote 0
      • S
        stampeder @rcoleman-netgate
        last edited by

        @rcoleman-netgate So then each of the lan ports can be treated as an independent trunk port, similar to a Cisco router?

        R 1 Reply Last reply Reply Quote 0
        • R
          rcoleman-netgate Netgate @stampeder
          last edited by

          @stampeder They're not switch ports -- they're discrete interfaces. LACP a couple together to a switch that supports LACP. Put everything on the LACP interface.

          https://docs.netgate.com/pfsense/en/latest/interfaces/lagg.html

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          1 Reply Last reply Reply Quote 0
          • AndyRHA
            AndyRH @stampeder
            last edited by

            @stampeder Yes. I have a 7100 and I use one 10Gb NIC to my switch with 5 VLANs. Setup your switch correctly and it works well. My goal was to use as few switch ports as possible.

            You may find your network usage is low enough on some VLANs that you can decrease the ports you are using by going beyond doubling up..

            o||||o
            7100-1u

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yes, you can tag as many VLANs as you like on each interface. Within reason.

              What you can't do is put the same VLAN on two interfaces. I.e. em3.20 is not the same VLAN as em4.20 even if they use the same tags.

              But it sounds like you're doing the first thing so that should be OK.

              I would also look at using two interfaces in an LACP lagg to the switch and putting all the VLANs on that.

              Steve

              S 2 Replies Last reply Reply Quote 0
              • S
                stampeder @stephenw10
                last edited by

                @stephenw10 Thanks for the reply.
                What I am actually trying to accomplish is VLAN routing on the FW 7541. As it has six opt ports I thought I could put say my vlan 60 and vlan 99 vlans on the same "trunk" port from my managed switch.
                Since you point out that it is possible, my issue now is how to actually do it within the device?

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @stampeder
                  last edited by

                  @stampeder said in Five lan ports and nine vlans.:

                  my issue now is how to actually do it within the device?

                  What are you asking how to put more than 1 vlan on a physical interface?

                  vlans.jpg

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    stampeder @johnpoz
                    last edited by

                    @johnpoz Cool! So, I can also apply FW rules to each of these vlans separately?
                    Is there a document or writeup on this whole procedure from Netgate?
                    Sorry, I'm too used to Cisco........

                    1 Reply Last reply Reply Quote 0
                    • S
                      stampeder @stephenw10
                      last edited by

                      @stephenw10 One more thing. I don't need to aggregate any ports as the traffic on the ones I want to "trunk" is low and the interfaces are already 1G. But thanks.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @stampeder
                        last edited by

                        @stampeder no you don't need to create a lagg, not really a fan of laggs to be honest because you don't have control over what physical interface traffic might flow. lagg is good if don't care about that and your goal is redundancy of physical ports.

                        Yes once you create a vlan on pfsense - it would have its own firewall rules.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 1
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Yeah the VLAN interfaces are treated exactly like any other interface; you can apply firewall rules to them individually.

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.