Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense configuration with Layer3 Switch

    Scheduled Pinned Locked Moved Routing and Multi WAN
    18 Posts 5 Posters 2.8k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Sonicpat2018
      last edited by

      I have a brand new XG-7100U box with 8 interfaces.
      The network is about 60 computers and another 50 phones on the wifi.
      The businness plan to grow about the double in the next 2 years.
      I just wanted to isolate 2 different lan traffic plus the Guest WIFI.
      I think as you said that the Pfsense box will pretty easyly handle all the traffic without any speed issue.
      I was planning to implement SQID as proxy soon too.

      Thanks you very much for your light!

      1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator
        last edited by

        @sonicpat2018 said in Pfsense configuration with Layer3 Switch:

        XG-7100U

        Are you using the sfp+ ports? Or just port on the switch.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        1 Reply Last reply Reply Quote 0
        • S Offline
          Sonicpat2018
          last edited by

          only ports

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Do you plan on using them at some time in the future at only 1 gig? I recall some threads I believe where they only work at 10ge.. People had to send their units in, or replace them or something.. Will try to find the thread in question.

            But sure your switch ports will be fine as uplinks for your 2 vlans, etc.

            Here is atleast 1 of the threads I remember
            https://forum.netgate.com/topic/131725/xg-7100-sfp-module-1gbps

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • G Offline
              gjaltemba @Sonicpat2018
              last edited by

              @sonicpat2018
              Also need pass rules on lan interface for subnets 192.168.0.0 and 10.0.10.0

              1 Reply Last reply Reply Quote 0
              • S Offline
                Sonicpat2018
                last edited by

                Ok now I tried to reconfigure the pfsense from scratch and experiment another problem when I try to assign interface to vlan 2 and 3

                The only interface availlable is the Lagg0 wich is the switch for ethernet port 2-8.
                I am pretty confused about this setup.
                How would I be able to dedicate a single port to a specific vlan without having the ability to choose one?

                Thanks

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  why do you have a lagg setup?

                  But sure you can assign your vlans to a lag.. Or you can assign your switch ports to different vlans.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    Sonicpat2018
                    last edited by

                    The pfsense unit came with this setup by default
                    Lagg1 for WAN with vlan 4090
                    Lagg0 for LAN with vlan 4091

                    I tried to assign the switch ports to different vlan, but i am unable to communicate between vlans.

                    Does anyone know about documentation on how to configure pfsense hardware with internal switch configuration in vlan?

                    Thanks

                    pfSenseTestP 1 Reply Last reply Reply Quote 0
                    • pfSenseTestP Offline
                      pfSenseTest @Sonicpat2018
                      last edited by

                      @sonicpat2018 said in Pfsense configuration with Layer3 Switch:

                      The pfsense unit came with this setup by default
                      Lagg1 for WAN with vlan 4090
                      Lagg0 for LAN with vlan 4091

                      This is incorrect according to the documentation...
                      https://www.netgate.com/docs/pfsense/solutions/xg-7100/switch-overview.html

                      2x SG-5100 | MBT-4220 (retired) | SG-1000 (retired)

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        Sonicpat2018
                        last edited by Sonicpat2018

                        Sorry you arre right, configuration reflecting LAGG0 with different vlan for WAn and LAN.

                        But the point is that with vlan configured other than default one EX: Vlan 3 : 10.0.10.0 /24 I am not able to ping the gateway in this vlan.

                        I configured the Vlan 3 by tagging port 9 and 10 in the menu:
                        interfaces / switch / Vlans
                        And add port 4, untaggged as it is the port I plan to use for this network.

                        But I am still unable to ping the gateway in the vlan3

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          Sonicpat2018
                          last edited by

                          Now everything is working correctly on the pfsense for Vlan routing.
                          It was firewall issues.
                          I am facing a problem where I am unable to isolate vlan on particular port on the ubiquiti Switch.
                          Vlan are isolating well on the Pfesense interface but I am unable to tag ports on the Edgeswitch.
                          Does anyone have exemple of a working setup with a pfsense Vlan routing and a Ubiquiti Edgeswitch only in vlan aware mode?

                          Thanks

                          1 Reply Last reply Reply Quote 0
                          • DerelictD Offline
                            Derelict LAYER 8 Netgate
                            last edited by

                            What does UBNT mean when they say "VLAN aware" mode.

                            Tag the VLANs on a port on the XG-7100 switch.

                            Tag the VLANs on a port on the UBNT switch.

                            Cross-connect them.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.