Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't get pfSense to communicate with Ubiquiti switch

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    24 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @mcury
      last edited by

      @mcury yeah it works.. And price isn't bad, and sure can not complain about free ;)

      Not overly impressed with how its managed, not really a fan of how unifi does management overall for their switches, etc. And its underwhelming from feature set, etc..

      Mine is currently just sitting on a shelf, there was a thread around here somewhere when I fired it up - it spews a lot of noise.. I think I was seeing issues with lldp or something if I recall.. I believe I figured out how to turn it off. Or it wasn't showing up correctly in the controller for where it was placed or something.

      Only place I would most likely use it is behind my TV where I have a pi as well on a different vlan.. But the little tplink currently there works fine.. If it fails I would prob use the mini as replacement. I currently don't have any other use for it.

      But I know when they first came out with their switch line - the lack of L3 was causing a lot of complaints.. Nice that they added it to their enterprise and pro lines.. But those are not cost advantageous either..

      We need to understand what switch the OP is using to move forward if it can actually do L3 at all.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply Reply Quote 0
      • M
        mcury @johnpoz
        last edited by

        @johnpoz said in Can't get pfSense to communicate with Ubiquiti switch:

        But those are not cost advantageous either..

        Indeed..

        We need to understand what switch the OP is using to move forward if it can actually do L3 at all.

        Lets wait for his reply then, but I think he shouldn't have added that gateway in the first place, only the static route would be enough.

        dead on arrival, nowhere to be found.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • ArimilA
          Arimil @johnpoz
          last edited by Arimil

          @johnpoz said in Can't get pfSense to communicate with Ubiquiti switch:

          @Arimil said in Can't get pfSense to communicate with Ubiquiti switch:

          Ubiquiti switch setup and afaik all of the addresses on that switch are 10.0.0.0/8.

          What unifi switch do you have, when did they add L3 to their switches? Before they were all just L2..

          USW Pro 24

          1 Reply Last reply Reply Quote 0
          • ArimilA
            Arimil @johnpoz
            last edited by Arimil

            @johnpoz said in Can't get pfSense to communicate with Ubiquiti switch:

            @mcury what is the switch model? The enterprise models can have routing.. But many of their other ones do not.

            l2switch.jpg

            If you want router or L3 switch that routes downstream, it should be connected via a transit network. And your going to need routes on both ends, pfsense side and on the "switch" where either the default route points to pfsense IP on the transit interface that the switch has an IP on, or to the networks that are on pfsense, etc..

            Here is a good diagram on how to setup a downstream router connected to pfsense and route networks that are on the downstream router

            pfsense-layer-3-switch.png

            It looks like I mostly had it setup correctly, I just need to configure the default gateways correctly, I wont be able to attempt this again until Friday likely since these systems are being used atm, I replaced the old hardware for now.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Arimil
              last edited by

              @Arimil yeah if the old L3 was routing, its gateway was prob set to whatever the old network was. Which prob now different?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @mcury
                last edited by

                @mcury said in Can't get pfSense to communicate with Ubiquiti switch:

                but I think he shouldn't have added that gateway in the first place

                you need a gateway to point the route too ;) So yeah pfsense needs to have a gateway, that it sends traffic to get to other networks that are downstream or upstream depending on where pfsense sits in the network ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                M 1 Reply Last reply Reply Quote 0
                • M
                  mcury @johnpoz
                  last edited by

                  @johnpoz said in Can't get pfSense to communicate with Ubiquiti switch:

                  you need a gateway to point the route too ;) So yeah pfsense needs to have a gateway, that it sends traffic to get to other networks that are downstream or upstream depending on where pfsense sits in the network ;)

                  hmmm ohh yes, you need to create that gateway to use it in the static route, my mistake :)

                  dead on arrival, nowhere to be found.

                  1 Reply Last reply Reply Quote 0
                  • ArimilA
                    Arimil
                    last edited by

                    I got a chance to mess with this over the weekend, it seems I was mistaken about the switch doing the routing, the switch just has a bunch of VLAN configured that it's resolving using the upstream gateway, so it seems I have to configure all those VLAN to match what the switch is expecting for the VLAN ids.

                    1 Reply Last reply Reply Quote 0
                    • C
                      coxhaus @mcury
                      last edited by coxhaus

                      @mcury
                      Look at Cisco. They have been doing layer 3 for many years and it works well. All of Cisco small business 300 and 500 switches do layer 3. I have been running layer3 at home for 15 years.

                      You want to point all the local gateways at the layer 3 switch and point the default route to Pfsense.

                      If you are doing trunking then you are NOT doing layer 3 switching.

                      M 2 Replies Last reply Reply Quote 0
                      • M
                        mcury @coxhaus
                        last edited by

                        @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                        @mcury
                        Look at Cisco. They have been doing layer 3 for many years and it works well. All of Cisco small business 300 and 500 switches do layer 3. I have been running layer3 at home for 15 years.

                        You want to point all the local gateways at the layer 3 switch and point the default route to Pfsense.

                        I used to work a lot with Cisco switches, but at that time, most of them didn't support L3.
                        The VLAN interface was for management only.

                        According to the specs, USW Pro 24 is L3 capable but I'm not sure If I would use it.
                        See, the L3 support is pretty recent, maybe three months ago (not sure exactly when) they released a firmware that fixed ACL and other things.
                        Until that moment, nobody was using the L3 features of these switches because a simple reboot would erase all your ACL configuration.

                        dead on arrival, nowhere to be found.

                        C 1 Reply Last reply Reply Quote 0
                        • M
                          mcury @coxhaus
                          last edited by

                          @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                          If you are doing trunking then you are NOT doing layer 3 switching.

                          That is router on a stick.

                          @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                          You want to point all the local gateways at the layer 3 switch and point the default route to Pfsense.

                          We were not aware that the end user was speaking about L3 at that time.

                          dead on arrival, nowhere to be found.

                          1 Reply Last reply Reply Quote 0
                          • C
                            coxhaus @mcury
                            last edited by coxhaus

                            @mcury
                            You must be as old as me. Back when I worked, we only used Cisco enterprise. I retired around 20 years ago.
                            I have been running Cisco small business equipment since then. The nice thing about Cisco small business networking equipment is you get firmware updates for life of the product. It is not like Cisco enterprise where you have to pay for IOS upgrades. So, it works well for home and small businesses. I run a CBS350 switch and 3 Cisco 150ax WiFi 6 Aps.

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              mcury @coxhaus
                              last edited by

                              @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                              You must be as old as me.

                              Yes, I feel old ehhe

                              @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                              I have been running Cisco small business equipment since then.

                              They are way to expensive around here, maybe one day I get one to play with, for fun :)

                              dead on arrival, nowhere to be found.

                              C 1 Reply Last reply Reply Quote 0
                              • C
                                coxhaus @mcury
                                last edited by coxhaus

                                @mcury I paid less than $300 for my POE+ Cisco cbs350 switch and my last wireless 150ax AP costs me $102. Not expensive for me.

                                M 1 Reply Last reply Reply Quote 0
                                • M
                                  mcury @coxhaus
                                  last edited by mcury

                                  @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                                  Not expensive for me.

                                  I live in a third world country. I bought a SG-4100 for 500 dollars, paid 9 minimum wages in local currency.
                                  Here, if you want to import something, you buy one for yourself and a bunch for the government, in taxes. 🤕

                                  dead on arrival, nowhere to be found.

                                  C 1 Reply Last reply Reply Quote 0
                                  • C
                                    coxhaus @mcury
                                    last edited by

                                    @mcury
                                    So, I would assume an Ubiquiti switch would cost around the same. You may be better off with Cisco.

                                    M 1 Reply Last reply Reply Quote 0
                                    • M
                                      mcury @coxhaus
                                      last edited by

                                      @coxhaus said in Can't get pfSense to communicate with Ubiquiti switch:

                                      So, I would assume an Ubiquiti switch would cost around the same. You may be better off with Cisco.

                                      Yeap, I'll definitely check those, I usually wait a lot, do a lot of research..

                                      When I got the SG-4100, I was thinking about an upgrade of my entire network to 2.5Gbps, but since then, I couldn't find a managed 2.5Gbps switch that worth the price.

                                      In this mean time, I got non managed switch, tp-link (TL-SH1005), it gets the job done.
                                      Also got a 2.5Gbps ethernet adapter for my NAS, which is working perfectly.

                                      So, for the time being, I can search for prices, no rush..

                                      dead on arrival, nowhere to be found.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.