Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    General Questions from a Noob

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 8 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      Tell you for sure that the synology nas is way more user friendly than freenas or nas4free, etc. Running their DSM 6.2rc currently…  No brainer simple stuff..  Running virtual machine manager on it - easy to setup some VMs so running unifi controller on a ubuntu vm, and domotoz on a vm.. They have a package for synology but don't see how you can do vlans with that so just run it on ubuntu vm.  Also run some docker stuff on there..

      You could for sure prob run pfsense on there - but have not gotten around to playing with that yet.

      I ran pfsense on esxi for many years.  On the same esxi host I ran my nas, etc. plus many other vms..  And I do love running pfsense as vm - makes no brainer to play with snapshots since you just take a snapshot of the vm before you do anything - so click to rollback, etc.

      But then again with your router on your esxi host - when you have to say upgrade esxi, your whole network is down..  When the older esxi host couldn't keep up with my new faster internet speed moved to pfsense on hardware - got the sg4860.. Loving IT!  And broke out my nas to a synology ds918+ which very happy with.. Kind of wishing I would of went with more bays and should of gotten something I could go 10ge with.. Next one ;)

      You did not give any sort of budget.. You can get your basic smart vlan capable switch for under $40 for sure 8 port gig.  Or you could spend drop a couple hundred on more ports and more features.  I am huge fan of the cisco small business sg300 line have 28 port and 10 port.. Love them...  But I concur with jknott stay away from tp-link.  They suppose to have fixed their 108e model v3 with firmware on the vlans... But previous v2 has no firmware update and vlans are borked on them..  I believe same thing with their AP they don't actually do vlans correctly.

      For AP I run unifi and they are very nice and very home budget friendly for the feature set.. $130 gets you the AP pro model, or 80$ gets AC lite model..  I have 3 in my house and they support pretty much anything you would want to play with home network.  Recently added dynamic vlans via mac address on PSK ssids - can hand them out via freerad running on pfsense ;)

      If you want to build a VM host for your router and nas that is fine - but do yourself a favor and break out your wifi to real AP..

      While your VM host if you do one for sure 4 ports a good start, your still going to want a vlan capable switch..  POE 4 port nic?  Don't think I have ever heard of such an animal..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • G
        gzorn
        last edited by

        I'm guessing that the OP was looking for recommendations on a POE switch, rather than NIC. I'm building an IP camera setup behind my pfsense router. I use a Netgear GS108PEv3 (8 ports total, 4 have POE) and a GS110TP (cannot remember version number - used from ebay, 8 port POE + 2 SFP). They seem to work, though they get warm (no fans) and the mgmt webserver on the GS110TP is quite slow. It's more than sufficient for powering a bunch of cameras (usually no more than 6W each). Both are VLAN capable, though it takes some experimentation to make that work right.

        A few bits of unsolicited advice - I was initially thinking about doing something similar to what you're planning. However, I decided to buy an old, cheap Dell desktop off ebay ($150 for a used 3020 under warranty + $40 multiport NIC) to dedicate to the router. I think that's a better choice for manageability (updates to the NAS, cameras, or VM server don't take your entire intranet down) and security (new variants of spectre have already surfaced).

        Although it sounds like a small thing, what you're planning is potentially a big, complicated project. Dividing it into separate, manageable chunks will dramatically reduce your workload and the consequences of making a mistake. If you're a *nix newbie, there's a LOT to learn.

        1 Reply Last reply Reply Quote 0
        • W
          Waqar.UK @JKnott
          last edited by

          @jknott said in General Questions from a Noob:

          No one suggested any 4 port switch, or Wifi devices.

          1. Avoid TP-Link
          2. Avoid TP-Link

          I use TP link switches across my house as well as my cousins. No problems so far.
          Router as AP, yes totally agree as I bought a TP link router two years ago, it needed to be re-booted every few days. I spoke to their friendly tech support and they could not solve it. Bought an Asus, works perfectly and I think their firmware is open source. Also third party firmware are also available.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Waqar.UK
            last edited by

            @waqar-uk

            So you use those tplink switches with vlans? If not then sure they are fine - the problem with the tplink 105e and 108e versions is they do not actually do vlans correctly. They do not allow removal of vlan 1 from ports you want to put into a different vlan. So every interface is in vlan 1 be it you put in in a new vlan 10 or not.

            So its not any better than a dumb switch running multiple layer 3 on.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            W 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott
              last edited by

              @waqar-uk said in General Questions from a Noob:

              I use TP link switches across my house as well as my cousins. No problems so far.

              As johnpoz says, some TP-Link switches don't handle VLANs properly. I also have the same issue with my TP-Link AP. However, other than that, it works well.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • W
                Waqar.UK @johnpoz
                last edited by

                @johnpoz said in General Questions from a Noob:

                @waqar-uk

                So you use those tplink switches with vlans? If not then sure they are fine - the problem with the tplink 105e and 108e versions is they do not actually do vlans correctly. They do not allow removal of vlan 1 from ports you want to put into a different vlan. So every interface is in vlan 1 be it you put in in a new vlan 10 or not.

                So its not any better than a dumb switch running multiple layer 3 on.

                I don't use VLANS, but I use them as 'dumb' switches that work fine for me.

                johnpozJ JKnottJ 2 Replies Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Waqar.UK
                  last edited by

                  @waqar-uk

                  Yeah they are fine for dumb - but why would you have purchased a smart if all you wanted wanted/needed was dumb. Was your future plan to use them as vlans? If so the v2 version has not gotten a firmware update while the v3 models seems to have a firmware update out that is suppose to fix their mishandling of vlans.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  W 1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @Waqar.UK
                    last edited by

                    @waqar-uk said in General Questions from a Noob:

                    I don’t use VLANS, but I use them as ‘dumb’ switches that work fine for me.

                    One thing you can do with managed switches is port mirroring. This allows you to use a separate computer, running Wireshark, to monitor the traffic. I have one of those VLAN challenged TP-Link switches, but it works fine in the port mirroring role. I carry it in my computer bag, so I can use it when necessary to monitor an Ethernet connection.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Yeah it would work for that because its like a hub ;) heheh with everything in vlan 1 ROFL hehehe So all broadcast/multicast is going to every port anyway. Your mirror just going to add the unicast traffic so it doesn't have to do much hehehehe

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      JKnottJ 1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @johnpoz
                        last edited by

                        @johnpoz said in General Questions from a Noob:

                        Yeah it would work for that because its like a hub ;) heheh with everything in vlan 1 ROFL hehehe So all broadcast/multicast is going to every port anyway. Your mirror just going to add the unicast traffic so it doesn't have to do much hehehehe

                        You set it up so that one port monitors another. I have mine configured so port 1 monitors port 2. I plug the computer running Wireshark into port 1 and pass the connection through port 2 and any other port. It does not turn a switch into a hub. The non mirror ports continue to work as a regular switch.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Dude I know what a span port is ;) I was freaking joking..

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @johnpoz
                            last edited by

                            @johnpoz said in General Questions from a Noob:

                            Dude I know what a span port is ;) I was freaking joking..

                            Some less knowledgeable may not know that.

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • W
                              Waqar.UK @johnpoz
                              last edited by

                              @johnpoz said in General Questions from a Noob:

                              @waqar-uk

                              Yeah they are fine for dumb - but why would you have purchased a smart if all you wanted wanted/needed was dumb. Was your future plan to use them as vlans? If so the v2 version has not gotten a firmware update while the v3 models seems to have a firmware update out that is suppose to fix their mishandling of vlans.

                              I just bough a TP link 8 port switch to use as a way to pass my Pfsense LAN to many of my devices, be they a wireless AP, power line networking and my main desktop direct Ethernet connection.

                              JKnottJ 1 Reply Last reply Reply Quote 0
                              • JKnottJ
                                JKnott @Waqar.UK
                                last edited by

                                @waqar-uk said in General Questions from a Noob:

                                @johnpoz said in General Questions from a Noob:

                                @waqar-uk

                                Yeah they are fine for dumb - but why would you have purchased a smart if all you wanted wanted/needed was dumb. Was your future plan to use them as vlans? If so the v2 version has not gotten a firmware update while the v3 models seems to have a firmware update out that is suppose to fix their mishandling of vlans.

                                I just bough a TP link 8 port switch to use as a way to pass my Pfsense LAN to many of my devices, be they a wireless AP, power line networking and my main desktop direct Ethernet connection.

                                They're OK as a regular switch or even for port mirroring. However, you can forget about using them for VLANs.

                                PfSense running on Qotom mini PC
                                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                UniFi AC-Lite access point

                                I haven't lost my mind. It's around here...somewhere...

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.