Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense with L3 Switch

    Scheduled Pinned Locked Moved NAT
    4 Posts 2 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hec
      last edited by

      I try to make a plan for upgrading to 2.1 and also to change my network setup a bit.
      Now the pfSense is acting as Firewall, NAT, VPN so more or less all network services. For the public ipv4 ips i have now 1:1 nat on pfsense to the internal ips. The servers only have private ips. We are talking of two /29 and one /28 network.
      The other NAT is needed for some VLANs like LAN, WLAN, VoIP, MGMT and so on in total i have here 10 vlans.
      Because of not so good performance of pfsense in intervlan routing i will change to L3 switching.
      I will include the pfSense into the OSPF routing here. are i'm right that i need to setup the NAT rules still on pfSense? If yes which rules do i have to configure?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        Yes, you still need outbound NAT rules to cover all of the subnets that exist behind the L3 switch

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • H Offline
          hec
          last edited by

          Is the 2.1 version ready for production use? I don't know if i should setup a 2.0 or 2.1.
          One the one side i think its better to use the stable version but on the other side i think why not using the 2.1 and don't have the work to upgrade in 2 months when 2.1 is released.
          Is it still possible to use IPv6 with 2.0 or is it better to use 2.1?
          I hope it is ok if i ask this here. Or should i open a new topic in right section?

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            No IPv6 on 2.0.x, you'd need 2.1

            May as well use 2.1 now, it's nearly ready, just a few more bugs to fix, nothing too major for most people.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.