Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN layer 2 or 3 switch?

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 9 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kejianshi
      last edited by

      I personally have no need for a layer 3 switch and layer 2 is easy and not a problem if pfsense is down.

      1 Reply Last reply Reply Quote 0
      • M
        mikeisfly
        last edited by

        If you have the option to get a layer 3 switch over a layer 2, I personally would choose the layer 3 switch. Think about it, all thing being equal the layer 3 switch can do more. You don't have to have it working in layer 3 if you want PfSense to do the routing across vlans, but later on if you want that capability then you have it. You never said if this was for home or work, but in a home environment could be good for lab purposes as well. Other than that I ditto what everyone said.

        1 Reply Last reply Reply Quote 0
        • jahonixJ
          jahonix
          last edited by

          Since Cisco SG300 Gb switches have become ridiculously cheap it's more a question of which mode to configure them than to decide buying L2 or L3.
          Personally I haven't been a friend of Cisco switches until I was forced to use them in an install 2 years ago. Haven't looked back since…

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            10x more expensive than what I'd budget for home.

            1 Reply Last reply Reply Quote 0
            • jahonixJ
              jahonix
              last edited by

              Was it mentioned already if it is for a home or commercial install?

              Other than that I use Cisco (and TP-Link) switches extensively in my house now. As a student an el-cheapo switch was sufficient but I moved out of my tent many moons ago. Always depends.

              1 Reply Last reply Reply Quote 0
              • K
                kejianshi
                last edited by

                I'm still in my tent - Will probably die in my tent.  Kids will do that.  haha.

                1 Reply Last reply Reply Quote 0
                • H
                  Harvy66
                  last edited by

                  Cisco SG300 Gb is $550 from NewEgg right now. I purchase my HP1810-24g(26 ports total) for only $220. I wouldn't spend 150% extra for layer 3, especially since most inter-vlan communications should be filtered in my case.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    What what are you looking at of the sg300 that is 550$

                    The 10 porter is $168
                    http://www.newegg.com/Product/Product.aspx?Item=9SIA1EA1YB6736&cm_re=sg300--33-150-087--Product

                    I see a 28 port POE version for 563$

                    Where is this going to be used?  Home or business?  I got a sg300-10 a while back for home use, and it ROCKS!!  Can not beat the price - I don't use it for layer 3, but its nice to know its there if do need it.  Pfsense is my layer 3

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • jahonixJ
                      jahonix
                      last edited by

                      @Harvy66:

                      … HP1810-24g ...

                      You can't really compare that to a Cisco SG300.
                      The HP neither has a CLI for management (web only) nor a serial console. That's fine for initial setup and probably some VLANs but that's about it.
                      And this does not account for all the other features and benefits.

                      Recently we had to track down an IGMP issue with Cisco Catalyst 2960 switches (made a runner limp every 5s on IP-TV). Turned out to be the switch's firmware. You don't have the necessary tools from a web-gui for such an analysis.

                      That said, part of my office still runs a rather old HP 1800-24g just fine but it's years old already. And that's only basic office switching, nothing fancy.

                      1 Reply Last reply Reply Quote 0
                      • J
                        jgraham5481
                        last edited by

                        @ei3000:

                        Hello

                        What will happen if I use layer 2 switch for VLAN`s and pfSense as router and pfSense goes down, will there be any security issues?
                        Is it better for security to use layer 3 switch if pfSense goes down?

                        Thanks

                        If this was your only concern, why not build a second firewall, for fail over? It's pretty easy, and in 2.2 you don't necessarily need 3 WAN IP's to make it work right.

                        1 Reply Last reply Reply Quote 0
                        • E
                          ei3000
                          last edited by

                          Hello

                          Thanks to all of you.

                          I will think about what soulution I go for.

                          Thanks

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.