Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense -14 network ports ! and freenas -please note - 2 separate machines

    Scheduled Pinned Locked Moved General pfSense Questions
    26 Posts 8 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      heper
      last edited by

      i grouped several of the internet connections together as a bridge and i have a router/switch and …....

      uhm? what?

      schematic please ;)

      1 Reply Last reply Reply Quote 0
      • F Offline
        fragged
        last edited by

        1. Use a real switch (managed if you need LACP/LAGG)
        2. Use the switch to connect all your LAN devices together.
        3. Use pfSense for what it's intended, ie a router / edge device. For home use you should only need 1 WAN and 1 LAN (DMZ, IP Cameras, etc. might warrant another LAN interface).
        1 Reply Last reply Reply Quote 0
        • F Offline
          firewalluser
          last edited by

          Cross posting the below as some of it may be useful namely gliffy.

          Example sticky for this forum.
          –------------------------------------------------------------------------------------
          Title:Need help? 20 seconds reading this post to save time.

          Content:
          Before posting:
          1. Use the FAQ at this link. https://www.pfsense.org/get-support/support-faq.html
          2. Use the WIKI at this link for step by step guides & other info. https://doc.pfsense.org/index.php/Main_Page
          3. Always search the forum using link top right of this webpage, to limit search to a subform, use the search from within the subforum. keywords work best.
          4. Investigate the pfsense bugtracker here https://redmine.pfsense.org/projects/pfsense/issues?set_filter=1
          and the pfsense packages bugtracker here https://redmine.pfsense.org/projects/pfsense-packages/issues?set_filter=1

          If you dont know the terminology, investigate links like http://www.linktionary.com/f/firewall_term.html & http://www.techrepublic.com/article/jargon-explained-learn-the-terms-used-with-firewall-technologies/

          Before posting.
          If you still havent found the knowledge you are looking for, when describing your problem, question or observation, include the following information.
          1. What version of pfsense and the hardware including model of network cards, you are currently or planning to use.
          2. Use Gliffy (its free and webbased) to draw your network layout. https://www.gliffy.com/uses/network-diagram-software/
          3. Ensure your post title is descriptive to attract the relevant knowledgable users. Lan problem, wan problem is not descriptive.
          4. Describe your problem, question or observation in as much detail as possible to avoid unnecessary questions being posted asking for more information, dragging out the total time it takes for you to resolve your post.

          Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

          Asch Conformity, mainly the blind leading the blind.

          1 Reply Last reply Reply Quote 0
          • M Offline
            Mega Man
            last edited by

            @firewalluser

            sorry i read the rules and did not see these, so i missed them  maybe you should get them put into it?

            i hope this helps because even i am more lost after "making" it

            @fragged

            thanks !~ i think that is what the consensus was/will be - i can not find the posts that made me think i could do what i wanted, but at least i had fun

            back @ firewalluser
            have i set up firewall rules-
            yes i think so ? all of the bridge gets ip addresses and can communicate with the internet

            although now that you mention it, maybe not. let me try a few things – thanks  ill get back with the "rules" i have made

            1 Reply Last reply Reply Quote 0
            • johnpozJ Online
              johnpoz LAYER 8 Global Moderator
              last edited by

              Why would you not just use a switch here?  The performance of your bridge without how many interfaces in it is not going to compare to what a CHEAP switch could do.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • M Offline
                Mega Man
                last edited by

                Tyvm for your reply.

                I thought (incorrectly it seems ) that it was one of the jobs of pfsense. - probably due to the fact the only networking experience I have is with home routers.

                One of the reasons I took on this project was for the fun and challenge.  I learned allot  and look forward to more learning.

                O well  live and learn.

                Thanks again for your help

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  how much money did you spend on nics for this pfsense box?  I am thinking you could of gotten one hell of nice managed switch for the cost of 14 nics ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    i can not find the posts that made me think i could do what i wanted

                    You could do it.

                    Just because you can doesn't mean you should.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      Mega Man
                      last edited by

                      Thanks for your help

                      @johnpoz:

                      how much money did you spend on nics for this pfsense box?  I am thinking you could of gotten one hell of nice managed switch for the cost of 14 nics ;)

                      Not much tbh. I had some consumer stuff around that I could of used.  But I wanted certain things like ipmi.

                      If I would of known not to use it as a switch I would of got a avoton  but I wanted the additional ports.

                      So all in all in its current condition I spent a total of.  260.

                      90 for the nics which will be repurposed  to my freenas and a few other servers I have

                      As to the switch I bought a srw2048.

                      I want 24 ports. So I always up size ( I would of bought more nics but I couldn't find a board with enough pie slots )

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        How much did you spend on that switch?  It goes end of support from cisco in feb of 2016.. Prob not something I would of gotten to be honest.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • ? This user is from outside of this forum
                          Guest
                          last edited by

                          That said those SRW switches are workhorses and will survive for many moons. I still have Linksys SRW versions working like a champ. Noisy fan is my only complaint. Excellent design…..

                          1 Reply Last reply Reply Quote 0
                          • M Offline
                            Mega Man
                            last edited by

                            @johnpoz:

                            How much did you spend on that switch?  It goes end of support from cisco in feb of 2016.. Prob not something I would of gotten to be honest.

                            looks like ~ 60 to 100

                            have not had a chance to purchase

                            which would you recommend ?

                            i want all ports to have 10/100/1000 and lacp  24 + ports

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ Online
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              So your getting it used off ebay then or something because that is not new cost by any means..

                              The SG300-28 would fit your bill I think.. This is replacement for the srw line to be sure.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • M Offline
                                Mega Man
                                last edited by

                                What's wrong with buying from ebay? The  cost of networking stuff makes it a great value for home use.

                                Besides less life is there a reason you  would recommend not buying from ebay

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ Online
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  Nothing is wrong with ebay - but there is no way could get a new unit for that price point ;)  I normally buy my stuff new is all.  Which was the reason for asking about how much you spent on nics ;)  New there is no way you would get 14 nic ports for less then the cost of a new switch, etc..

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • M Offline
                                    Mega Man
                                    last edited by

                                    TYVM guys for all your help
                                    And I got most of the stuff for this build used. I got really lucky tbh.

                                    My freenas build I bought new as I wanted specific things and data integrity was high priority

                                    1 Reply Last reply Reply Quote 0
                                    • S Offline
                                      SisterOfMercy
                                      last edited by

                                      @johnpoz:

                                      Why would you not just use a switch here?  The performance of your bridge without how many interfaces in it is not going to compare to what a CHEAP switch could do.

                                      Hmmm, I wouldn't know. Those SUN cards probably have an intel chipset.
                                      I have a similar setup, but only with three ports. Bridge0 is the lan interface. Bridge0 contains igb1, igb2 and igb3. I would think this is more practical for a small home network. I have a free quad port card, which I might install in the pfSense box, because I do not have enough ports on my switch.

                                      Hi, I'm Lance Boyle, and people often wonder if I'm real.

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ Online
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by

                                        "I would think this is more practical for a small home network."

                                        You would be thinking wrong then.. Lets be blunt and point blank about this!!  It is NEVER EVER EVER, NEVER better to bridge NIC ports to use as a "switch". Why would anyone think this ever??? When you can get a 5 port get switch for 20 freaking dollars that will out perform you nonsense bridge setup.  When would this ever make sense in any home or any setup anywhere??

                                        There are are times where a bridge can be useful.. This would not be one of them.. If you need more ports to connect devices, get another switch, update your switch to one with more ports, etc.. etc..  Bridging nics is not a switch! PERIOD!!!

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • ? This user is from outside of this forum
                                          Guest
                                          last edited by

                                          To make matter worse OpenWRT defaults to a Bridge type interface and you have to go -out of your way- to make a routed interface. I think the differences between all the router OS's make for confusion. I was there no long ago!!

                                          I remember when i came over from Monowall it blew my mind that I was being forced to make a WAN interface at bare minimum, whereas MonoWALL required at least a LAN interface. Small differences can be tough when your used to another way.

                                          I have used the clumped together mess of bridging for "convience" mostly due to all the bad wireless tutorials out there.

                                          1 Reply Last reply Reply Quote 0
                                          • F Offline
                                            fragged
                                            last edited by

                                            @Phishfry:

                                            To make matter worse OpenWRT defaults to a Bridge type interface and you have to go -out of your way- to make a routed interface. I think the differences between all the router OS's make for confusion. I was there no long ago!!

                                            Devices that run *WRT usually have a integrated switch chip in them to provide N number of LAN ports. Those are a complete different device from a PC with multiple NIC ports.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.